Cybersecurity firm BlueVoyant has released findings from its fourth annual global survey on supply chain cyber-risk management, The State of Supply Chain Defence: Annual Global Insights Report, revealing persistent struggles in the UK to reduce supply chain cyber-risk.
The study, conducted by independent research organiation Opinion Matters, gathered responses from 300 participants in the U.K., representing organisations with over 1,000 employees across various industries.
The UK results underscore a concerning trend, with 97% of organisations reporting negative impacts from breaches in third-party or supplier partners in the past year. This figure has remained consistent for the last three years, indicating a persistent challenge in the realm of supply chain cybersecurity.
Joel Molinoff, BlueVoyant’s global head of supply chain defense, acknowledged the ongoing struggle, stating: “UK businesses are still struggling to make progress on reducing supply chain and third-party cyber-risk. Awareness and prioritization remain low, and breach frequency is persistently high.”
Despite the challenges, there are positive indicators in the form of budget growth. Eighty-seven percent of UK organisations anticipate budget increases, with an average expected growth of 57%. This reflects a notable improvement from the previous year, signaling a growing recognition of the importance of cybersecurity investment.
High-profile breaches have played a role in influencing budgets, with 51% of UK respondents expecting them to result in increased budgets for internal and external resources to counter supply chain security issues.
Recommended reading
- Over 90% of companies hit by supply chain cybersecurity breaches
- Nearly half of young tech workers have negative experience
- How cybercriminals exploit trust between organisations
The study identifies pain points in managing supplier performance and visibility into cyber-risk. Key concerns for UK respondents include gaining up-to-date visibility into the organisation’s current risk posture, addressing blind spots where the organisation lacks resources and visibility to spot emerging risks, and understanding how to penalise third parties or suppliers for non-compliance or remediation issues.
While the global cohort highlights challenges related to internal understanding, working with suppliers, and meeting regulatory requirements, UK respondents emphasise the need for real-time visibility.
The study also explores the role of automation in managing cyber-risk across large and complex supply chains. Fifty-four percent of UK respondents prefer a mix of in-house or external analyst resources with automation used in specific areas. Only 20% opt for full automation technology wherever possible.





