Most organisations are at risk thanks to immature supply chain security


- Supply chain attacks are becoming more frequent and more dangerous
- Many security teams are worried about the risks
- 70% of firms have suffered one or more attacks in the past year
A new survey from SecurityScorecard reveals that cybersecurity leaders are faced with serious supply chain and third party risks. The survey outlines that CISOs and security professionals all around the globe are struggling to keep up with the pace of expanding threats.
The software supply chain has become a worrying weak link for firms of all sizes, as smaller software providers are difficult to assess and often don’t have the cybersecurity capabilities large organizations can afford – with cybercriminals choosing smaller software companies as a point of intrusion to gain access to larger firms.
A staggering 88% of respondents were either ‘very concerned’ or ‘somewhat concerned’ about supply chain cybersecurity risks, and with good reason too, since 70% say they have experienced one or more ‘material third-party cybersecurity incidents’, with 5% suffering 10 or more in the past year.
Persistent threats
Recent research suggests third party involvement in threats has doubled from 15% to 30% in recent months, and a growing dependence on digital technologies also means a growing dependence on third party software for all industries.
As such, organizations are tasked with stringent cybersecurity practices to keep themselves secure. But, not everyone is confident in their ability to do so, with only 26% of organizations incorporating supply chain security into their cybersecurity programs – most rely on ‘point-in-time, vendor-supplied assessments or cyber insurance.’
Cybersecurity can be overwhelming even for firms with powerful capabilities, and nearly 40% of respondents reported that data overload and issues with prioritizing threats are their biggest challenge.
“Supply chain cyberattacks are no longer isolated incidents; they’re a daily reality,” said Ryan Sherstobitoff, Field Chief Threat Intelligence Officer at SecurityScorecard
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“Yet breaches persist because third-party risk management remains largely passive, focused on assessments and compliance checklists rather than action. This outdated approach fails to operationalize the insights it gathers. What’s needed is a shift to active defense: supply chain incident response capabilities that close the gap between third-party risk teams and security operations centers, turning continuous monitoring and threat intelligence into real-time action. Static checks won’t stop dynamic threats—only integrated detection and response will.”
You might also like
Supply chain attacks are becoming more frequent and more dangerous Many security teams are worried about the risks 70% of firms have suffered one or more attacks in the past year A new survey from SecurityScorecard reveals that cybersecurity leaders are faced with serious supply chain and third party risks.…
Recent Posts
- Apple overhauls EU App Store rules following penalty
- Most organisations are at risk thanks to immature supply chain security
- Ember’s temperature-controlled smart mug is down to its best price
- Hackers are using fake Zoom apps to steal your data and your cryptowallet – here’s how to stay safe
- Google tweaked its AI-powered Ask Photos feature and restarted its rollout
Archives
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010