Most organisations are at risk thanks to immature supply chain security
- Supply chain attacks are becoming more frequent and more dangerous
- Many security teams are worried about the risks
- 70% of firms have suffered one or more attacks in the past year
A new survey from SecurityScorecard reveals that cybersecurity leaders are faced with serious supply chain and third party risks. The survey outlines that CISOs and security professionals all around the globe are struggling to keep up with the pace of expanding threats.
The software supply chain has become a worrying weak link for firms of all sizes, as smaller software providers are difficult to assess and often don’t have the cybersecurity capabilities large organizations can afford – with cybercriminals choosing smaller software companies as a point of intrusion to gain access to larger firms.
A staggering 88% of respondents were either ‘very concerned’ or ‘somewhat concerned’ about supply chain cybersecurity risks, and with good reason too, since 70% say they have experienced one or more ‘material third-party cybersecurity incidents’, with 5% suffering 10 or more in the past year.
Persistent threats
Recent research suggests third party involvement in threats has doubled from 15% to 30% in recent months, and a growing dependence on digital technologies also means a growing dependence on third party software for all industries.
As such, organizations are tasked with stringent cybersecurity practices to keep themselves secure. But, not everyone is confident in their ability to do so, with only 26% of organizations incorporating supply chain security into their cybersecurity programs – most rely on ‘point-in-time, vendor-supplied assessments or cyber insurance.’
Cybersecurity can be overwhelming even for firms with powerful capabilities, and nearly 40% of respondents reported that data overload and issues with prioritizing threats are their biggest challenge.
“Supply chain cyberattacks are no longer isolated incidents; they’re a daily reality,” said Ryan Sherstobitoff, Field Chief Threat Intelligence Officer at SecurityScorecard
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“Yet breaches persist because third-party risk management remains largely passive, focused on assessments and compliance checklists rather than action. This outdated approach fails to operationalize the insights it gathers. What’s needed is a shift to active defense: supply chain incident response capabilities that close the gap between third-party risk teams and security operations centers, turning continuous monitoring and threat intelligence into real-time action. Static checks won’t stop dynamic threats—only integrated detection and response will.”
You might also like
Supply chain attacks are becoming more frequent and more dangerous Many security teams are worried about the risks 70% of firms have suffered one or more attacks in the past year A new survey from SecurityScorecard reveals that cybersecurity leaders are faced with serious supply chain and third party risks.…
Recent Posts
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023