One in Four Businesses Hit by Supply Chain Cyber Incidents

A new survey finds that 26% of businesses experienced a cyber incident linked to their supply chain in the past year, highlighting ongoing challenges around third-party risk management and supplier security.

Key Highlights

  • Twenty-six percent (26%) of businesses experienced a supply chain-originated cyber incident in the past year, demonstrating the continued impact of third-party cybersecurity risks on organizational resilience.
  • Nearly half of organizations (48%) continued working with suppliers despite known security or resilience concerns, highlighting the challenges businesses face when managing critical supplier dependencies.
  • Supply chain vulnerabilities rank among the top cybersecurity and resilience concerns for the next five years, cited by 23% of respondents, behind AI-driven cyber threats (46%) and ransomware (26%).

More than one in four businesses (26%) experienced a cyber incident originating from their supply chain during the past year, according to the Data Health Check 2026, an annual survey of 500 IT decision-makers. The research also found that 48% of organizations have continued working with suppliers despite known resilience or security concerns.

The findings suggest that while supplier risk is widely recognized, many organizations face practical constraints in addressing it. More than a quarter of respondents (26%) cited dependence on suppliers as one of the main barriers to improving organizational resilience.

The survey found that supplier resilience assessments are now common practice. Nearly nine in ten organizations (89%) assess supplier resilience during onboarding, while 61% conduct assessments annually, quarterly or on a continuous basis.

Looking ahead, respondents identified supply chain vulnerabilities as one of the three biggest resilience and cybersecurity challenges they expect to face over the next five years. AI-driven cyber threats ranked highest, cited by 46% of respondents, followed by ransomware (26%) and supply chain vulnerabilities (23%).

The research also identified a relationship between supplier risk and cyber incidents. Organizations that reported knowingly continuing to work with suppliers presenting resilience or security concerns were more than four times as likely to experience a supplier-originated cyber incident. Among those organizations, 43% reported an incident during the past year, compared with 10% of organizations that did not report knowingly working with higher-risk suppliers.

Chris Butler, Resilience Director at Databarracks, said the findings indicate that supply chain resilience remains a significant challenge despite increased awareness of third-party risk.

"Many organizations have good visibility of their primary suppliers, but understanding of indirect suppliers further down the supply chain is often more limited," Butler said. "Assessment processes alone cannot eliminate risk. Organizations should seek greater visibility into critical supplier dependencies and, where appropriate, work collaboratively with key suppliers to strengthen resilience and rehearse response plans."

Source: Databarracks


Stay Connected with ISE Magazine 

Subscribe to our newsletters and magazine for the latest telecom insights, explore the current issue for in-depth features and strategies, and register for upcoming webinars to learn directly from industry leaders.

This piece was created with the help of generative AI tools and edited by our content team for clarity and accuracy.
Sign up for our eNewsletters
Get the latest news and updates