Supply Chain Cyber Attacks Hit 26% of Firms in Past Year

Share this article
Share this article
Prioritise Us on Google
Almost half (48%) of IT decision-makers admit to working with suppliers despite known resilience or security concerns, largely due to supplier dependence (Image source: Getty Images/ljubaphoto)
More than a quarter of organisations suffered third-party cyber breaches in 2025, with reliance on risky vendors quadrupling vulnerability rates

Supply chain leaders require more visibility than ever. One in four (26%) of businesses have experienced a security breach from their supply chain over the past year. These figures, from Databarracks’ Data Health Check 2026 report, highlight an obvious disconnect between threat awareness and operational action.

Key findings from the Data Health Check 2026 report include:
  • Widespread supply chain breaches: 26% of businesses suffered a cyber incident originating from their supply chain in the last year.
  • Awareness without action: 48% of IT decision-makers admit to working with suppliers despite known resilience or security concerns, largely due to supplier dependence.
  • Risk quadrupling: Organisations that knowingly work with risky suppliers are over four times as likely to suffer a third-party cyber incident (43% vs 10%).
  • Long-term threat priority: 23% of respondents rank supply chain vulnerabilities as a top three challenge over the next five years, behind AI-driven threats (46%) and ransomware (26%).
Youtube Placeholder

Blind dependence quadruples security breach rates

Commercial priorities mean that many businesses have little scope to demand better security standards from suppliers, with the report finding that 26% of firms cite ā€œdependence on suppliersā€ as a primary barrier to improving overall operational resilience.

However, for those that knowingly keep relationships with risky suppliers, their companies are more than four times as likely to suffer a third-party cyber incident. Among the firms that are aware they are using vulnerable partners, more than two-fifths (43%) have experienced a cyber breach, compared to 10% of those that actively avoid risky suppliers.

Supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers.

Chris Butler, Resilience Director at Databarracks

When looking at future challenges, almost a quarter (23%) of leaders say that supply chain vulnerabilities is one of their top three operational challenges over the next five years. This is followed by AI-driven cyber threats at 46% and ransomware at 26%.

Databarracks Resilience Director Chris Butler highlights that systemic supply chain blind spots remain a critical vulnerability for modern enterprises. "Supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers," Chris says.

Chris Butler, Resilience Director at Databarracks (Image source: Chris Butler via LinkedIn)

Deeply interconnected business ecosystems

Traditional risk assessments can rely heavily on administrative questionnaires and, as Chris points out, these surface-level reviews fail to address complex operational realities beyond immediate tier-one relationships. 

ā€œThis approach creates a false sense of assurance rather than real resilience,ā€ Chris adds. ā€œTo truly manage your supply chain continuity, it's vital to actually get visibility of the situation.ā€

When asked by Supply Chain Digital about how the increasing complexity of supply chains could be upping the likelihood of an attack, Max Imbiel, Field CISO at Cloudflare, highlights the underlying technical challenge facing enterprise security teams.

"Supply chain attacks succeed because modern business ecosystems are deeply interconnected," Max says.

Max Imbiel, Field CISO at Cloudflare (Image source: Max Imbiel via LinkedIn)

"The more vendors, software dependencies and third-party integrations an organisation relies on, the larger the attack surface becomes, and the harder it is to see where risk is actually entering the environment. 

ā€œThat is why visibility matters so much. Security teams need continuous insight into who and what is accessing critical systems, how sensitive data is moving across the business and where policy gaps exist. Without that level of visibility, organisations are trying to defend a supply chain they cannot fully see."

Collaboration is key for cyber resilience

Continuity requires integrating critical suppliers into an organisation’s internal incident response strategy while enforcing strict access controls. 

According to Chris, business leaders must treat supplier resilience as ā€œpart of their own resilience, not somebody else's problemā€ by inviting key vendors to rehearse joint business continuity exercises and offering technical guidance where in-house skills are lacking.

In a world where one weak link can create enterprise-wide exposure, security has to be built around visibility, verification and control rather than assumed trust.

Max Imbiel, Field CISO, Cloudflare

Actionable technical controls can dramatically reduce exposure when a partner is compromised and this helps to complement operational preparation.

As Max explains: ā€œThe good news is that many of the controls that reduce supply chain risk are practical and immediate: adopt a zero trust approach, verify every access request, apply least privilege, monitor third-party access continuously, and use strong data loss prevention policies to limit the blast radius if a partner or supplier is compromised. 

ā€œIn a world where one weak link can create enterprise-wide exposure, security has to be built around visibility, verification and control rather than assumed trust.ā€

Company portals

Executives