Cybersecurity leaders warn supply chain threats now ‘unmanageable’

Cybersecurity leaders warn supply chain threats now ‘unmanageable’

Sixty per cent of security leaders see supply chain risks as unmanageable. A new IO study reveals that confidence in cybersecurity response far exceeds real-world resilience, as 61 per cent of organisations suffered third-party breaches in the past year, driving financial losses and customer disruption across the board.


Security leaders across the U.K. and U.S. say supply chain risks have grown beyond their control, with 60 per cent now describing third-party threats as “innumerable and unmanageable.” The findings come from IO’s latest State of Information Security Report.

Despite widespread concern, 97 per cent of cybersecurity leaders still express confidence in their organisation’s ability to respond to breaches — 61 per cent “very confident.” Yet that assurance contrasts sharply with the reality that 61 per cent reported experiencing a third-party or supply chain attack in the past 12 months.

Recent incidents underscore the systemic nature of such risks. The cyberattack on Jaguar Land Rover disrupted production across multiple manufacturing plants, while the compromise of Collins Aerospace’s MUSE software halted operations at several European airports. Both demonstrate how digital dependencies can ripple through entire networks.

Among those affected, 38 per cent suffered customer, employee, or partner data breaches. Thirty-five per cent incurred financial losses or unplanned costs such as remediation, fines, and legal fees, and one-third experienced temporary system outages or operational disruption. Over a third of organisations hit by data breaches reported customer or partner attrition, while 28 per cent said supplier scrutiny increased in the aftermath.

“Cybersecurity leaders clearly recognise the importance of supply chain security, but many still underestimate how complex and interdependent modern supply networks have become,” said Chris Newton-Smith, CEO of IO. “This confidence needs to be matched by continuous action to avoid the domino effect across networks, impacting customer trust, finances, and operations.”

Despite the impact, only 23 per cent of respondents listed supply chain compromise among their top emerging threats — ranking it below AI misuse, misinformation, and phishing. The imbalance suggests that many organisations still underestimate the potential reach of supplier-originating attacks.

The report also highlights disproportionate exposure among smaller companies. Twenty-eight per cent of cybersecurity leaders at businesses with up to 49 employees reported cascading partner issues after a customer data breach, compared with 21 per cent of large enterprises. IO’s analysis links this to resource constraints, smaller security teams, and less formalised risk processes.

“Attackers increasingly see smaller suppliers as soft entry points into larger targets,” Newton-Smith added. “They may not be the ultimate prize, but they’re often the route into the larger organisations. Securing the entire supply chain is essential for national and commercial resilience.”

Investment in third-party and vendor risk management is rising, with 64 per cent of organisations planning to increase spending in the next year. Among small and mid-sized enterprises, that figure falls to 45 per cent, with many expecting no budget change.

Encouragingly, 80 per cent of businesses have already strengthened vendor risk practices in the past year, and another 17 per cent intend to do so within the next 12 months. IO’s report suggests a growing recognition that resilience must extend beyond technology to include people, processes, and culture.

“Supply chain resilience is now one of the top security priorities for the year ahead,” Newton-Smith said. “To close the confidence gap, leaders must focus on people and process, putting strategies in place to ensure compliance and build a culture of security and resilience across the chain.”


Stories for you

  • Raindrop reunites UK savers with £1bn in lost pensions

    Raindrop reunites UK savers with £1bn in lost pensions

    Raindrop has helped savers recover £1 billion in lost pensions. The pension-finding platform, which partners with major UK financial providers, has traced more than 100,000 missing pots, reconnecting customers with savings worth an average of £11,000 each since launch.


  • How tech is supercharging the North East’s regeneration

    How tech is supercharging the North East’s regeneration

    Technology is redefining regeneration across the UK’s North East region. James Hunnybourne, Executive Chairman at Cybit, explores how AI, digital twins, and sustainable construction are reshaping the region’s economy. With a new AI Growth Zone and major investment underway, the North East is building a smarter, stronger future.


  • ECB to simplify bank rules but hold firm on capital buffers

    ECB to simplify bank rules but hold firm on capital buffers

    The ECB has outlined plans to streamline bank supervision. The European Central Bank moved to simplify oversight for smaller lenders while rejecting calls to loosen capital buffers, underscoring its focus on resilience as the EU’s revised banking framework approaches implementation next year.