CyberSecurity SEE

One in Four Businesses Targeted by Cyber Attacks via Supply Chain in the Past Year

Recent findings from Databarracks, a specialist in business continuity and disaster recovery, reveal that a significant percentage of UK businesses, specifically 26%, have encountered cyber incidents stemming from their supply chains within the past year. This alarming statistic underscores a pressing issue as organizations navigate the vulnerabilities associated with third-party suppliers. Despite their awareness of potential risks, nearly half of the surveyed companies—48%—admitted to maintaining relationships with suppliers even when aware of existing resilience or security concerns.

The insights come from the Data Health Check 2026, Databarracks’ annual survey which gathers opinions from 500 IT decision-makers across the UK. This survey has been an influential tool for tracking IT resilience since its inception in 2008. The latest report offers a stark portrayal of businesses that are increasingly aware of the dangers lurking within their supply chains, yet often feel powerless to mitigate these threats effectively.

A major barrier that emerged from the research is the heavy reliance on certain suppliers, with over a quarter of respondents—26%—acknowledging that dependence on suppliers hampers their ability to improve organizational resilience. As many companies find themselves bound to specific suppliers, alternatives become scarce, complicating their efforts to enhance security measures.

In what is becoming a standard practice, nearly nine out of ten organizations—89%—now conduct supplier resilience assessments during the onboarding process. Furthermore, the majority of these businesses (61%) commit to performing assessments on an annual, quarterly, or continuous basis. However, despite this due diligence, the risks remain prevalent once a supplier relationship is established. Notably, “supply chain vulnerabilities” has been identified as one of the top three IT resilience challenges that organizations expect to grapple with over the next five years, standing behind only AI-driven cyber threats at 46% and ransomware attacks at 26%.

The data demonstrates a clear link between acknowledged risks and actual incidents. Organizations that knowingly continued partnerships with high-risk suppliers faced dire consequences; 43% of those enterprises reported experiencing a cyber incident, a stark contrast to the mere 10% of organizations that refrained from engaging with risky suppliers.

Chris Butler, Resilience Director at Databarracks, commented on the findings, emphasizing that supply chain resilience remains a crucial vulnerability within the defenses of UK businesses. He stated, “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses. The majority are aware of the threat, yet attackers continue to exploit these vulnerabilities. The consequences of a problem at a key supplier can have a ripple effect that severely impacts businesses throughout the supply chain.”

Butler further argued that organizations often lack a comprehensive understanding of the complexities inherent in their supply chains. While companies may identify their core suppliers, visibility into broader supplier networks tends to diminish. He criticized the conventional, checklist-based approach to supplier assessment, suggesting that it fosters a false sense of security rather than igniting genuine resilience.

To foster improvement, Butler recommended that businesses go beyond superficial assessments and take direct responsibility for managing supplier risks. “To truly manage your supply chain continuity, it’s essential to gain visibility into the situation. Leaders should view supplier resilience as an extension of their own operations, rather than an external concern. The principle remains: treat your critical suppliers as you would your own business,” he added.

The report also emphasizes a collaborative approach, particularly when dealing with smaller or less mature suppliers that lack feasible replacement options. Butler suggests organizations help their suppliers develop necessary business continuity skills and include them in continuity exercises, enabling joint rehearsals in the face of potential disruptions.

Jamie Akhtar, CEO and Co-Founder of CyberSmart, echoed Butler’s observations. He stressed the substantial consequences of supply chain attacks on organizations of all sizes and highlighted the troubling statistic that almost half of businesses are knowingly engaging with suppliers exhibiting security weaknesses. “This research emphasizes the complexity for organizations trying to remain secure. It’s imperative that businesses not only safeguard their own operations but also attend to the security and resilience of their suppliers,” he noted.

Akhtar urged organizations, particularly small and medium-sized enterprises, to include suppliers in their security framework. He advocated for assessing third-party risks pre-onboarding, controlling access to critical systems, enforcing multi-factor authentication, and maintaining tested backups. “Regular supplier reviews and shared incident-response plans can significantly alleviate disruptions in the event of a partner’s security breach,” he concluded.

The findings regarding supply chain integrity are a part of a broader analysis in the Data Health Check 2026 report, which identifies a shift towards increased vigilance among organizations. The study reveals that 65% of businesses now perceive serious cyber-attacks as a potential threat to their survival. Cybersecurity remains a primary source of IT downtime for the fourth consecutive year, with 30% citing it as their leading cause of outages.

However, there are signs of optimism; business continuity planning has reached an all-time high, with 90% of organizations implementing a plan, and four out of five maintaining current versions. Furthermore, resilience against ransomware is improving, as evidenced by a decline in the proportion of affected organizations that chose to pay ransoms.

The overall findings from Databarracks indicate a growing recognition among organizations of the need to integrate IT and business resilience, highlighting that modern incidents—often emanating from supply chains—do not respect traditional boundaries in cyber security, IT operations, business continuity, and executive decision-making.

Source link

Exit mobile version