DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

Databarracks Report: 26% of Firms Hit by Supply Chain Attacks

Originally published on CyberNetSec.

Executive Summary

The "Data Health Check 2026" report from IT resilience firm Databarracks reveals that supply chain attacks remain a pervasive threat, with one in four (26%) businesses experiencing a cyber incident originating from a supplier in the last 12 months. The survey of 500 IT decision-makers in the UK uncovered a dangerous paradox: while businesses recognize supply chain vulnerabilities as a top threat, nearly half (48%) admit to working with suppliers despite having known security concerns. This high-risk behavior was strongly correlated with being breached, as these firms were four times more likely to suffer a supplier-related incident. The findings highlight a critical gap between risk awareness and operational practice in third-party risk management.


Regulatory Details

This article is based on a survey report, not a new regulation. However, the findings have significant implications for compliance with regulations like GDPR, which mandate that data controllers are responsible for the security of data processed by their third-party suppliers (data processors).

The report's key findings include:

  • Prevalence of Attacks: 26% of surveyed organizations were impacted by a supply chain cyberattack in the past year.
  • High-Risk Behavior: 48% of IT leaders knowingly continued working with suppliers despite security or resilience concerns.
  • Increased Likelihood of Breach: Companies working with risky suppliers were over four times more likely to be breached via their supply chain (43% vs. 10%).
  • Primary Barrier: "Dependence on suppliers" was cited by 26% of respondents as the main reason for not being able to switch to more secure partners.
  • Awareness vs. Action: While 89% of companies assess supplier resilience at onboarding, the high rate of risky partnerships suggests these assessments are not always acted upon.

Affected Organizations

The survey targeted 500 IT decision-makers in the United Kingdom, so the direct findings apply to UK businesses. However, the trends identified are globally relevant and affect organizations of all sizes and industries that rely on external suppliers for software, hardware, or services.

Compliance Requirements

To mitigate the risks highlighted in the report and align with best practices and regulatory expectations (like GDPR's Article 28), organizations must implement a robust Third-Party Risk Management (TPRM) program. Key requirements include:

  1. Due Diligence: Conduct thorough security and resilience assessments of all potential suppliers before onboarding. This should include reviewing certifications (e.g., ISO 27001, SOC 2), penetration test results, and data processing agreements.
  2. Contractual Obligations: Ensure contracts include strong cybersecurity clauses, right-to-audit provisions, and clear requirements for incident notification.
  3. Continuous Monitoring: Do not rely on point-in-time assessments. Implement a program for continuous monitoring of suppliers' security posture using external scanning tools, questionnaires, and regular reviews.
  4. Risk-Based Tiering: Classify suppliers based on the criticality of the service they provide and the sensitivity of the data they access. Apply more stringent controls and monitoring to high-risk suppliers.

Impact Assessment

The business impact of ignoring supply chain risk is starkly illustrated by the report. The 43% breach rate for companies that accept risky suppliers demonstrates a direct correlation between policy and negative outcomes. A supply chain breach can lead to:

  • Data Breaches: Loss of sensitive corporate or customer data held by a supplier.
  • Operational Disruption: An outage at a critical supplier can halt business operations.
  • Reputational Damage: Being associated with a breach, even if it originated with a third party, damages customer trust.
  • Regulatory Fines: Regulators hold organizations accountable for the security failures of their suppliers.

The report indicates a difficult business reality where dependence on a single or specialized supplier can force companies into accepting risks they know are significant.

Compliance Guidance

  1. Elevate TPRM to a Board-Level Issue: Secure executive buy-in to empower IT and security teams to make risk-based decisions, including vetoing or terminating high-risk supplier relationships.
  2. Develop an Exit Strategy: For critical suppliers where there is high dependence, proactively develop an exit or transition plan. Even if never used, the plan provides leverage and a fallback option.
  3. Automate Monitoring: Use TPRM platforms and security ratings services to automate the continuous monitoring of your suppliers' external attack surface.
  4. Collaborate with Suppliers: Instead of simply accepting risk, work with suppliers to create a joint plan for improving their security posture. Tie this to contract renewals and commercial incentives.

Top comments (0)