High Concern, Low Visibility: Supply Chain Cyber Risk Findings
An ISC² survey of over 1,000 cyber professionals shows that concern about cybersecurity risks in third-party supply chains is widespread. A large portion report past incidents originating from suppliers, yet many lack visibility into their vendors’ broader networks. Key challenges include not knowing who their vendors’ vendors are and needing to “trust but can’t verify” supplier security posture. The top threat types identified are data breaches, malware/ransomware, and vulnerabilities in supplier-provided software. To counter these risks, organizations commonly assess third-party risk on a recurring basis (but some only at onboarding) and require vendor compliance with standards, security audits, multi-factor authentication, and incident-response protocols. Some firms have a formal supply-chain risk program; others rely on contracts or ad hoc methods.
https://www.isc2.org/Insights/2025/11/2025-isc2-supply-chain-risk-survey
Comments
Post a Comment