A new report from SecurityScorecard has revealed a ‘growing crisis’ in supply chain cybersecurity, with five in six organizations now at risk due to immature security practices. The 2025 Supply Chain Cybersecurity Trends Survey, based on responses from nearly 550 CISOs and security leaders worldwide, highlights a significant gap between awareness and action when it comes to third-party cyber risk.
According to the report, 88% of cybersecurity professionals are concerned about supply chain threats, yet only 26% of organizations have incident response capabilities built into their supply chain cybersecurity programmes. Most continue to rely on static assessments and cyber insurance, which fail to address the dynamic and fast-evolving nature of supply chain attacks.
Key findings include:
- Over 70% of organizations experienced at least one material third-party cyber incident in the past year.
- 79% of businesses monitor less than half of their nth-party supply chains.
- Nearly 40% cite data overload and an inability to prioritise threats as their biggest challenge.
Supply chain cyberattacks are no longer isolated incidents; they’re a daily reality. Yet breaches persist because third-party risk management remains largely passive, focused on assessments and compliance checklists rather than action. This outdated approach fails to operationalize the insights it gathers. What’s needed is a shift to active defense: supply chain incident response capabilities that close the gap between third-party risk teams and security operations centers, turning continuous monitoring and threat intelligence into real-time action. Static checks won’t stop dynamic threats – only integrated detection and response will.
Ryan Sherstobitoff, Field Chief Threat Intelligence Officer at SecurityScorecard
Based on the survey findings, SecurityScorecard offers these recommendations for security teams:
- Integrate threat intelligence across vendor ecosystems: to stay ahead of active campaigns targeting the supply chain, organizations should connect threat intelligence feeds to their vendor risk management workflows. This integration enables teams to identify threats like ransomware or zero-day exploits in real time and assess their potential impact on the broader ecosystem.
- Establish a dedicated supply chain incident response workflow: organizations should define roles, responsibilities and communication pathways across teams to ensure that risks identified in the supply chain are resolved quickly and consistently. These processes should be regularly tested and refined as part of a broader incident response strategy.
- Implement vendor tiering: not all vendors or risks carry equal weight. Security teams should prioritize based on potential business impact, likelihood of exploitation and criticality to operations. Mapping the supply chain to identify high-risk dependencies and single points of failure allows for more strategic allocation of resources and focused risk mitigation efforts.
- Foster a culture of shared accountability and resilience: supply chain cybersecurity isn’t just a risk or IT issue. It requires collaboration across procurement, legal, operations and leadership. Embed security into decision-making processes, align on resilience goals and ensure teams are educated and measured against clear, shared metrics.






