97% of cybersecurity leaders told a recent IO survey that they were confident in their breach response, with 61% describing themselves as ‘very confident’. This confidence contrasts with the 60% of respondents who admitted that security risks originating from third parties and supply chain partners are ‘innumerable and unmanageable’.
The above findings are from The State of Information Security Report by IO.
Among those who suffered a third-party or supply chain attack, 38% experienced breaches involving customer, employee, or partner data, 35% suffered financial losses or unplanned costs (e.g. remediation, fines, or legal fees), and 33% faced temporary system outages or operational disruption. More than a third (36%) of organizations that suffered a customer data breach said they had experienced customer or partner churn, or loss of trust, as a result, while 28% faced heightened scrutiny from partners or suppliers.
“Cybersecurity leaders clearly recognise the importance of supply chain security, but many still underestimate how complex and interdependent modern supply networks have become,” said Chris Newton-Smith, CEO of IO. “This confidence needs to be matched by continuous action to avoid the domino effect across networks, impacting customer trust, finances, and operations.”
Despite the growing risk, only 23% of respondents ranked supply chain compromise among their top emerging threats, placing it below AI misuse, misinformation, and phishing. This suggests that while investment is rising, supply chain risk is still underestimated relative to its potential impact.
Encouragingly, 80% of organizations have already strengthened third-party and vendor risk management practices in the last 12 months, with a further 17% planning to do so within the next year. Meanwhile, 21% of leaders list strengthening vendor and third-party risk management among their top cybersecurity priorities for the next 12 months, reflecting a clear shift toward long-term resilience planning.
“Supply chain resilience is now one of the top security priorities for the year ahead, but this needs to be embedded within the organization. To close the confidence gap, leaders must focus on people and process, putting strategies in place to ensure compliance and build a culture of security and resilience across the chain to avoid any weak links,” Newton-Smith added.






