Supply chain breaches impacted 97% of firms in the past year
New BlueVoyand research finds that supply chain security breaches are increasing


Cyber security breaches that occurred in the supply chain have negatively impacted 97% of firms in the past 12 months, according to a recent BlueVoyant survey.
The firm surveyed 1,200 CIOs, CISOs, and chief procurement officers as part of its research for the Managing Cyber Risk Across the Extended Vendor Ecosystem report, which also found that 93% admitted they had suffered a direct cyber security breach because of weaknesses in their supply chain.
The number of organizations reporting a supply chain of over 1,000 companies more than doubled from 14% in 2020 to 31% in 2021. At the same time, the number of companies reporting 500 vendors or fewer dropped from 29% to 22%. The report said it is possible that supply chains rapidly increased, but it is more likely that companies became more aware of the full extent of their vendor networks.
The survey of IT leaders in organizations with more than 1,000 employees across a range of industries found the average number of breaches experienced in the past 12 months grew from 2.7 in 2020 to 3.7 in 2021 – a 37% year-on-year increase.
It revealed that only 13% of companies said that third-party cyber risk was not a priority, a drop compared to 31% of companies last year. Respondents who said they had no way of knowing when or if an issue occurs with a third-party supplier’s cyber security increased from 31% to 38%.
Additionally, 91% say the budget for third-party cyber risk management is increasing in 2021.
The research revealed that the health care sector exhibited the highest rate of third-party cyber risk awareness, and 55% said identifying risks was a key priority, compared to an average of 42% of all other respondents. However, this sector also reported high breach figures, with 29% reporting six to 10 breaches in the last 12 months, compared to a 19% average across all other respondents.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Manufacturing respondents were least likely to identify supply chain/third-party cyber security risk as a key priority and were most likely to be reporting on an annual basis only, according to the report.
RELATED RESOURCE
Managing security and risk across the IT supply chain: A practical approach
Best practices for IT supply chain security
“Budget increases demonstrate that firms are recognizing the need to invest in cybersecurity and vendor risk management. However, the wide yet consistent array of pain points suggests that this investment is not as effective as it needs to be,” said Adam Bixler, global head of third-party cyber-risk management at BlueVoyant.
“This, tied to the lack of visibility, monitoring, and senior-level reporting, underscores a need for further improvement when approaching third-party cyber risk, to reduce the exposure of data before attackers take advantage of this.”
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Using APIs to rewire supply chains in 2023
In-depth Supply chains are on the mend after breaking down recently, and APIs are helping stakeholders get a better handle on data
By Rich McEachran Published
-
Uber says compromised third-party to blame for data breach
News Vulnerable third-party vendor Teqtivity sparks second major incident for Uber in the space of three months
By Ross Kelly Published
-
SolarWinds hackers strike again with a new “MagicWeb” authentication exploit
News Microsoft warns MagicWeb can abuse admin credentials to hijack AD FS enterprise identity system
By Praharsha Anand Published
-
Former Apple worker alleged to have defrauded company out of $10 million
News The man faces five federal charges after he is said to have exploited his position in Apple's Global Service Supply Chain
By Connor Jones Published
-
KP Snacks supply chain shut down by Conti ransomware attack
News Crippled IT systems are unable to process new orders "safely" and could be down until late-March
By Bobby Hellard Published
-
Spar stores forced to close following supply chain attack
News The UK supermarket chain is working with the NCSC to investigate the incident
By Connor Jones Published
-
Majority of UK's top business leaders are failing to manage supply chain security risks
News New findings from a DCMS review have sparked concern in government which could see new laws introduced to protect Britain's digital supply chains
By Connor Jones Published
-
Managing security and risk across the IT supply chain: A practical approach
Whitepaper Best practices for IT supply chain security
By ITPro Published