Cybersecurity Risks: One in Four Businesses Hit by Supply Chain Attacks

In the past year, a significant proportion of businesses have fallen victim to cyber attacks that infiltrated their operations through their supply chains. According to recent findings from Databarracks's Data Health Check 2026, a staggering 26% of businesses reported suffering from cyber incidents caused by vulnerabilities in their supply chains.

The research highlights a troubling trend: almost half of the surveyed organizations are aware of the risks associated with their suppliers but still choose to do business with them despite security concerns. Specifically, 48% of IT decision-makers admitted to continuing relationships with suppliers that display known resilience or security issues. This data raises essential questions about the decision-making processes at these organizations.

A major barrier to improving supply chain resilience has been identified as the dependency on suppliers. Around 26% of respondents cited this reliance as a challenge that hinders their capability to bolster their security posture. Moreover, it's revealed that a majority of businesses—89%—conduct resiliency assessments of their suppliers at the onboarding stage, with 61% performing annual, quarterly, or continuous evaluations.

However, the reality seems far from satisfactory. The findings indicate that an alarming 43% of organizations working with risky suppliers have encountered cyber incidents. In contrast, only 10% of those who do not engage with such suppliers have reported similar experiences. This disparity underscores the critical importance of thorough vetting and ongoing evaluations of supplier security.

As cyber threats evolve, the research indicates that organizations view supply chain vulnerabilities as one of the top three challenges for the next five years, alongside AI-driven cyber threats and ransomware. Approximately 23% of respondents stated that they regard supply chain security as a primary concern, emphasizing the urgent need for improved measures in this area.

Chris Butler, Resilience Director at Databarracks, commented on these findings: "This year, the results underscore that supply chain resilience remains a pressing issue for many businesses. It is essential to understand that when a critical supplier faces challenges, the ripple effects can be extensive throughout the entire supply chain."

Despite the earnest intentions of assessing supplier resilience, Butler notes that many organizations struggle to grasp the complexity of their supply chains. While companies might keep track of their primary suppliers, a lack of visibility often leads them to underestimate the potential risks posed by secondary suppliers. He argues that instead of merely ticking boxes on compliance questionnaires, organizations should delve deeper into the reality of their supply chain dynamics.

Butler continued, "To effectively manage supply chain continuity, leaders must gain complete visibility into their suppliers' security status. They should consider the resilience of their critical suppliers as integral to their overall business resilience, rather than viewing it as a separate issue. It’s crucial to treat your suppliers with the same priority as you would for your business."

When faced with a lack of viable alternatives, Butler recommends that organizations assist their suppliers in developing internal business continuity capabilities. Including suppliers in business continuity exercises can foster a collaborative approach to managing disruptions. He emphasized that rehearsing responses to potential crises together is key to ensuring long-term resilience.

The full report, Data Health Check 2026, made available by Databarracks, sheds light on the precarious state of cybersecurity and vendor relationships in today's business environment, illuminating the need for proactive measures and comprehensive assessments of suppliers to safeguard organizational operations.

Databarracks continues to position itself as a leader in business and technology resilience, providing innovative solutions that enable organizations to navigate the complexities of cyber threats and maintain operational stability. With a commitment to supporting businesses through every layer of resilience, they strive to ensure that organizations can withstand and recover from modern cyber threats effectively.

Topics Policy & Public Interest)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.