The survey of 500 IT decision-makers highlights a paradoxical landscape where awareness of risk does not translate into decisive action. A primary obstacle remains the lack of viable alternatives, with over a quarter of firms citing deep-seated dependence on specific vendors as a major barrier to upgrading their defensive posture. Companies that knowingly maintain relationships with vulnerable suppliers are four times more likely to experience a breach, with 43% of these firms reporting incidents compared to just 10% of those that vet their partners more strictly.
In section Releases
Supply Chain Vulnerabilities Fuel Surge in Corporate Cyber Attacks
One in four businesses suffered a cyber incident originating within their supply chain over the past year, according to the Data Health Check 2026. Despite this clear and present danger, nearly half of organizations admit they continue to work with suppliers even after identifying significant security or resilience concerns.

Chris Butler, Resilience Director at Databarracks, argues that traditional compliance questionnaires offer little more than a false sense of security. He suggests that businesses must move beyond tick-box exercises and integrate critical suppliers into their own continuity planning. By including vendors in joint response rehearsals, firms can address the visibility gaps that often leave them exposed to the cascading effects of a third-party failure. With supply chain risks now ranking among the top three challenges for the next five years, sitting behind only AI-driven threats and ransomware, the need for integrated resilience has never been more urgent.
Comments (0)
No comments yet. Be the first!