BlueVoyant, a pioneering cyber defense company published the findings of its The State of Supply Chain Defense Annual Global Insights report.

Currently, in its fifth year, the UK findings reveal that tackling supply chain cyber risk continues to be a pressing and persistent challenge. Ninety-five percent of surveyed UK organizations experienced negative impacts from cyber security incidents in their supply chain, which is significantly higher than the 81% of global respondents who indicated the same.

Key highlights

Other key highlights from UK respondents include:

  • 34% said they have no way of knowing when a cyber security incident occurs within their supply chain, greater than the global average of 30%.
  • 66% said that third-party cyber security risk management is either not a priority or somewhat of a priority, a slight decrease from 68% who said this in 2023.
  • 92% said their budget increased for third-party cyber security risk management programs, compared to 86% globally.

Risk management

"UK businesses continue to struggle with the pressing challenge of mitigating supply chain and third-party cyber risks," said Robert Hannigan, BlueVoyant head of international business Europe and Middle East, and former director of GCHQ.

"Despite the risks, awareness and prioritization of these issues remain low, while breaches continue to happen. The importance of managing risk across the supply chain cannot be understated. Not just from a brand and security perspective, but also with growing EU regulations such as NIS2 and DORA which call for better risk management, particularly across the supply chain, this is a strategic imperative."

Opinion Matters study

The research was conducted in 11 countries across North America, Europe, and Asia Pacific

The study was carried out by an independent market research organization, Opinion Matters, which surveyed 2,100 C-suite leaders responsible for supply chain and cyber risk management.

The research was conducted in 11 countries across North America, Europe, and Asia Pacific. Three hundred respondents were from the UK, representing organizations with more than 1,000 employees across a range of industries.

Decreasing supply chain cyber risk monitoring and visibility

The research highlights that monitoring frequency in the UK is not improving it has decreased. In 2024, 34% of businesses said they monitor third-party supplier risk monthly or more frequently, which is a drop from 46% in 2023.

This lack of regular monitoring is likely having a big impact, as 95% of UK organizations say they were negatively affected by supply chain cyber incidents in the past 12 months.

Lack of expertise, technology, and resources

34% of the UK respondents indicated they have no way of knowing if an issue arises with a third-party

Additionally, 34% of the UK respondents indicated they have no way of knowing if an issue arises with a third party, compared to 27% globally. This is likely because 57% of respondents said they don't assess all vendors, primarily due to a lack of expertise, technology, and resources.

UK respondents are also less likely to use solutions that provide autonomous visibility into the cyber risks of their supply chain ecosystem, with only 11% saying they do this, compared to 15% globally.

Disconnect between budgets

The good news is that 92% of UK organizations are reporting budget increases with their third-party cyber security risk management programs.

"Prioritisation of third-party cyber security risk in UK organizations isn't changing as much as it should be," said Joel Molinoff, BlueVoyant's global head of supply chain defense.

Enforcement and compliance

"Organizations must step up their efforts to proactively monitor their third parties and drive mitigation of critical risks with their vendors. Globally we are seeing a shift from third-party risk management identification to enforcement and compliance."

"The budget increases should help the UK's organizations move toward more third-party cyber risk maturity like other regions."

Understand how converged physical and cybersecurity systems can scale protection.

In case you missed it

Which Vertical Markets Have The Greatest Growth Potential For Security?
Which Vertical Markets Have The Greatest Growth Potential For Security?

To serve various vertical markets and industries effectively, security professionals must recognize that each sector has unique assets, risks, compliance requirements, and operatio...

eCLIQ Enhances Security At Marin Hospital Of Hendaye
eCLIQ Enhances Security At Marin Hospital Of Hendaye

The Marin Hospital of Hendaye in the French Basque Country faced common challenges posed by mechanical access control. Challenges faced Relying on mechanical lock-and-key technol...

What’s Behind (Perimeter) Door #1?
What’s Behind (Perimeter) Door #1?

A lot has been said about door security — from reinforced door frames to locking mechanisms to the door construction — all of which is crucial. But what security measur...