48% of Breaches Now Originate in the Supply Chain. It’s Time to Admit the Industry’s Approach Has Failed.

By Jason Thompson, CEO and founder, Factor [ Join Cybersecurity Insiders ]
supply-Chain-CSI

For more than two decades, organizations have invested heavily in third-party risk management programs, vendor assessments, security questionnaires, compliance reviews, and monitoring platforms. The underlying assumption has always been the same: if organizations could gain enough visibility into their suppliers, they could reduce supply chain risk. Yet according to Verizon’s latest Data Breach Investigations Report, supply chain-related breaches now account for 48% of all breaches. Despite years of investment and billions of dollars spent on monitoring, assessments, and compliance programs, nearly half of successful attacks now involve a third party somewhere in the victim’s supply chain.

At some point, the industry has to confront an uncomfortable reality. The current approach isn’t working.

This isn’t because organizations lack visibility. Most large enterprises have more visibility into their suppliers than ever before. They maintain vendor inventories, conduct assessments, monitor external attack surfaces, review security certifications, and consume a constant stream of risk intelligence. The problem isn’t visibility. It’s execution.

Where the breakdown actually happens

Consider a common scenario. A security team identifies a critical vulnerability affecting a supplier. The finding is legitimate. The business impact is understood. The risk has been identified. What happens next? Who owns remediation at the supplier? Is there a trusted security contact? Has the issue reached the right team? Does the supplier have the resources to investigate and remediate the finding? How is progress tracked? How is resolution verified?

These questions expose the fundamental weakness in today’s supply chain cyber risk programs. Most organizations have built systems for detecting risk. Far fewer have built systems for driving outcomes. The result is an industry optimized for producing findings rather than reducing risk. Organizations generate alerts, suppliers receive notifications, dashboards are updated, and reports are delivered to leadership. Yet the actual state of remediation often remains unknown.

The cybersecurity market responded to supply chain risk by building more monitoring. Security ratings platforms emerged. Attack surface monitoring became mainstream. Continuous monitoring tools promised real-time visibility into vendor risk. These technologies created valuable insight, but they did not solve the operational challenge. Knowing a supplier has a vulnerability and ensuring that vulnerability is remediated are fundamentally different problems. A completed questionnaire cannot remediate a vulnerability. A SOC 2 report cannot coordinate incident response. A security rating cannot establish accountability. The industry built visibility at scale but never built the operational infrastructure required to act on that visibility.

The problem becomes even more difficult once organizations look beyond direct suppliers. Most supply chain programs focus on third parties because those are the organizations they contract with directly. But modern supply chains extend far beyond procurement systems. Critical business operations depend on cloud providers, software components, identity platforms, managed service providers, infrastructure providers, subcontractors, and countless downstream dependencies. Many of the most significant risks no longer originate with direct suppliers at all. They emerge from shared dependencies.

A vulnerability in a widely used software platform can impact thousands of organizations simultaneously. A cloud outage can disrupt entire industries. A compromised identity provider can create cascading consequences across multiple sectors. These events expose a hard truth: organizations cannot stop at third parties if they want to understand supply chain risk. They need visibility into the broader ecosystem where dependencies converge and systemic risk accumulates. The challenge is that no individual company can realistically map, monitor, and operationalize risk across the deeper layers of the global supply chain. The scale is simply too large.

Yet the industry’s current model assumes exactly that. Every organization is expected to build its own supply chain cyber risk function. Every organization sends questionnaires. Every organization performs assessments. Every organization attempts to identify the same risks, establish the same supplier relationships, and coordinate the same remediation efforts. Thousands of security teams are performing nearly identical work against the same suppliers. Suppliers are overwhelmed by requests. Information becomes fragmented. Effort is duplicated across the ecosystem. Most importantly, the model does not improve execution. It simply distributes the burden of execution across thousands of organizations that are all trying to solve the same problem independently.

This is the industry’s fundamental mistake. It treated a network problem like a company problem.

Supply chains are shared systems. Dependencies are shared. Risks are shared. Points of failure are shared. Yet the industry continues to approach supply chain cyber risk as if every organization should independently assess, monitor, and manage the same ecosystem. The result is duplication, fragmentation, and a growing inability to respond effectively to systemic threats.

The cybersecurity community already embraces collective defense in other areas. Threat intelligence sharing, coordinated vulnerability disclosure, fraud prevention networks, and ISACs all exist because organizations recognize that certain problems are too interconnected to solve alone. Supply chain cyber risk belongs in the same category. Organizations need shared operational infrastructure capable of identifying risk, establishing trusted communication channels, coordinating remediation, validating outcomes, and responding collectively when systemic issues emerge. This is not primarily a technology challenge. It is a coordination challenge.

Other industries have already solved similar problems through shared operating models. Financial markets rely on exchanges and clearinghouses because it is neither efficient nor scalable for every participant to independently manage every counterparty relationship. Shared infrastructure creates visibility, standardization, coordination, and resilience across the entire ecosystem. Supply chain cyber risk has reached a similar inflection point. Instead of thousands of organizations independently attempting to assess, notify, investigate, coordinate, and remediate the same risks, the industry should begin building shared infrastructure for execution.

The first generation of supply chain cyber risk focused on assessment. The second generation focused on monitoring. The third generation must focus on execution. The industry has spent years improving visibility while supply chain-related breaches continue to climb. That should tell us something. The challenge is no longer identifying risk. The challenge is coordinating action across a complex, interconnected ecosystem.

If nearly half of all breaches now originate in the supply chain, the verdict on the current model is becoming increasingly difficult to ignore. The future of supply chain cyber risk will not be defined by more questionnaires, more assessments, or more monitoring platforms. It will be defined by the industry’s ability to execute collectively. The question is no longer whether organizations can see the risk. The question is whether they are willing to solve it together.

 

Join our LinkedIn group Information Security Community!

No posts to display