Skip to main content

Loading component...

ISC2 survey reveals that organizations of all sizes and sectors struggle with a shared challenge: a lack of visibility across their expansive network of third-party vendors and partners.

Levels of Concerns about Supply Chain Security | A Closer Look at the ResultsThe State of Supply Chain Cybersecurity IncidentsNuances Behind the NumbersThe Biggest ChallengesTop Areas of ConcernMitigating Supply Chain Security RiskTaking Back Control Through ActionA Sector Snapshot of the Most Stringent ControlsMixed Approaches to Supply Chain Risk ManagementMaturity of Incident ResponseSupply Chain Security Considerations for OrganizationsMethodologyRelated Insights

Any organization operating in the digital economy today is no stranger to supply chain risk. After 2020’s powerful one-two punch of physical (pandemic-fueled breakdowns) and digital (e.g., the SolarWinds attack) disruptions, adopting a deeper focus on supply chain stability and cybersecurity has become a must-have for mature risk management programs.

Recognizing the escalating importance of supply chain cybersecurity, ISC2 conducted a global survey of 1,062 cybersecurity professionals to gauge the current state of this pressing topic and its effects on the cybersecurity workforce and operations. Respondents worked in organizations of varying sizes: small (1–499 employees), medium (500–2,499), large (2,500–4,999) and enterprise (5,000+). 

Levels of Concerns about Supply Chain Security

The survey found that 70% of respondents said their organizations are highly (i.e., very or extremely) concerned about cybersecurity risks in their supply chains. Concern is highest among respondents from enterprise organizations, where 82% report high levels of concern. In comparison, 57% of respondents from both small and medium organizations share this level of concern.

Supply Chain Concerned About Risk

A Closer Look at the Results

Organizations that have experienced a cybersecurity incident originating from a third-party vendor or supplier are significantly more likely to report high levels of concern (75% are very or extremely concerned versus 63% among those without such incidents).

Similarly, organizations that provide software, digital services or managed solutions to other businesses are more likely to express concern compared to those that do not (72% are very or extremely concerned vs. 65%, respectively).

Concern is highest among certain sectors: 82% of financial services organizations and 81% of military and military contractor organizations report being very or extremely concerned, compared to 70% across all organizations. Healthcare, an increasingly digitalized sector reliant on an extensive third-party supply chain, is also facing significant pressure; 67% report being very or extremely concerned about cybersecurity risks in their supply chain.

Loading component...