The point: Supply chain protection becomes a strategic priority – organisations must involve third-party providers on a least-information basis and integrate their control mechanisms into their cyber-resilience strategy.
Organisations are more dependent than ever on suppliers and service providers, but the majority do not implement adequate security controls. 60 percent of companies experienced outages caused by third parties in the past year; only 34 percent trust their supply chain control mechanisms.
The classic security perimeter no longer exists. Modern organisations are embedded in ecosystems of suppliers, SaaS platforms and external service providers – and these mutual dependencies become a threat. A study titled “The Ripple Effect: A Hallmark of Cybersecurity” shows that 68 percent of IT leaders say they are more dependent on third parties than ever before. Yet fewer than half of organisations have implemented corresponding security controls.
The consequences are real: 60 percent of organisations experienced an outage caused by third-party providers in the past year. 63 percent expect another incident within the next twelve months. Particularly critical: only 42 percent include external service providers and freelancers in their cyber-resilience strategy, and only 34 percent trust their supply chain control mechanisms. If a supplier is compromised, a chain reaction threatens to cripple operations, expose sensitive data or disrupt critical services.
The risks are multifaceted: In the classic scenario, the compromised supplier becomes the entry point for lateral attacks. If a service provider with remote access is compromised, the attacker gains direct access to the corporate environment via network credentials. A second threat scenario is data disclosure by third parties – many organisations unknowingly grant partners oversized permissions: entire databases instead of individual records, system-wide access instead of isolated functions. If the partner is attacked, hackers immediately gain access to extensive datasets, intellectual property and customer data.
For CISOs, a central requirement emerges: the least-privilege principle must be supplemented by a least-information principle. Third-party providers should only have access to those data and systems they actually need for their specific function – nothing more. At the same time, regulatory requirements such as the NIS2 Directive demand an expanded cyber-resilience strategy that also includes the supply chain. With the deployment of autonomous AI agents in organisations, an additional risk dimension emerges: these synthetic employees require data and system access and become a rapidly growing group of “contractors” for whom clear security protocols are required.
Source: www.it-daily.net · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.