76 percent of companies experienced disruptions caused by external partners with damages sometimes exceeding 10 million dollars, yet only 31 percent conduct joint tests with critical third-party providers.
Formal compliance requirements such as NIS2 or DORA are necessary but not sufficient — organisations that rely on documentation and certifications overlook the reality of attack scenarios and operational failure risks.