Supply Chain vs Insider Threat

Supply Chain

75

statistics from 27 sources

Insider Threat

107

statistics from 13 sources

Latest Supply Chain

66% of incidents involve the supply chain or a third party, up from 45% in 2024.

Supply ChainThird-Party Risk

In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.

Supply ChainTyposquattingAI Code Agents

Top AI-related cybersecurity concerns are data leakage through copilots and agents (22%), third-party and supply chain risks (21%), evolving regulations (20%), shadow AI (18%), and prompt injection attacks (18%).

CybersecuritySupply Chain RiskAI Risk

Confidence in data security falls to 40% when data passes through third-party provider networks.

Data SecurityThird-Party RiskNetwork SecurityEnterprise

32% of leaders do not know the locations of all of their data centers, rising to 49% when including third-party providers.

Data VisibilityThird-Party RiskData SecurityData CentersEnterprise

11% of leaders say they are aware of definite weak points when their data travels across third-party infrastructures.

Third-Party RiskData SecurityEnterprise

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

Third-Party Software SecuritySoftware Supply ChainSBOM ValidationVulnerability Management

70% of organizations experienced at least one material third-party cyber incident in the past year.

Third-Party RiskThird-Party Cyber Incident

97% of organizations reported negative impacts from supply chain breaches over the past twelve months, an increase from 81% in 2024.

Supply chain breach

47% of retail executives reported having very low to moderate visibility into their software supply chain.

RetailSoftware supply chain

33% of leaders at financial services firms say they are unprepared to recover effectively from a Supply chain attack.

Financial services RecoverySupply chain attack

Supply chain attacks against healthcare organizations decreased significantly from 68% in 2024 to 44% in 2025.

HealthcareSupply chain attack

44% of healthcare organizations say their organizations experienced an attack against its supply chains, which is a significant decline from 68% in 2024.

HealthcareSupply chain attack

Healthcare organizations that experienced supply chain attacks, on average, experienced four supply chain attacks in the past two years.

HealthcareSupply chain attack

57% of healthcare organizations say their organizations are very or highly vulnerable to supply chain attacks.

HealthcareSupply chain attack
View all Supply Chain

Latest Insider Threat

60% of insider threat incidents involved personal cloud application instances in 2025.

Insider ThreatCloud ApplicationsPersonal Cloud Application Instances

93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.

Human RiskInsider Threats

Malicious insiders accounted for incidents at 36% of organizations.

Insider ThreatsRisk ManagementMalicious Insiders

58% of organizations attribute their most significant data loss events to careless employees or third-party contractors.

Proofpoint2025 Data Security Landscape·6mo ago
Data lossInsider riskEmployeesThird-party contractors

Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskSensitive dataSaaSShadow IT

77% of organizations experienced insider-driven data loss in the past 18 months.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData loss

43% of security professionals are concerned about disgruntled employees.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskDisgruntled employees

55% of security professionals are concerned about departing employees.

Fortinet2025 Insider Risk Report·6mo ago
Insider risk

• 21% of organizations faced more than 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData loss

17% of insider incidents involved personal healthcare information.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData lossHealthcare information

73% of security professionals are concerned about careless, negligent, or uninformed employees.

Fortinet2025 Insider Risk Report·6mo ago
Insider risk

53% of insider incidents involved customer records.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData lossCustomer records

47% of insider incidents involved personal information or Personally Identifiable Information (PII).

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData lossPII

12% of detected insider incidents could not be attributed, underscoring challenges in detection.

Fortinet2025 Insider Risk Report·6mo ago
Insider risk

40% of insider incidents involved business-sensitive financial and strategic information.

Fortinet2025 Insider Risk Report·6mo ago
Insider riskData lossFinancial data
View all Insider Threat