Supply Chain vs Insider Threat

Supply Chain

165

statistics from 64 sources

Insider Threat

166

statistics from 28 sources

Latest Supply Chain

Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.

Cloud SecurityThird-Party RiskRansomwarePreparadnessCyber Resilience

Half of organisations are making changes to vendor, third-party, and supply chain risk management, while 49% are making changes to cyber insurance, incident response, and crisis management.

Supply Chain RiskIncident ResponseCyber InsuranceCrisis Management

Six previously resolving MCP hostnames were unregistered and available for purchase for $4 to $12 per year.

Domain SecuritySupply Chain RiskAI Infrastructure

21% of financial services organizations fully segment third-party access with enforced policy controls.

Third-Party RiskAccess ControlNetwork SecurityFinancial Services

37% of security leaders cited "detecting more than we can fix" as their organization's single biggest obstacle to improving software supply chain security

Software Supply Chain SecuritySupply ChainVulnerabilities

54% of CVE instances observed in third-party production code come from CVEs published more than a year ago.

Contrast SecurityAppSec Overflow 2026·1mo ago
Third-Party RiskVulnerability ManagementSoftware Supply ChainCVEs

Small and midsize companies carry 414 unsanctioned AI tools per 1,000 employees.

AI AdoptionThird-Party RiskAI ToolsAI Risk

79% of third-party applications are authorized.

Third-Party RiskSaaS Governance

31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries.

ManufacturingUKSupply ChainCyber Incident

30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.

ManufacturingUKSupply ChainCyber Incident

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Supply chain attacks generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·2mo ago
Supply ChainVictim NoticesData Breaches

Organisations that knowingly work with risky suppliers are more than four times as likely to experience a supplier-originated cyber incident.

Data Health Check 2026Databarracks·2mo ago
Third-Party RiskSupply Chain
View all Supply Chain→

Latest Insider Threat

68% of business admins say employees entering sensitive data into AI is their biggest concern.

Data SecurityInsider RiskAI Risks

48% of security leaders rank AI agents operating with excessive, compromised, or unintended access as the greatest threat to their organization, while 28% rank external threat actors, 12% rank compromised insiders, and 12% rank malicious insiders.

Agentic AIInsider RiskAccess Control

47% of enterprise identity-based attacks are discovered manually: 22% via coworker reports, 15% via internal audits, and 10% via external notifications

Incident DetectionInternal ReportingHiring FraudInsider Threat

Prior to day one, HR leaders claim ownership of identity risk in 53% of cases while IT and security teams claim 17%

Identity AttacksHiring FraudInsider Threat

Nearly 90% of HR leaders report heightened concern over hiring fraud

Hiring FraudInsider Threat

69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.

Proofpoint2026 Voice of the CISO·4w ago
Employee BehaviorInsider ThreatUK

Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.

Proofpoint2026 Voice of the CISO·4w ago
Insider ThreatData LossUK

95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.

Proofpoint2026 Voice of the CISO·4w ago
Insider ThreatData LossUK

Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·2mo ago
Insider Threat

50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments

Insider RiskAI GovernanceFederal agenciesAgentic AI

41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.

Insider ThreatAIHuman Risk

68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.

Human RiskAIInsider Threat

40% of CISOs fear employees are sharing sensitive information with generative AI platforms.

Data SecurityGenerative AIInsider RiskHuman Risk

38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.

Insider ThreatDetectionCritical Alerts

12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.

Access ControlInsider RiskPrivileged Access
View all Insider Threat→