Financial Services Supply Chain Statistics
PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.
Third-party involvement occurs in 30% of financial-sector breaches.
73% of large organizations with 5,001 or more employees fall into the lowest TPRM confidence tiers.
Individual TPRM professionals are responsible for 100 or more vendor relationships.
13% of the most mature TPRM programs view TPRM as little more than a compliance formality.
Financial institutions using manual TPRM processes report 50% lower satisfaction with their tools.
Nearly 87% of financial institutions use TPRM software.
Financial institutions using manual TPRM processes are 71% more likely to receive exam findings.
72% of financial institutions are only partially aware of which vendors use AI, and 0% feel extremely confident managing vendor AI.
63% of TPRM programs operate with just one or two dedicated full-time employees.
13% of TPRM programs have no dedicated staff.
26% of the most mature TPRM programs report TPRM delivering high value across the organization.
67% of organizations with no TPRM processes view TPRM as little more than a compliance formality.
53% of TPRM programs manage 300 or more vendors.
10% of financial institutions still rely on spreadsheets, down from 13% in 2025.
33% of leaders at financial services firms say they are unprepared to recover effectively from a Supply chain attack.
It takes financial organisations nearly 16 hours to respond to supply chain attacks on average.
35% of financial services professionals identified political instability as a challenge to supply chain assessment.
26% of financial services professionals identified geopolitical risk as a challenge to supply chain assessment.
Among financial services professionals who were less than "very confident" in their program's ability to assess their supply chains for threats, more than half (56%) of global respondents identified cybercrime as the biggest challenge to their programs in 2025.