Report by Cobalt

CISO Perspectives Report: AI and Digital Supply Chain Risks

11 FINDINGSPublished Jul 31, 2025
View Original Report →

Key Findings

53% of respondents supplement their efforts with internal testing

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
TestingInternal testing

73% of security leaders reported receiving at least one notification of a software supply chain vulnerability or incident within the past year.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskSoftware supply chain

Nearly nine in 10 security leaders (88%) view penetration testing as an essential component of their overall security programme.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
TestingPen testing

55% of respondents conduct independent code reviews.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Code review

46% of security leaders are uneasy about AI-driven features and large language models.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
AI

55% of security leaders are constantly worried that a single employee mistake could put their entire organisation at risk.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Human error

60% of security leaders believe that attackers are evolving too quickly to maintain a truly resilient security posture.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Security postureAttacker capabilities

68% of security leaders are concerned about the risks associated with third-party software tools and components integrated into their tech stacks.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskThird-party softwareThird-party software tools

68% of security leaders state that their boards now view the secure deployment of generative AI as a critical priority.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Gen AI

More than half (58%) of respondents require third-party penetration test reports to validate software security.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
TestingPen testingSoftware security

68% of CISOs consider supply chain risk and generative AI security to be top concerns, viewing them as intertwined challenges that are redefining the attack surface.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskGen AICybersecurity risk