Supply Chain Statistics

75 STATS27 SOURCES

Latest Statistics

66% of incidents involve the supply chain or a third party, up from 45% in 2024.

BarracudaThe Managed XDR Global Threat Report·Feb 18, 2026
Supply ChainThird-Party Risk

In MCP registries, for every server provided by a verified technology vendor there are up to 15 lookalike servers from untrusted sources.

UpGuardYOLO Mode: Hidden Risks in Claude Code Permissions·Feb 4, 2026
Supply ChainTyposquattingAI Code Agents

Top AI-related cybersecurity concerns are data leakage through copilots and agents (22%), third-party and supply chain risks (21%), evolving regulations (20%), shadow AI (18%), and prompt injection attacks (18%).

TinesTines Report Finds Widespread Use of AI in Security Operations, But Manual Work Persists.html·Jan 28, 2026
CybersecuritySupply Chain RiskAI Risk

Confidence in data security falls to 40% when data passes through third-party provider networks.

ArelionConnecting through chaos: how enterprise networks are protecting their data in a volatile world·Jan 28, 2026
Data SecurityThird-Party RiskNetwork SecurityEnterprise

32% of leaders do not know the locations of all of their data centers, rising to 49% when including third-party providers.

ArelionConnecting through chaos: how enterprise networks are protecting their data in a volatile world·Jan 28, 2026
Data VisibilityThird-Party RiskData SecurityData CentersEnterprise

11% of leaders say they are aware of definite weak points when their data travels across third-party infrastructures.

ArelionConnecting through chaos: how enterprise networks are protecting their data in a volatile world·Jan 28, 2026
Third-Party RiskData SecurityEnterprise

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Third-Party Software SecuritySoftware Supply ChainSBOM ValidationVulnerability Management

70% of organizations experienced at least one material third-party cyber incident in the past year.

MarshCyber catalyst report: Guiding priorities in cyber investments ·Dec 9, 2025
Third-Party RiskThird-Party Cyber Incident

97% of organizations reported negative impacts from supply chain breaches over the past twelve months, an increase from 81% in 2024.

BlueVoyantState of Supply Chain Defense Report·Nov 20, 2025
Supply chain breach

47% of retail executives reported having very low to moderate visibility into their software supply chain.

LevelBlueBuild Cyber Resilience for a Stronger Retail Future·Nov 12, 2025
RetailSoftware supply chain

33% of leaders at financial services firms say they are unprepared to recover effectively from a Supply chain attack.

Omega Systems2025 Financial Services Cyber Resilience Report ·Oct 15, 2025
Financial services RecoverySupply chain attack

Supply chain attacks against healthcare organizations decreased significantly from 68% in 2024 to 44% in 2025.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareSupply chain attack

44% of healthcare organizations say their organizations experienced an attack against its supply chains, which is a significant decline from 68% in 2024.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareSupply chain attack

Healthcare organizations that experienced supply chain attacks, on average, experienced four supply chain attacks in the past two years.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareSupply chain attack

57% of healthcare organizations say their organizations are very or highly vulnerable to supply chain attacks.

Proofpoint2025 Ponemon Healthcare Cybersecurity Report ·Oct 8, 2025
HealthcareSupply chain attack

38% of organizations identify runtime as their most vulnerable phase in AI supply chain security.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI Supply chainRuntime

31.2% of organizations expect AI Supply Chain Security to require the most new investment in AI security over the next 12 months.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chainInvestmentBudget

29% of organizations identify external APIs and SaaS-embedded AI features as their greatest AI supply chain risk.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chainAPISaaS

31% of organizations identify data sources and embeddings as their greatest AI supply chain risk.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chain

Over 31% of organizations are planning to allocate their security budgets to AI supply chain security over the next 12 months.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chainInvestmentBudget

Only 13% of organizations rank model sourcing and provenance as concerns regarding AI supply chain risk.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chain

27% of organizations view AI supply chain risks as spanning the entire AI supply chain from sourcing through runtime deployment.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI Supply chain

16% of organizations rank plugins and extensions as their greatest AI supply chain risk.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI Supply chain

Just 9% of organizations rank orchestration layers and agents as their greatest AI supply chain risk.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI Supply chain

3% of organizations are unsure which aspect of the AI supply chain poses the greatest risk to their organization.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI Supply chain

31% of organizations are redirecting their largest security investments toward AI supply chain security over the next 12 months.

Acuvity AI2025 State of AI Security·Oct 7, 2025
AIAI supply chainInvestmentBudget

CISO confusion about cyber insurance policy coverage for supply-chain attacks decreased from 58% in 2024 to 43% in 2025.

PortnoxCISO cybersecurity trends survey·Oct 5, 2025
USCyber insuranceSupply ChainCISO

Business associates (including billing vendors, imaging firms, and outsourced IT providers) were involved in 17 of the 107 email-related breaches in healthcare. This represents 16% of all incidents.

Paubox2025 mid-year email breach data reveals there's no slowing down·Sep 5, 2025
HealthcareEmailThird-party risk

68% of healthcare leaders cited third-party software as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareThird-party risk

68% of healthcare leaders cited third-party software as the top risk.

CobaltState of Pentesting in Healthcare 2025·Sep 3, 2025
HealthcareThird-party risk

73% of security leaders reported receiving at least one notification of a software supply chain vulnerability or incident within the past year.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskSoftware supply chain

68% of security leaders are concerned about the risks associated with third-party software tools and components integrated into their tech stacks.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskThird-party softwareThird-party software tools

68% of CISOs consider supply chain risk and generative AI security to be top concerns, viewing them as intertwined challenges that are redefining the attack surface.

CobaltCISO Perspectives Report: AI and Digital Supply Chain Risks·Jul 31, 2025
Supply chain riskGen AICybersecurity risk

In Latin America, 50% say they are prepared for software supply chain attacks.

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chainLatin America

80% of organizations with low visibility of their software supply chain view critical factors like custom code, commercial off-the-shelf software, and API integrations as "very risky" or "somewhat risky".

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chain

About half (49%) of companies say they lack the visibility to fully understand – or even identify – software supply chain risks.

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chain

40% of CEOs believe that the biggest security risk the organization faces today is from the software supply chain, compared with 29% of CIOs and 27% of CTOs.

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chain

Despite high investment in enhanced software supply chain security, Europe ranks lowest at 23% in prioritizing engaging with software suppliers about security credentials

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chainEurope

39% of CEOs say AI adoption presents a greater risk to the software supply chain.

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chainAI

57% of North American organizations say they are prepared for software supply chain attacks.

LevelBlueData Accelerator: Software Supply Chain and Cybersecurity·Jul 9, 2025
Software supply chainNorth America