Lehigh University’s latest Supply Chain Risk Management Index shows broad improvement across most risk categories in Q4 2025. Supplier and economic risks saw the largest declines, signaling that global supply chains are stabilizing after several years of disruption. However, cybersecurity threats continue to rise, keeping digital resilience high on the agenda.
Cybersecurity Tops the List as Other Risks Retreat
Eight of ten major risk categories tracked by the Lehigh Business Supply Chain Risk Management Index (LRMI) fell in the fourth quarter of 2025, marking the lowest overall risk levels in three quarters. Cybersecurity and data risk was the lone category to increase slightly, reflecting the growing sophistication of cyberattacks targeting supply chain systems.
“Cyber risk remains persistent and adaptive in nature,” said Zach G. Zacharia, Ph.D., associate professor of supply chain management and director of the Center for Supply Chain Research at Lehigh, in an official statement. “As organizations digitize procurement, logistics, and supplier management, the attack surface continues to expand.”
Government intervention risk, the second-highest category, dropped by six points as concerns over trade restrictions and regulatory changes eased. Supplier risk, previously a top concern, saw the sharpest decline, down 12.5 points, suggesting reduced anxiety around overreliance on specific suppliers or geographies. According to trade reports, improved nearshoring strategies and diversified sourcing are helping companies manage supplier concentration more effectively.
Economic risk also declined, supported by easing energy prices and fewer border bottlenecks. Customer risk remained largely unchanged, with demand volatility continuing but at more predictable levels.
Resilience Through Digital Oversight
The LRMI, developed in partnership with the Council of Supply Chain Management Professionals, measures ten broad categories of risk including operational, transportation, and environmental factors. Its quarterly reports allow executives to anticipate which risk vectors could become critical in upcoming quarters.
The Q4 findings also include comments from supply chain professionals who cite the growing complexity of managing AI-driven systems and the persistent influence of geopolitical uncertainty. “AI tools have expanded both productivity and exposure,” one respondent noted, pointing to a rise in intrusion attempts linked to generative AI. Others reported limited supply capacity in onshoring operations still scaling up to meet domestic demand.
Industry analysts note that while risk levels have moderated, organizations are entering a phase of “active monitoring” rather than complacency. As one respondent put it, “We’re building agility on the assumption there may never be a ‘new normal.’”
Interconnected Risks Demand Cross-Functional Readiness
Lehigh’s findings point to a structural shift in how risks propagate through global networks. Cyber threats that originate in supplier systems or logistics software now carry financial, legal, and reputational consequences that span far beyond IT boundaries. As generative AI and automated planning tools become embedded in core operations, the ability to trace, verify, and secure shared data will define resilience as much as physical redundancy once did.