A new NCC Group report reveals that most organizations believe they can contain a supply chain cyberattack, even as nearly half suffered breaches in the past year. The findings expose a widening gap between confidence and operational readiness across global networks.
False Sense of Readiness Masks Systemic Weakness
The State of Supply Chain Security 2025 report by NCC Group shows that 94% of companies are confident in their ability to respond to a supplier-related cyberattack, despite 45% having already been breached within the last 12 months. Nearly half of those incidents disrupted operations outright. Yet, 92% of respondents said they trust their suppliers to follow cybersecurity best practices, a level of confidence that experts warn may be misplaced.
Mike Maddison, NCC Group’s CEO, said this overconfidence has become a liability at a time when global ransomware activity is at record levels. “Threat actors are profiteering from this complacency, using straightforward techniques to access virtually unguarded supply chain networks,” he noted, emphasizing that recent attacks have disrupted medical care, grounded flights, and emptied retail shelves.
While 68% of respondents anticipate that supply chain attacks will grow more severe over the next year, many underestimate their potential impact. One in five firms believe they would remain unaffected even if a key supplier went offline for five days, a view NCC says is dangerously detached from operational reality.
Visibility Gaps and AI Risks Intensify Exposure
The study reveals a persistent lack of visibility across supplier ecosystems. Only 34% of organizations claim full and detailed insight into their supply chain’s cybersecurity posture, while the same proportion admit they are not conducting regular supplier risk assessments. Furthermore, just 36% have visibility into how partners store and protect critical business data.
Cost remains a major barrier to better protection. Forty-five percent of suppliers cited the expense of cybersecurity compliance as their top pain point. Despite these weaknesses, 90% of respondents still believe existing policies and standards effectively reduce supply chain risk, even as the growing patchwork of international legal frameworks complicates compliance.
Artificial intelligence is emerging as both a defensive tool and a new attack vector. Fifty-nine percent of respondents believe AI will increase supply chain security risks over the next 12 months, a finding echoed by recent reports from ENISA and Gartner highlighting the rise of AI-assisted phishing and code injection attacks targeting logistics and manufacturing networks.
From Compliance to Collaboration
The next phase of supply chain cybersecurity won’t be defined by audits or patching cycles but by shared visibility between partners. As regulations like the EU’s NIS2 and the U.S. SEC’s new cyber disclosure rules tighten expectations, companies will need to treat cybersecurity as a co-managed responsibility rather than a delegated one. Those that embed continuous assurance into supplier relationships, blending data transparency, contractual alignment, and operational collaboration, will move beyond compliance toward genuine ecosystem resilience.