Supply Chain Risks Grow as Cloud Tools Multiply

Supply Chain Risks Grow as Cloud Tools Multiply

Attacks on trusted third-party tools are quickly becoming one of the most dangerous blind spots in enterprise cloud security. A new survey by SentinelOne shows that while nearly all organizations acknowledge the risks, few have the visibility or controls to manage them effectively, leaving software supply chains especially vulnerable.

Alerts Overload, Visibility Shortfalls

SentinelOne’s 2025 Cloud Security Survey Report highlights the scale of the challenge. Roughly 87% of respondents said they struggle to validate and prioritize alerts, and more than half report that at least half their alerts turn out to be false positives. This noise makes it far easier for genuine supply chain breaches to slip through. Nearly 92% of respondents said the proliferation of point solutions has created blind spots, with too many disconnected tools undermining coordinated defense.

Secret scanning, a critical practice for uncovering exposed credentials in developer environments, remains underutilized. Only 12.9% of security teams view it as a priority, and close to 30% admit they have not implemented it at all. That oversight is striking given that credential theft and code repository compromises have been key entry points in recent high-profile breaches, including the SolarWinds attack that reshaped government and corporate security policies.

AI Seen as Relief for Stretched Security Teams

Despite these weaknesses, the survey suggests confidence in the next phase of cloud security. An overwhelming 98% of organizations expect artificial intelligence to enhance their defenses, especially in incident response, threat detection, and alert triage. The expectation is that AI will cut through the flood of false positives, accelerate detection of real threats, and extend the reach of smaller security teams.

The push toward unified cloud security platforms is also accelerating. According to trade reports, companies are consolidating fragmented tools into integrated platforms that offer end-to-end visibility and automated workflows. This shift is seen not only as a way to simplify operations but as essential for catching supply chain intrusions that often span multiple systems and linger undetected for months.

A Hidden Cost of Fragmentation

While AI and platform unification may ease some of the strain, the deeper issue is structural. The survey reinforces what recent breach investigations have shown: when organizations rely on dozens of uncoordinated tools, they create complexity that attackers can exploit. The real threat is not just the sophistication of adversaries but the operational drag of fragmented defenses. For companies depending on global software supply chains, the risk is less about whether attackers will find a way in, and more about how long they will remain invisible once they do.

Subscribe to Newsletter

Don’t miss tomorrow’s supply chain industry news

Let Supply Chain 360’s free newsletter keep you informed, straight from your inbox.

Tip: select one or more digests.

EVENTS

03 MAR
LIVE EVENT | The Belfry, Birmingham, UK

SupplyChain360 Summit

3rd & 4th March 2027
06 OCT
LIVE EVENT | Soho Hotel London

SupplyChain360 Forum

6th October 2026