Skip to content

Anticipating cyber risks in a supply chain: the growing supply chain threat landscape

18 May 20264 min read
Guest Insights
Anticipating cyber risks in a supply chain: the growing supply chain threat landscape

Supply chains are an increasingly common vector for cyber attacks, as evidenced by high-profile cases. Information supply chains are as vulnerable to attack as logistical ones, especially where open-source software has been utilised in development.

Cyber criminals operate in their own multi-layered commercial ecosystem. The size of an individual breach does not necessarily determine its impact; attackers often harvest small but sensitive datasets that can be ‘weaponised’. Attacks are increasingly sophisticated, exploiting zero-day vulnerabilities to create ripple effects across entire supply chains.

Beyond known risks: the iceberg challenge

Investment in IT-based security technologies has been the conventional response to combating cyber threats. However, this approach is inherently reactive and largely focused on known risks, meaning it can only reduce, rather than eliminate the likelihood of successful attacks.

There remains a vast volume of unknown or poorly understood data available to adversaries, often undiscovered by organisations until it is too late. As illustrated in the iceberg model below, the visible ‘attack surface’ represents only a fraction of the true risk. Beneath the surface lies a much larger, more complex layer of third-party exposure and unknown vulnerabilities that organisations must actively identify and manage.

Understanding the anatomy of a breach

The 2025 report by Lab 1, The Anatomy of a Breach, analyses 141 million unstructured files across 1,297 data breach incidents. It shifts the focus from the volume of leaked data to the high-impact nature of its content. Based on these incidents, the “average” breach contains:

  • 22,647 individual files

  • 13.44 GB of total data

  • 14 different file types and 22 file classifications

  • Exposure impacting 482 organisations

Financial data appeared in 93% of incidents, while HR data featured in 81.7% of breaches, creating rich datasets for AI-driven fraud such as deepfakes, voice cloning, and social engineering. Customer service records were present in 66.6% of incidents, exposing personal data that can lead to identity theft and regulatory penalties.

Technical data is also frequently exposed, including system logs and cryptographic keys. This can enable attackers to bypass authentication processes or gain access to sensitive artefacts such as Software Bills of Materials (SBOMs). Additionally, datasets often include Social Security numbers, banking details (e.g. IBANs), and email addresses.

From data exposure to actionable risk

It is important to stress that all exposed data represents potential risk. Determining actual risk requires contextualisation against an organisation’s specific risk profile.

However, the manual effort required to analyse large-scale, unstructured data and assess risk is considerable. As a result, organisations must increasingly rely on emerging technologies to automate and scale this process.

The role of emerging technologies

To effectively address supply chain risk, organisations must first locate, collect, extract, and analyse compromised or exposed data across sources such as the dark web. This requires a combination of advanced data processing techniques, including machine learning and graph-based analysis.

Frontier large language models (LLMs) can significantly enhance both efficiency and effectiveness by enabling rapid analysis of extracted data, tasks that would otherwise be prohibitively time consuming. AI can also support validation of third-party and open-source software, identifying potential vulnerabilities or malicious code.

However, applying AI in isolation is not sufficient. The challenge lies in integrating these capabilities into a broader, structured security architecture.

Securing the information supply chain

A key question is where and how this advanced analysis should take place. Ideally, it should occur at trust boundaries or across security domains within the information supply chain, supported by technologies such as data guards.

Unlike traditional firewalls, data guards provide deep data inspection, filtering, and data loss prevention capabilities. However, conventional appliance-based guards are typically hard-coded, requiring manual updates and struggle to keep pace with evolving threats.

Software-defined data guards offer a more adaptive approach. Rather than relying on static rules, they provide a flexible platform where security functions can be dynamically orchestrated via APIs. For example, extracted software code can be routed to an LLM for inspection, before being triaged, allowed, quarantined, or removed, based on the outcome. This provides assurance that software moving through the supply chain has not been compromised.

An additional advantage of cloud-native, software-defined guards is their ability to scale dynamically in response to demand, optimising resource usage while maintaining security coverage.

Towards intelligent, contextual defence

The addition of Agentic Triage capabilities enables organisations to complete the picture by embedding their specific risk criteria into the analysis process. This allows systems to prioritise what matters most, cutting through noise and reducing false positives.

By combining AI-driven analysis, adaptive security architectures, and contextual risk assessment, organisations can move from reactive defence to proactive cyber resilience, better anticipating and mitigating risks across increasingly complex supply chains.