Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Suppliers Overlooked By Large UK Businesses When Developing Cyber Strategies
Study & Research

Suppliers Overlooked By Large UK Businesses When Developing Cyber Strategies

ISBuzz TeamBy ISBuzz TeamJune 7, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

~ However, the majority of IT security decision makers are confident in their own organisation’s cybersecurity recovery strategy ~

  Large businesses in the UK could be falling short when it comes to assessing the cybersecurity resilience of external providers within their supply chain network, according to new research.

The poll – commissioned by Citrix and carried out by OnePoll – quizzed 750 IT security decision makers in companies with 250 or more employees across the UK, to uncover the extent to which large UK businesses are prepared for cyber-attacks. The research also considered whether businesses are conducting the necessary due diligence when assessing new suppliers, and whether this affects the effectiveness of cybersecurity practices.

‘Cyber resilience’ in the supply chain

When questioned about the on boarding process of new suppliers, only 35% of respondents consider the cybersecurity audit conducted by their organisation to be ‘very comprehensive’. Additionally, almost one in 10 (9%) state that their organisation simply asks a few questions during the initial pitch process. To add to this, just over a third (35%) of organisations polled said they have insurance to cover their supply chain providers – should they have cybersecurity concerns or a breach.

The research findings also highlight the need for improved communication between organisations and their supply base, with one in five (20%) of those surveyed confirming that they do not communicate with suppliers when testing their cybersecurity recovery process.

Confidence in cybersecurity strategy

Yet, whilst the supply chain could have been overlooked, there appears to be growing confidence within IT security teams in their own organisations. Indeed, the vast majority (93%) of IT security decision makers questioned are confident in the maturity of their own organisation’s ‘cybersecurity resilience’ – indicating they are confident that the business will be able to effectively operate following a cyberattack.

Many respondents also consider their cybersecurity recovery strategy to be either ‘quite mature’ (51%) or ‘very mature’ (42%), with significant confidence that their organisation is fully prepared against a ransomware (57%), phishing (64%) and malware (72%) attack. However, less than half of those surveyed were confident that their organisation is ready to tackle a DDoS (49%) or application layer attack (49%).

The findings also suggest that cybersecurity resilience is becoming more of a priority for the wider business – not just the IT team. A quarter (25%) of respondents stated that this is an issue discussed at boardroom level within their organisation. A further one third (33%) consider this to be an issue discussed at a managerial level.

Despite this growing confidence and awareness, almost half (44%) of the respondents questioned by OnePoll in May confirmed that their business has experienced a data breach in the last three months that required business recovery. A further one in 10 (11%) have experienced a data breach in the last week.

Cloud complications 

However, IT security decision makers are still concerned that a cloud-based IT environment complicates the development of cybersecurity strategy. Three in five respondents stated that a ‘multi-cloud’ (64%) and ‘hybrid-cloud’ (60%) environment add further complication when considering cybersecurity. Furthermore, over two thirds (67%) of respondents cited ‘public cloud’ as the IT environment that adds the greatest complication to the development of cybersecurity strategy.

Chris Mayers, chief security architect, Citrix, said: 

“Recent cyberattacks demonstrate that the supply chain can be the weakest link for a significant number of organisations. For example, the ‘NotPetya’ campaign began with an extremely effective supply chain attack, which had disastrous consequences for Ukraine’s national bank, airport and government department – proceeding to infect machines in a staggering 64 countries.

“It is therefore vital that businesses conduct the necessary due diligence when integrating a new provider into their supply chain. Considering the risk associated with a supply chain attack and conducting a cybersecurity audit of your supply base should not be a box-ticking exercise. Ask yourself this question: has my business ever rejected a supplier on the basis of audit findings? I suspect this number would be significantly lower than the amount that are confident in their supplier due diligence.

“The assessment of cybersecurity procedures should be a vital part of any contractual agreement and organisations will need to ensure that they have insurance to cover their supply base. Without these measures in place, cyber criminals will use suppliers as a stepping stone to gain access to their ultimate target – your business.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}