Supply Chain Attacks on the Rise as Organizations Struggle to Close the Gaps

Supply Chain Attacks on the Rise as Organizations Struggle to Close the Gaps

Global research company CrowdStrike surveyed over a thousand IT decision-makers and found companies awarness to combat supply chain attacks.

When one thinks about securing an organization, they often think of the physical security of the building around the organization. Now, in the world of data breaches and cyber attacks, a company can no longer afford to turn a blind eye to its infrastructure and networks.

Global research company CrowdStrike surveyed 1,300 IT decision-makers and IT professionals in the US, Canada, UK, Mexico, Australia, Germany, Japan and Singapore across major industry sectors to determine the mindset across organizations when it came to supply chain attacks, like NotPetya and the breaches that affected Target and Equifax.

The survey discovered that although nearly 80 percent of respondents believe software supply chain attacks have the potential to become one of the biggest cyber threats over the next three years, few organizations are prepared to mitigate the risks.

Specific findings from the survey include:

  • 1,300 respondents found that two in three said their organization experienced a software supply chain attack in the past 12 months.
  • The majority (87%) of those that suffered a software supply chain attack had either a full strategy in place, or some level of response pre-planned at the time of their attack. But attacks are still successful, which indicates that the strategies and technology currently in place aren’t stopping them.
  • 90 percent confirmed they incurred a financial cost as a result of experiencing a software supply chain attack in the past, with the average cost of an attack at $1.1 million dollars
  • 80 percent of U.S. respondents said supply chain attacks have the potential to become one of the biggest cyber threats over the next three years
  • Just 37 percent of respondents in the U.S. said their organization has vetted all suppliers, new or existing, over the past 12 months
  • 44 percent plan to use Artificial Intelligence/Machine Learning to fight software supply chain attacks in the next 12 months

The survey points out that even though threats can occur in every sector of the economy, the industries that mostly experience thee attacks are biotechnology and pharmaceuticals, hospitality, entertainment and media and IT services.

Visit CrowdStrike to learn more about the Securing the Supply Chain Survey.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.