Supply chain risks: is your supplier making you vulnerable?

The more companies outsource, the less control they have over their own security. At the same time, regulations require greater verification than ever. Find out how CISOs resolve this contradiction – even beyond their own firewalls.

August 2026, Text Andreas Heer           7 min.

A Swiss company analyses a security incident involving a leak of data. Investigations reveal that it was accessed via an insufficiently secure SaaS. Although the service had been in use for some time, it was neither classified as a critical dependency nor monitored accordingly.

This is a pattern we see in real-life cases. When a Swiss procurement service provider suffered a cyberattack in 2025, employee data from various companies made its way via suppliers to the darknet. And in July 2026, cybercriminals seized data from a large industrial company through a supplier’s platform and (unsuccessfully) demanded a ransom of millions.

The supply chain as target

These incidents are no longer isolated cases. According to Verizon’s 2026 Data Breach Investigations Report (DBIR), almost half of all breaches now affect third parties – a 60% increase on the previous year.

This means a change in perspective for the CISO. When a company’s area of attack shifts to the ecosystem, effective cybersecurity requires transparency, control and detection capabilities beyond its own infrastructure. Especially as this ecosystem continues to grow in importance, says Oliver Jäschke, Product Owner Security Assurance at Swisscom and thus responsible for the security of supplier relationships. ‘Dependence on SaaS services and suppliers has increased massively. Today, companies integrate functionalities via API instead of developing their own or fixing bugs themselves.’ But according to Jäschke, this dependency comes with another risk: ‘Companies are also dependent on the availability of the SaaS services they use. For example, if the CRM isn’t running, employees can’t talk to customers about their concerns, and they can’t know see the next orders.’This applies all the more to critical services. ‘Even cloud services from large providers can fail, as recent history has shown,’ says Jäschke. Companies need to take this risk into account. And according to Jäschke, the same applies to the lack of transparency. ‘With smaller tools in particular, it is often unclear which cloud provider they are using in the background.’

On top of this there is the concentration risk. Many companies – and many of their SaaS providers – rely on the same handful of hyperscalers in the background. This creates ‘fourth-party risks’; even if the direct suppliers are different, multiple critical services may depend on the same basic services. That means an outage or security incident can have a more extensive impact than originally assumed. In industries such as the financial sector, this risk is also relevant from a regulatory perspective, for example in the context of FINMA requirements on outsourcing.

Swisscom Cybersecurity Threat Radar 2026: AI risks, supply chain attacks, digital sovereignty and OT security – an overview of the most important cyber trends.

What risks are lurking in the supply chain?

The benefits of state-of-the-art SaaS from third parties are beyond dispute. But they also give today’s cybercriminals a much larger area of attack than traditional on-premises environments. Points of vulnerability include:

  • SaaS and cloud platforms (including shared responsibility)
  • Managed service providers (MSPs)
  • Open-source components and libraries in vendor stacks
  • AI models and APIs

Attackers have changed their methods accordingly. They zero in on the weakest link in the supply chain – or the link with the greatest impact. They’ve expanded beyond ‘traditional’ attacks via phishing mails and security loopholes to the entire area of attack:

  • Compromised SaaS accounts with advanced permissions
  • Manipulated software updates or manipulated dependencies such as software libraries
  • Lateral movement via integrations and APIs
  • Access via privileged service providers (managed service providers)

Companies find these attacks difficult to detect because they are outside the their own cyber defence sphere. They have less control and rely on the security maturity of the supply chain to a certain extent. And depending which provider you use, monitoring can be difficult. ‘This is where threat intelligence helps us identify security gaps,’ says Oliver Jäschke. ‘Also, the exchange of expertise between companies. For this you need a well-connected SOC.’

AI from the perspective of supply chain security

Generative artificial intelligence (GenAI) represents a further risk from a cybersecurity perspective. Key concepts here include shadow AI, and prompt injection and unsafe agents that increase the area of attack. GenAI is a data security issue, but it also entails supply chain risks. That’s because AI models and APIs are themselves suppliers – think of training data, model updates, agents, services and upstream cloud infrastructure. And shadow AI is ultimately an SaaS governance problem – in other words, a classic supply chain issue.

Oliver Jäschke sees software security testing as another risk. True, ever-improving AI models such as Anthropic’s Claude Mythos can scan software for vulnerabilities. ‘Large software suppliers have the financial means to do that. But small providers and open-source projects struggle to afford it. This increases the risk of undetected security loopholes.’

Regulation as a driver for greater control

It’s something of a paradox – on the one hand, companies are losing a measure of control as the use of third-party services increases, while on the other, new and revised regulations actually require greater control, and transparency. And even if your company isn’t directly subject to the Information Security Act (ISG) or the European NIS2 Directive, you may still need to meet their requirements for the sake of customer relationships or your role as supplier.

Oliver Jäschke gives an example of this new reality: ‘The Digital Operational Resilience Act (DORA) has significantly increased the burden of proof for the financial sector in the EU. For example: you now have to document how suppliers are integrated into your business continuity management.’

Some regulations also come with notification requirements – with deadlines that are usually between 24 and 72 hours. For serious incidents, DORA calls for notification within as little as four hours. And: if data is leaked through a third party, the commissioning company remains responsible under the data protection provisions of revised Federal Act on Data Protection (FADP). If a supplier is involved in an incident, this information needs to be passed on. But this often doesn’t work in practice, as Jäschke explains: ‘Communication often fails. Something has to change here with the new regulations.’

Supply chain risk management measures

Transparency is the key factor in supply chain risk management. ‘Companies need to know the critical suppliers that could endanger operations in the event of a security incident,’ says Jäschke. ‘Then you can check their security measures as well.’

In practice, this is already happening through recognised means of verification, such as ISO-27001 certificates, and SOC 2 and ISAE-3402 reporting. Clear governance is just as important; third-party risks call for defined responsibilities that involve procurement, legal and business functions, not just the security organisation.

Companies also need transparency around the inventory of SaaS services, MSPs and external APIs they use. Threat detection and response functions need this information to develop response plans and playbooks for supply chain incidents.

However, transparency alone is not enough. Effective management of third-party risk also includes:

  • Tiering of suppliers by criticality so the depth of inspection corresponds to the risk
  • Continuous monitoring of critical suppliers rather than annual questionnaires
  • Contractual security requirements such as audit rights, reporting deadlines for incidents, and exit clauses
  • SBOM (software bill of materials) requirements to create transparency around software components in use
  • Supply chain scenarios in tabletop exercises and BCM to ensure that response plans are in place before an emergency happens
  • Systematic authorisation management for SaaS accounts, service accounts and service provider access: least privilege, MFA and control of OAuth and API integrations
  • A continuous supplier lifecycle with due diligence prior to onboarding, periodic reassessments and regulated offboarding

Supply chain security as a resilience factor

Current third-party risk programmes don’t just aim to avoid security gaps. The decisive factor is a company’s capacity to remain operational even if a critical service provider fails. This puts the focus on operational resilience rather than a purely compliance perspective.

Not every supplier risk can be mitigated. This makes a defined process for risk acceptance all the more important. Who bears residual risks, and are they compatible with the company’s risk appetite? Established standards such as ISO 27036, the supplier controls of ISO 27001, and the Swiss federal government’s ICT minimum standard provide guidance in implementation.

The challenge for CISOs today is no longer control of every component of the supply chain. What actually counts is the ability to identify critical dependencies, make risks transparent and systematically increase the company’s resilience in the face of outages and security incidents. And that’s making supply chain security a core function of modern corporate resilience.

Five questions a CISO should ask about supply chain risks

1. Which suppliers are really business critical, and who is the most important contact in the company?

Not all suppliers are equally relevant. Providers whose failure would have a negative impact on core processes are key.

2. Where are the privileged access points?

Service providers, SaaS platforms and MSPs often have advanced permissions for access to important business data and systems.

3. Where are the concentration risks?

How many critical applications are indirectly dependent on the same hyperscaler or technology provider?

4. What is the status of verification?

Are certifications, audit reports and security assessments up to date?

5. How quickly are incidents reported?

Are contractual provisions sufficient for meeting regulatory deadlines?

Would you like to find out more?