Supply chain cyber security

Discover why supply chain attacks have grown in sophistication and how regulatory expectations have intensified

Notable supply chain attacks

Four incidents in particular have shaped how organisations think about supply chain cyber security:

Marks & Spencer (2025) – attackers from the Scattered Spider group compromised M&S through Tata Consultancy Services (TCS), the outsourced provider running M&S’s IT helpdesk. Using social engineering to steal login credentials from the supplier, they moved laterally into M&S’s internal systems, deployed ransomware, and exfiltrated customer data. M&S was forced to suspend online clothing orders for 46 days, revert to pen-and-paper stock tracking across over 1,400 stores, and reported a £300 million revenue impact. Pre-tax profits fell from £391.9 million to £3.4 million in the following half-year. A single compromised supplier relationship crippled one of the UK’s largest retailers.

Jaguar Land Rover (2025) – attackers used AI-generated phishing calls impersonating JLR’s IT help desk to trick employees into revealing credentials, then escalated privileges via VPN access and deployed ransomware across ERP and production systems. JLR halted all vehicle production for six weeks, causing UK car output to fall 27% in September 2025 – the worst month for the industry since 1952. The attack cascaded through the entire UK automotive supply chain, with the estimated total damage to the British economy reaching £1.9 billion and the UK government issuing a £1.5 billion loan guarantee to stabilise JLR’s suppliers. It is considered the most financially damaging cyberattack in British history.

3CX (2023) – attackers compromised 3CX’s desktop application through a supply chain attack on another vendor (Trading Technologies). The trojanised 3CX application was digitally signed and distributed through legitimate update channels to approximately 600,000 customer organisations. This was notable as a ‘cascading’ supply chain attack – a supply chain attack used to launch another supply chain attack.

MOVEit (2023) – the Cl0p ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer file-sharing platform. Because MOVEit was used by thousands of organisations for secure file transfer, the attack affected over 2,500 organisations and exposed data on more than 80 million individuals. Victims included the BBC, British Airways, Boots, and multiple UK government departments.

Types of supply chain risk

Supply chain cyber risk takes several forms:

  • Software supply chain – compromised software updates, malicious code in open-source libraries, trojanised development tools. This is the 3CX attack model. The OWASP Top 10 addresses this through A06 (Vulnerable and Outdated Components) and A08 (Software and Data Integrity Failures)
  • Service provider compromise – an MSP, cloud provider, or outsourced IT team is breached, giving attackers access to their clients’ environments. Data sharing risk – suppliers who hold your data (payroll providers, HR platforms, file transfer services) are breached, exposing your data without your systems being compromised. The MOVEit attack is the defining example
  • Hardware and firmware risk – tampered hardware, compromised firmware, or counterfeit components introduced into the supply chain. More common in critical infrastructure and defence contexts

Assessing supply chain risk

Effective supply chain cyber security requires a structured approach to vendor assessment and ongoing monitoring:

Supplier classification – categorise suppliers by the level of access they have to your systems, data, and critical functions. Not all suppliers carry equal risk. A cloud hosting provider with administrative access to your infrastructure is a higher-risk supplier than a stationery vendor.

Due diligence at onboarding – assess the supplier’s security posture before granting access. This includes reviewing certifications (Cyber Essentials Plus, SOC 2, ISO 27001), requesting evidence of penetration testing, reviewing their incident response capability, and understanding their own supply chain dependencies.

Contractual controls – security requirements written into contracts including data handling obligations, breach notification timescales, right to audit, and insurance requirements. Under GDPR, data processors must provide sufficient guarantees of security.

Ongoing monitoring – supplier risk is not static. Continuous monitoring includes reviewing supplier security ratings, tracking their exposure in breach databases, and requiring annual re-assessment for high-risk suppliers.

Regulatory requirements

Supply chain cyber security is increasingly mandated by regulation:

  • NIS2 Directive – requires organisations in scope to implement supply chain security measures and assess the security of their direct suppliers
  • DORA – mandates ICT third-party risk management for financial entities, including registers of all ICT service providers and exit strategies for critical suppliers
  • NCSC Supply Chain Guidance – the UK’s National Cyber Security Centre has published a 12-principle framework for managing supply chain cyber risk, covering supplier assessment, contract management, and ongoing monitoring
  • UK Government Cyber Security Strategy 2022 – identifies supply chain resilience as a national priority and commits to strengthening supply chain security across government and critical national infrastructure

Cyberfort and supply chain cyber security

We help organisations assess and manage supply chain cyber risk through our supplier governance and supplier assurance audit services . This includes supplier risk classification, vendor security assessment, GRC framework alignment, and gap analysis against NCSC supply chain guidance and NIS2 requirements. For organisations that need to test their response to a supply chain compromise, our crisis simulation exercises include supply chain attack scenarios designed to test detection, communication, and recovery across your organisation and key suppliers. Discuss your supply chain security posture →

Related glossary terms

  • NIS2 Directive – EU directive mandating supply chain risk management for organisations in scope
  • DORA – financial services regulation requiring ICT third-party risk management
  • GRC – governance, risk, and compliance frameworks that encompass supply chain risk
  • Cyber Essentials Plus – baseline certification used in supplier due diligence
  • SOC 2 – audit standard commonly requested from cloud and SaaS suppliers

External references

Frequently asked questions

What is a supply chain cyber attack?

A supply chain cyber attack is an attack in which an adversary compromises a trusted third-party supplier, such as a software vendor, managed service provider, or cloud platform, to gain access to the supplier’s customers. Rather than attacking each target organisation directly, the attacker exploits the trust relationship between the supplier and its customers. A single compromise can cascade to hundreds or thousands of downstream organisations, as demonstrated by the Marks & Spencer, Jaguar Land Rover, and MOVEit incidents.

How do you assess a supplier’s cyber security?

Start by classifying suppliers based on their level of access to your systems, data, and critical functions. For high-risk suppliers, review their security certifications (ISO 27001, Cyber Essentials Plus, SOC 2), request evidence of recent penetration testing, assess their incident response capability, and understand their own supply chain dependencies. Write security requirements into contracts, including breach notification timescales and right to audit. Re-assess high-risk suppliers annually and monitor for changes in their security posture.

Is supply chain cyber security a regulatory requirement?

Increasingly, yes. The NIS2 Directive requires organisations in scope to implement supply chain security measures. DORA mandates ICT third-party risk management for financial entities. The UK Government’s Cyber Security Strategy identifies supply chain resilience as a national priority. Even where not explicitly mandated, regulators expect organisations to manage third-party risk as part of their overall cyber security posture. The ICO has taken enforcement action in cases where data breaches resulted from inadequate supplier due diligence.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.