No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Risk Ledger Analysis: Expect More Supply Chain Cyber Attacks

Report finds nearly one-third of companies examined don’t have supplier security policies

by Staff and Wire Reports
April 20, 2023
in Cybersecurity
supply chain inside factory

A third-party supply chain cyber attack against computer chip giant Applied Materials, expected to result in losses of $250 million, won’t be the last one targeting down-stream suppliers, according to an analysis by British cybersecurity provider Risk Ledger. In fact, nearly one-third of organizations analyzed lack supplier security policies, according to the analysis.

Risk Ledger’s report, “State of Cyber Security in the Supply Chain 2023,” is based on anonymized, proprietary data of more than 2,500 suppliers that have shared information on their risk posture, revealing leading cybersecurity weaknesses in the supply chain.

The report found, for example that 40% of third-party suppliers do not conduct regular penetration tests of internal systems and 32% do not have a supplier security policy that outlines the security requirements that their suppliers should meet, putting their own and their customers’ data at risk.

“Companies rarely run security assurance against more than 10% of their immediate third-party suppliers, while visibility into the risks existing further down the chain remains almost non-existent,” Risk Ledger CEO Haydn Brooks said in a news release. “To improve this situation, better data and insights into the most prevalent weaknesses in the wider supplier ecosystem are needed, so that remedial efforts can become more focused.”

Here are some other key findings:

  • 17% of firms analyzed do not enforce multi-factor authentication (MFA) on all remotely accessible services.
  • 23% do not use privileged access management controls to securely manage the use of privileged accounts.
  • 20% do not use a password manager.
Tags: Cyber RiskCybercrimeSupply Chain
Previous Post

Kuberno Lands $4.4M Series A Led by Nasdaq Ventures

Next Post

70% of UK Compliance Pros Fear Crypto-Enabled Money Laundering

Staff and Wire Reports

Staff and Wire Reports

Related Posts

phishing attempt concept

Feds: Cybercrime Is Getting Worse & Compliance Can’t Treat It Like Someone Else’s Problem

by Jennifer L. Gaskin
September 28, 2026

Federal officials say cybersecurity is squarely an ethics & compliance concern

mexico city plaza and flag

Standard Due Diligence May Not be Enough in Mexico

by Alejandro Ortega, Miguel Salcedo and David Williams
September 28, 2026

KYC screening does not always reveal ownership connections

news roundup data grungy

Only 10% of Companies Could Live up to UK Bill’s Hack Reporting Rules

by Staff and Wire Reports
September 25, 2026

Plus: Almost 9 in 10 companies don’t fully assess third parties

man welding in shop

Welding Fumes Are Gassing Up New Compliance Processes

by Neeta Verma
September 11, 2026

Listing change implicates processes, not just products

Next Post
crypto exchange

70% of UK Compliance Pros Fear Crypto-Enabled Money Laundering

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights