With growing concerns about cybercriminals targeting supply chains, Richard LaTulip, a Field Chief Information Security Officer at Recorded Future, looks at the importance of building cyber threat intelligence.
New research shows that 78% of CEOs view third-party and supply chain vulnerabilities as the biggest barrier to strengthening cyber resilience. This is according to the World Economic Forum’s Global Cybersecurity Outlook 2026, which highlights a decisive shift: leaders are broadening their focus beyond internal systems to the wider ecosystems their organisations rely on.
This heightened attention comes amid a marked rise in supply-chain-focused attacks. In October last year, data from the Chartered Institute of Procurement and Supply revealed that nearly a third of business leaders reported a rise in cyberattacks on supply chains. High profile breaches at organisations including Marks & Spencer and the Co-op have shown how quickly a technology breach can cascade through supplier ecosystems and disrupt core operations.
The surge in supply chain cyberattacks reflects an evolving threat landscape, with attackers modifying how they target large enterprises by opting for indirect routes to bypass robust defences.
Why attackers are targeting supply chains
Supply chains span multiple tiers of different entities and depend on expansive, interconnected systems. These networks are built on trust to enable collaboration, consistent quality standards and operational efficiencies. However, that same trust can be exploited. Instead of attempting to directly target the large organisation they are aiming to infiltrate, which will most likely have sophisticated security measures in place, attackers exploit trust downstream, where they can also hide among complex workflows to find a covert route into their primary target.
In many cases, trusted third-parties can prove easier for attackers to break into, because they don’t have the same budgets, resourcing or cybersecurity maturity as a large enterprise. Systems and platforms can be cracked earlier in a supply chain, creating a backdoor for attackers to deploy malicious code, which then makes its way through networks until it hits its primary goal. Trusted interactions and connections throughout a supply chain inadvertently enable the sharing of malicious code, such as malware and ransomware. The resulting impact can extend beyond technical compromise to include operational disruption, financial loss and reputational damage.
Despite many large organisations being alert to the threat of supply chain cyberattacks, it remains a difficult problem to solve. Many existing controls are inherently point-in-time, with periodic assessments providing only a snapshot of risk, while attacker activity evolves continuously. This often leaves organisations with an outdated understanding of third-party exposure. At the same time, threats originate in areas outside of an organisation’s direct control. While vendor standards, due diligence and audits provide some level of oversight, they cannot fully mitigate risks introduced by third-party dependencies.
Findings from Recorded Future’s State of Security Report 2026 show how cybercriminals are increasingly leveraging infostealers and generative Artificial Intelligence (AI) to target trusted platforms and vendor pathways at scale and with greater speed. This evolution is coupled with a sharp rise in advanced social engineering techniques, including spear phishing, voice impersonation and deepfake-enabled fraud, designed to bypass even the most sophisticated technical controls.
Threat groups like Scattered Spider have demonstrated how these capabilities can be combined to devastating effect, with attackers continuously refining their methods to remain difficult to predict and detect. This shift underscores the need to move beyond static governance models toward intelligence-led, continuously adaptive approaches. Evolved strategies can provide real-time visibility, integrate third-party risk monitoring, and enable faster detection and response across a supply chain ecosystem.
Intelligence-led Resilience
To build true resilience in their supply chains, organisations need to approach cybersecurity as a foundational element of operational risk management, not just an IT concern. That starts with understanding where vulnerabilities lie, both internally and across third-party partners.
Cyber threat intelligence and external telemetry can be leveraged to build a continuous, informed approach to managing and mitigating third-party risk. When used strategically, intelligence empowers organisations to detect threats early, monitor for signs of compromise within their supply chain, and make proactive decisions.
For example, sophisticated software can utilise machine learning and natural language processing to monitor in real-time for key indicators that the access credentials of supply chain personnel have been compromised. Risk-prioritised alerts can then be set, so that security teams are immediately aware of new threats and their severity, and have the context and evidence required to address threats quickly and confidently.
In many real-world incidents, early alerts from intelligence providers about active compromise, credential abuse, or vendor-related exposure are the decisive factor that allow organisations to act before damage occurs. Early, reliable warnings can bolster resilience, even as supply chain cyber threats continue to evolve.










