Logo
Cybersecurity

Supply Chain Attacks Are Growing: Why Third-Party Risk Needs Continuous Testing

Third-party breaches doubled from 15 to 30 percent in a single year, per Verizon's DBIR. ITSEC Asia, Indonesia's leading cybersecurity company, explains why continuous testing is now essential for supply chain risk.

ITSEC AsiaITSEC Asia
|
Jul 31, 2026
Supply Chain Attacks Are Growing: Why Third-Party Risk Needs Continuous Testing

Introduction
Third-party involvement in data breaches doubled from 15 percent to 30 percent in a single year, the largest one-year shift ever recorded in the Verizon 2025 Data Breach Investigations Report. That is not a gradual trend line, it is a structural shift in how attackers reach their targets. Rather than breaching a company directly, they go after the vendor, the software dependency, or the service provider sitting quietly inside that company's trust boundary. As Indonesia's leading cybersecurity company, ITSEC Asia works with organizations across finance, healthcare, and technology who are only now realizing that their own defenses were never the whole picture, because a breach can start three vendors away and still land squarely on their desk.


Source: Supply Chain Attack Statistics 2026, Stingrai Research · Supply Chain Attack Statistics for 2026, Swif


The Numbers Behind the Shift
A supply chain compromise now costs an average of 4.91 million US dollars and takes 267 days to identify and contain, the longest lifecycle of any breach vector tracked in IBM's Cost of a Data Breach Report. That is nearly nine months where a vulnerability introduced by a vendor, a plugin, or an open source package sits undetected while attackers move laterally through connected systems. The scale of the problem shows up clearly once the separate data points are lined up side by side.

  1. A supply chain breach costs 4.91 million US dollars on average and takes 267 days to identify and contain, the longest lifecycle of any breach vector tracked by IBM
  2. Sonatype identified more than 454,600 new malicious open source packages in 2025 alone, a 75 percent jump from the year before
  3. Checkmarx research found that 63 percent of organizations experienced a supply chain attack within the past two years

Put together, these numbers suggest this is no longer a rare event reserved for large enterprises with complex vendor networks, but something most organizations should now expect to face directly.


Source: Supply Chain Attack Statistics for 2026, Swif · Supply Chain Attack Statistics 2026: 65+ Key Facts & Data, AppSec Santa


Why the Old Vendor Review Model No Longer Works
Most organizations still manage third-party risk the way they always have, through a questionnaire sent once a year and a signed compliance checklist filed away until the next renewal. That approach assumes a vendor's security posture on the day they were reviewed still holds true twelve months later, and a closer look at how vendor access actually behaves shows why that assumption rarely survives contact with reality.

  1. 60 percent of security leaders reported an increase in third-party security incidents over the past year, per a 2026 CISO survey from Panorays
  2. Only 15 percent of those same CISOs said they had full visibility into their third-party risks, up from just 3 percent the year before
  3. Vendor access today spans SaaS platforms, APIs, cloud integrations, identity providers, and outsourced development teams, often indistinguishable from internal access

A static annual review simply cannot keep pace with how quickly that access, and the risk attached to it, changes. Continuous testing closes that gap by validating a vendor's actual exposed surface on an ongoing basis, catching the moment a new integration or an unpatched dependency opens a door that a once a year checklist would never have caught until it was too late.


Source: 2026 Study from Panorays: 85% of CISOs Can't See Third-Party Threats, CIO · Third-Party Risk Statistics 2026, DeepStrike


Closing the Gap with Continuous Validation
This is precisely the shift ITSEC Asia has been helping clients make, moving third-party risk management from a paperwork exercise into a continuously validated process. Through Bronyx, ITSEC Asia's AI powered autonomous penetration testing platform, organizations can extend the same continuous testing discipline they apply to their own infrastructure to the vendors, APIs, and software dependencies connected to it, surfacing exploitable weak points across an extended attack surface rather than relying on a vendor's self reported questionnaire. Given that a supply chain breach now costs roughly 4.91 million US dollars and takes over eight months to resolve, the economics favor catching a misconfigured vendor integration or a vulnerable dependency early, while it is still cheap to fix, over discovering it only after an attacker already has been inside for months. For Indonesian organizations operating under UU PDP, where a third party's failure can still trigger the company's own regulatory exposure, that distinction is not academic, it is the difference between a routine fix and a breach notification.


Source: Supply Chain Attack Statistics for 2026, Swif · Supply Chain Risk in 2026, Cyberlab
 

Talk to ITSEC Asia About Third-Party Risk
Vendor and partner ecosystems are no longer an edge case in an organization's threat model, they are the default path attackers are already using. Visit bronyx.ai or connect with the ITSEC Asia team at itsec.asia/contact to see how continuous, AI powered testing can validate the vendors and integrations your organization depends on before they become the next entry point.

Share this post

You may also like

Cybersecurity Skills Need Maintenance Too
Cybersecurity

Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills. Six months later, the environment looks different. A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive. This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance. NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application. The format matters. Learning doesn’t always need another full week away from work. SMALL LEARNING CAN SOLVE SPECIFIC PROBLEMS CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes,

ITSEC AsiaITSEC Asia
|
Sep 14, 2026 3 minutes read
What Makes AI-Powered Penetration Testing Different From Automated Scanners?
Cybersecurity

What Makes AI-Powered Penetration Testing Different From Automated Scanners?

INTRODUCTION How much of what a vulnerability scanner flags every week actually turns out to be real? Research from OWASP puts the false positive rate for common vulnerability types somewhere between 15% and 30%, and separate research from Snyk found that security teams now spend roughly 70% of their time chasing alerts that end up being nothing at all. That gap between what a tool reports and what is actually exploitable is not a minor inconvenience. It is the reason a third of companies surveyed admitted they responded late to a genuine attack because their team was buried in phantom threats instead. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across the region that have learned this the hard way, and the question that keeps coming up is simple. If a scanner already checks the boxes, why does AI-powered penetration testing exist at all, and what does it actually do differently? Source: OWASP false positive research via DEV Community [https://dev.to/kuboidsecurelayer/why-automated-vulnerability-scanners-miss-most-real-security-vulnerabilities-2p96] · Snyk: Minimizing False Positives [https://snyk.io/blog/minimizing-false-positives-enhancing-security-efficiency/] THE FUNDAMENTAL DIFFERENCE: FOLLOWING RULES

ITSEC AsiaITSEC Asia
|
Jul 03, 2026 5 minutes read
Why Cybersecurity Awareness Matters for Modern Enterprises
Cybersecurity

Why Cybersecurity Awareness Matters for Modern Enterprises

INTRODUCTION As organizations accelerate digital transformation through cloud adoption, remote work, and AI-driven systems, the nature of cyber risk continues to evolve. Security challenges are no longer limited to technical vulnerabilities alone. Increasingly, attackers exploit human behavior, trust, and routine workflows to gain unauthorized access to systems and sensitive data. Phishing campaigns, social engineering tactics, and impersonation attacks have grown more sophisticated and harder to detect. Industry guidance from ENISA [https://www.enisa.europa.eu/] highlights that human-centric attack techniques remain among the most effective methods used against organizations today. In this context, cybersecurity awareness has become a critical factor in determining how effectively enterprises can prevent, detect, and respond to cyber threats. This article explains why cybersecurity awareness is important, the challenges enterprises face in building it, and how awareness strengthens overall cybersecurity resilience. WHAT IS CYBERSECURITY AWARENESS? According to findings highlighted in the Verizon Data Breach Investigations Report (DBIR), [https://www.verizon.com/business/resources/reports/dbir/]human interaction continues to play a significant role in successful cyber incidents. In enterprise environments, cybersecurity awareness is not limited to IT or security teams. It applies to every

ITSEC AsiaITSEC Asia
|
Jan 19, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe