UK Businesses Struggle with Supply Chain Cyber Risks Despite Heightened Awareness
A recent report from business continuity specialist Databarracks reveals that 26% of UK businesses experienced a cyber incident originating in their supply chain over the past year despite nearly half (48%) admitting they continued working with suppliers despite known security or resilience concerns.
The findings, part of the Data Health Check 2026 survey of 500 UK IT decision-makers, highlight a gap between awareness and action. While 89% of organizations assess supplier resilience during onboarding and 61% conduct regular reviews, many remain vulnerable due to dependence on critical suppliers. 26% of respondents cited supplier reliance as a key barrier to improving resilience, with few viable alternatives available.
The data underscores the real-world consequences of inaction: businesses that knowingly worked with risky suppliers were over four times more likely to suffer a supply chain cyber incident (43% vs. 10% for those that avoided high-risk suppliers).
Key challenges ahead
Supply chain vulnerabilities ranked among the top three IT resilience threats for the next five years, trailing only AI-driven cyber threats (46%) and ransomware (26%). Chris Butler, Resilience Director at Databarracks, warned that cascade effects from supplier disruptions can be severe, yet many organizations lack visibility beyond their immediate partners. He criticized traditional "tick-box" compliance assessments as insufficient, advocating for direct ownership of supplier risks and collaborative resilience planning especially with smaller or less mature suppliers.
Broader resilience trends
The report also found that 65% of organizations now view a serious cyber attack as an existential threat, while cyber incidents remain the leading cause of IT downtime for the fourth consecutive year. However, progress is evident: 90% of businesses now have a business continuity plan, and 59% of ransomware victims recovered via backups up from 18% who paid ransoms.
Looking ahead, integrating IT and business resilience emerged as the top priority for 2026, reflecting the need for a unified approach to modern threats that blur the lines between cybersecurity, operations, and executive decision-making.
Databarracks cybersecurity rating report: https://www.rankiteo.com/company/databarracks
"id": "DAT1784637028",
"linkid": "databarracks",
"type": "Cyber Attack",
"date": "7/2025",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'location': 'UK', 'type': 'Businesses'}],
'attack_vector': 'Third-Party Supplier Compromise',
'description': 'A recent report from Databarracks reveals that 26% of UK '
'businesses experienced a cyber incident originating in their '
'supply chain over the past year, despite nearly half (48%) '
'admitting they continued working with suppliers despite known '
'security or resilience concerns.',
'impact': {'downtime': 'Leading cause of IT downtime for the fourth '
'consecutive year',
'operational_impact': 'Cascade effects from supplier disruptions'},
'lessons_learned': "Traditional 'tick-box' compliance assessments are "
'insufficient; direct ownership of supplier risks and '
'collaborative resilience planning are needed, especially '
'with smaller or less mature suppliers.',
'post_incident_analysis': {'corrective_actions': ['Direct ownership of '
'supplier risks',
'Collaborative resilience '
'planning with suppliers',
'Unified approach to IT and '
'business resilience'],
'root_causes': ['Dependence on critical suppliers '
'with known security/resilience '
'concerns',
'Lack of viable alternatives to '
'high-risk suppliers',
'Insufficient visibility beyond '
'immediate partners']},
'ransomware': {'ransom_paid': '18% paid ransoms'},
'recommendations': ['Integrate IT and business resilience',
'Improve supplier resilience assessments beyond '
'onboarding',
'Avoid working with high-risk suppliers when alternatives '
'exist',
'Enhance visibility into supply chain risks'],
'references': [{'source': 'Databarracks Data Health Check 2026'}],
'response': {'recovery_measures': '59% of ransomware victims recovered via '
'backups'},
'title': 'UK Businesses Struggle with Supply Chain Cyber Risks',
'type': 'Supply Chain Attack'}