Supply chain attacks have emerged as the most common cyberthreat businesses faced over the past 12 months, according to a new global study commissioned by Kaspersky. The study found that 31% of enterprise businesses globally and 30% of companies in Saudi Arabia experienced a supply chain attack during that period.
The findings place supply chain threats ahead of all other cyberthreat categories. Moreover, data from the World Economic Forum shows that 65% of large enterprises identify third-party and supply chain vulnerabilities as their greatest barrier to cyber resilience.
Large Enterprises Bear the Highest Exposure to Supply Chain Attacks
Large enterprises — defined as organizations with 2,500 or more employees — reported the highest rate of supply chain attacks at 36%. This figure exceeds the rates recorded among low-size enterprises (500–1,499 employees) and mid-size enterprises (1,500–2,499 employees).
The study links this elevated exposure to the scale of supplier relationships. Large enterprises manage an average of approximately 100 software and hardware suppliers, creating a broad potential attack surface. In addition, these organizations grant system access to an average of more than 130 contractors, compared to roughly 50 for smaller enterprises.
Trusted Relationship Attacks Also on the Rise
A related threat category — trusted relationship attacks — affected 25% of companies globally over the past year. In Saudi Arabia, 21% of organizations reported experiencing such attacks. These incidents occur when attackers exploit legitimate connections between organizations to gain unauthorized access.
The high contractor counts at large enterprises consequently increase exposure to this vector. Attackers can leverage trusted third-party access to move laterally within target networks.
“We’re operating in a digital ecosystem where every connection, every supplier, every integration becomes part of our security profile. As organizations grow more interconnected, their exposure to attacks grows with them. Against this landscape, protecting the modern enterprise now demands an ecosystem-wide approach that strengthens not just individual systems, but the entire network of relationships that keeps business operating.”
Sergey Soldatov, Head of Security Operations Center, Kaspersky
Kaspersky Recommendations for Reducing Supply Chain Risk
Kaspersky outlined six measures organizations should adopt to reduce cybersecurity exposure across their supplier networks. The recommendations cover vendor evaluation, contractual obligations, technical controls, and incident response planning.
- Evaluate suppliers thoroughly before entering agreements, including reviewing cybersecurity policies, past incidents, and compliance with industry security standards. For software and cloud services, review vulnerability data and penetration test results.
- Implement contractual security requirements, conduct regular security audits, and ensure suppliers comply with incident notification protocols.
- Adopt preventive technical measures including the principle of least privilege, zero trust architecture, and mature identity management systems.
- Use continuous monitoring solutions such as Kaspersky Next XDR or MXDR to detect anomalies in software behavior and network traffic in real time.
- Develop an incident response plan that specifically covers supply chain attacks, including steps to isolate compromised suppliers from company systems.
- Collaborate with suppliers on security priorities, treating protection as a shared responsibility across the partnership.
Study Methodology and Scope
The Kaspersky-commissioned survey questioned 1,714 technical experts across 16 countries, including Saudi Arabia, Germany, China, India, the United Arab Emirates, and Russia. Respondents ranged from C-level executives and vice presidents to team leads and senior specialists at enterprises with more than 500 employees.
The study provides a broad view of how businesses across major economies are managing the growing risks associated with digital supply chain interdependence. As organizations continue expanding their supplier and contractor networks, the findings suggest that ecosystem-level security strategies will become increasingly necessary.

