
Supply Chain Attacks: Recent Examples, Trends & How to Prevent Them in 2027
Anna Fitzgerald
Senior Content Marketing Manager
Emily Bonnie
Senior Content Marketing Manager
Nearly half of all data breaches (48%) now involve a third party, according to Verizon's 2026 Data Breach Investigations Report. This represented a 60% year-over-year increase.
As hackers increasingly target supply chains, most organizations fear that their suppliers aren’t prepared to defend themselves. SecurityScorecard’s 2026 survey found that 86% of global cybersecurity leaders are deeply concerned about supply chain risks.
This concern extends to the private and public sector, with governments increasingly rolling out regulatory requirements related to supply chain risk management. For example, a July 2026 executive order directed the Department of War to write rules requiring contractors to map their critical supply chains down to the origin of raw materials and vet suppliers for foreign ownership and cyber risk. This is on top of existing DFARS 252.204-7012 and CMMC Phase 1 contractual obligations in force today, which mandate NIST SP 800-171 implementation and flowdown requirements.
To help understand and navigate the latest supply chain risks and regulations, we’ve rounded up some of the most consequential supply chain attacks of the past 18 months to extrapolate key takeaways and trends for 2027 and beyond. Keep reading for these examples plus a complete overview of the major types of supply chain attacks, how they work, and how you can prevent them.
Recent supply chain attacks and trends
Supply chain incidents in the past year and a half have clustered around three targets: open-source software that teams trust implicitly, defense contractors handling sensitive unclassified information, and the operational technology running physical infrastructure. Here are seven recent incidents and what they tell us about supply chain risk heading into 2027.
1. LiteLLM supply chain attack
Date: March 2026
Impact: 153GB of data exfiltrated from over 2,500 organizations across approximately 430,000 CI/CD pipelines
On March 24, 2026, a threat actor tracked as TeamPCP used the previously compromised open-source vulnerability scanner Trivy to steal the PyPI publishing tokens for LiteLLM, a widely used open-source library that routes requests across large language model providers. The attacker then published two backdoored LiteLLM versions, 1.82.7 and 1.82.8.
According to LiteLLM's own incident report, those packages were live for roughly 40 minutes before PyPI quarantined them. But 40 minutes was long enough for the malicious code to propagate, ultimately exposing 434,000 CI/CD pipelines and impacting over 2,500 organizations across technology, industrial, financial, and telecommunications firms and making it the largest AI supply chain breach of 2026.
According to analysis of the exfiltration archive, 153GB of data was compromised, including environment variables, cloud credentials, API tokens, and configuration files. Since hackers can use these secrets to take over accounts, inject malicious commits, disrupt services, deploy malware, and mount other types of attacks, organizations are being urged to rotate keys and secrets, review audit logs, and check for unauthorized files or suspicious activity.
Emerging trend
Future attacks are expected to continue to target the AI layer because it connects to, and can therefore expose, so many systems and identities around it. Open-source libraries like LiteLLM are also often dependencies used in autonomous agent frameworks and orchestration tools, meaning teams can be exposed by downstream AI packages without realizing it.
Verizon's 2026 DBIR finding that employee use of unapproved AI tools tripled from 15% to 45% in a single year points at the same underlying problem: AI infrastructure is entering organizations faster than governance is catching up. But given the scale and criticality of this new attack layer, organizations must extend the same security scrutiny to AI systems as other critical enterprise infrastructure.
Recommended reading
Software Supply Chain Security: Why Your Organization Must Protect Its Software Supply Chain
2. Lockheed Martin breach claim
Date: March 2026
Impact: 375 TB of data, including F-35 aircraft blueprints, allegedly stolen and ransomed for over $400 million
In March 2026, a pro-Iran hacktivist collective calling itself APT Iran claimed to have stolen 375 TB of data from Lockheed Martin, according to reporting by Cybersecurity Dive. The group posted on social media network Telegram claiming to hold copies of F-35 aircraft blueprints alongside other corporate files and demanding a ransom exceeding $400 million to prevent the sale of this sensitive data to U.S. adversaries.
Lockheed Martin acknowledged the reports without confirming a breach. A company spokesperson said it has policies and procedures in place to mitigate cyber threats and remains confident in the integrity of its information systems and data security.
Emerging trend
Targeting has shifted from data monetization toward strategic value. A hacktivist collective aligned with a foreign state is not primarily interested in reselling records. The value is in controlled technical information: engineering drawings, specifications, and test data with military application. That is precisely the category of CUI that DFARS 252.204-7012, CMMC, and NIST SP 800-171 exist to protect.
It also underscores how much of a prime's technical data lives outside the prime. A program like F-35 involves thousands of suppliers, and the same drawings that sit in a prime's PLM system get shared down through tiers of subcontractors, many of them small manufacturers with limited security staff. An adversary that cannot get into the prime has a large number of alternative doors.
This is the reasoning behind prime contractor flowdown enforcement of CMMC and DFARS 7012.
Recommended reading
Which Prime Contractors Have Begun Enforcing CMMC in Their Supply Chains?
3. Coordinated OT attacks on U.S. water systems
Date: July and August 2026
Impact: Operational disruptions at water and wastewater facilities across at least seven states
Between July 26 and July 28, 2026, water operators across Minnesota reported failures at water treatment plants. In Braham, a town of roughly 1,700, the pump at the treatment plant stopped working and crews took the plant offline while residents drew on a backup tank. Minnesota state IT teams attributed the outages to a coordinated cyberattack against industrial technology nationwide, which targeted 30 water systems in Minnesota alone.
The pattern repeated elsewhere. Clayton County outside Atlanta issued a boil-water advisory after an overnight pump station failure. There were outages in New Jersey and Michigan. The FBI later confirmed that at least seven states experienced similar attacks on water and wastewater facilities, with the investigation ongoing.
The entry method for most of these attacks: operational technology. Attackers went after programmable logic controllers exposed directly to the internet and in many cases running default credentials, outdated software, or misconfigurations.
Emerging trend
Rob Lee, CEO of the industrial cybersecurity firm Dragos, told NPR he could not recall a time “when there's been this many targets at once with operational impact" and that he was aware of victims outside the water sector. That makes sense given that critical infrastructure operators tend to run the same aging and specialized technology.
The challenge is that operational technology is hard to replace, patch, and secure. As one former municipal CIO explained to NPR, the devices that open valves and dose chemicals run on small industrial computers that cannot be updated on demand because the manufacturer has to certify the fix and the plant may have to come offline. Sometimes no fix exists at all.
That’s why federal agencies including CISA and the DoW are increasingly focused on managing IT and OT risks, most recently releasing guidance on adapting Zero Trust principles to OT as well as Brilliant at the Basics with a list of Top 10 best practices for OT. The DoW CIO also recently indicated at DIBX 2026 that OT security may be at the center of CMMC reform.
Recommended reading
Brilliant at the Basics vs. NIST 800-171: What Defense Contractors Need to Know About the DoW's Cybersecurity Campaign
4. Jaguar Land Rover supply chain attack
Date: September 2025
Impact: Weeks-long production halt costing $2.5B and likely causing thousands of layoffs
Starting on August 1, a cyber attack on the global car giant Jaguar Land Rover (JLR) brought vehicle production to a standstill across the U.K., Slovakia, India, and Brazil, costing the company an estimated £120 million in lost profit and £1.7 billion in revenue.
As the U.K.'s largest automotive employer, JLR's production halt sent shockwaves through its supplier network, triggering layoffs, factory shutdowns, and bankruptcies. Nearly 80% of firms surveyed by the Black Country Chamber of Commerce reported negative impacts from the cyberattack, and 14% had already made redundancies by late September.
It is already considered the most economically damaging cyberattack in British history, likely costing the country a whopping £1.9 billion ($2.5 billion).
Emerging trend
The attack on JLR highlights how deeply interdependent global manufacturing has become, so that one breach can ripple across entire economies. The U.K.'s National Cyber Security Centre now warns of four "nationally significant" cyberattacks every week, double the previous year's average. That makes it more important than ever for operational technology and industrial suppliers to strengthen cyber resilience immediately.
There has been a surge in EU regulations in the past decade as a result, including the Trusted Information Security Assessment Exchange (TISAX) for the automotive supply chain specifically.
5. Asahi supply chain attack
Date: September 2025
Impact: System outage forced production halts at 30 domestic plants leading to product shortages across the national and global beer supply chain
At the end of September, Asahi, the brewer behind Japan's best-selling beer with a 40% share of the domestic market, was hit by a cyberattack that halted production at most of its 30 factories. For weeks, operations were forced offline, with staff reverting to pen and paper to process orders and shipments.
The outage caused widespread product shortages in convenience stores and supermarkets across the country and impacted shipping, orders, and customer service nationwide for months, with Asahi Breweries planning to resume shipments of all its products starting April 7, 2026. The personal data of approximately 1.9 million individuals, including 1.5 million customers, may have been exposed during the attack as well.
The direct financial impact was estimated to be $31.4 million in lost revenue and $12.6 million in lost profit.
Emerging trend
Unlike past cyberattacks that solely aimed at stealing customer data or financial records, the Asahi breach is part of a growing wave targeting vulnerabilities in operational technology across the manufacturing sector in order to paralyze operations and extract ransoms. These incidents show that attackers are now striking at the core of production, logistics, and distribution, where downtime translates directly into lost revenue and other commercial consequences.
Organizations in the manufacturing sector are particularly exposed, since many still rely on legacy systems and lack sufficient cybersecurity expertise, as many in Japan do. Manufacturing has been the most targeted industry for cyber attacks worldwide five years in a row, according to IBM's X-Force Threat Intelligence Index, and accounts for 65% of all cyberattacks in the Asia-Pacific region. As operations grow more automated and connected, the line between cyber risk and business risk is disappearing.

Looking to strengthen your supply chain defenses before a breach or incident like this hits? Download our Supply Chain Risk Management Policy Template to put the right processes and documentation in place.
6. Marks & Spencer supply chain attack
Date: May 2025
Impact: Major operational disruptions that halted online shopping and reduced food availability, costing £300M in profit
In May 2025, UK retailer Marks & Spencer (M&S) suffered a highly targeted cyberattack traced back to social engineering against employees at a third-party contractor. The breach forced M&S to manually operate critical logistics processes, disrupted food distribution, reduced availability across stores, and temporarily halted online shopping. With more than 60,000 employees and 500 stores, the operational slowdown quickly escalated into broader supply chain and revenue impacts, including increased waste, higher stock management costs, and an estimated £300 million ($400 million) loss in operating profit for 2025/2026.
The attack was part of a coordinated campaign by the ransomware group DragonForce, which also targeted Co-op and Harrods before shifting focus to U.S. retailers.
Emerging trend
The M&S incident highlights how attackers are increasingly exploiting third-party contractors to infiltrate complex retail supply chains where the consequences extend far beyond data loss. These disrupt logistics, in-store availability, and e-commerce operations and often result in significant profit losses.
Retailers have therefore become high-value targets for financially motivated and opportunistic ransomware groups, with recent breaches at Dior, M&S, Harrods, and Co-Op illustrating a pattern of escalating, industry-wide vulnerability.
The attack vector also matters, not just the target. Verizon's 2026 findings show that social engineering remained the third most common attack pattern, accounting for 16% of confirmed breaches, but the techniques are evolving. Mobile-centric social engineering, meaning fake text messages and voice calls, for example, succeeded at a rate 40% higher than traditional email phishing.
7. National Defense Corporation supply chain attack
Date: March 2025
Impact: Leak of procurement and logistics data across multiple defense manufacturing subsidiaries
In March 2025, the home appliance and ammunition manufacturer National Presto Industries and its defense subsidiary, National Defense Corporation (NDC), were targeted by the Interlock Ransomware Group. The attackers claimed to have stolen roughly three million files and encrypted systems belonging to several affiliated entities, including AMTEC, a key supplier of ammunition and explosives for the military and law enforcement.
While no classified materials were confirmed as exposed, compromised procurement and logistics data could disrupt critical supply lines supporting military operations. The attack underscored how cybercriminals and potentially state-sponsored actors are exploiting lower-tier suppliers to gain visibility into the Defense Industrial Base's broader logistics network.
Emerging trend
The NDC incident reflects a broader shift in ransomware tactics, from opportunistic data theft to targeted attacks on critical infrastructure and the defense sector in particular. Cybercriminals and, in some cases, state-sponsored actors are increasingly targeting lower-tier suppliers to infiltrate the DIB's logistics network for economic or military gain.
Regulatory scrutiny of defense and other government contractors has intensified alongside it, with the DOJ announcing an all-time high in False Claims Act recoveries for FY 2025. $52 million was recovered in settlements against contractors and grant recipients who failed to meet contractual cybersecurity requirements, more than triple the previous two years. Several resolved allegations of noncompliance with NIST 800-171 controls required through DFARS 7012.
This underscores the messaging behind the CMMC Phase 2 pause: While the rollout of third-party assessment requirements is currently on hold pending a program review, the underlying obligations are not. DFARS 252.204-7012 still requires NIST SP 800-171 implementation, SPRS scores and annual affirmations are still expected, and primes are still enforcing flowdown on their own timelines.
Not sure where your NIST 800-171 implementation stands? Download the NIST 800-171 compliance checklist to work through all 110 requirements.
Recommended reading
CMMC Cybersecurity Misrepresentation: The False Claims Act Cases DIB Contractors Should Know
What is a supply chain attack?
A supply chain attack occurs when an adversary targets an organization, person, process, information, or resource that is part of a supply chain as a means to infiltrate downstream or upstream systems rather than attacking the target organization directly.
Because many companies rely on third-party components and services, an exploit at any link in a supply chain can expose vast numbers of businesses to operational disruption, corruption, data disclosure, or destruction. That link might be a trusted partner, a service provider, a software vendor, an open-source library, or a hardware component.
An adversary may target a smaller supplier with lower cyber maturity in order to gain access to a larger organization with higher cyber maturity, or it may target a larger supplier with hundreds or thousands of customers and users in order to maximize its impact.
Within this broader domain, software supply chain attacks refer specifically to when software vendors are used as the attack vector. These attacks often originate from malicious updates, injected dependencies, compromised build pipelines, or open-source library backdoors.
All types of supply chain attacks are rising in frequency and impact because organizations are increasingly dependent on third-party software, open-source libraries, outsourced services, and interconnected vendor ecosystems. The trust model that allows enterprises to scale also creates expanded attack surfaces.
Recommended reading
Supply Chain Risk Management (SCRM) in 2026: The Process + Policy Template You Need
How do supply chain attacks work?
Supply chain attacks exploit a third-party dependency, such as a service provider or open-source library, in order to gain access to a target organization's systems or as many users as possible. Once inside other systems, attackers can deepen access, elevate privileges, and expand reach.
Attackers can exploit a third-party dependency in many ways: insertion of counterfeits, unauthorized production, tampering, theft, insertion of malicious software or hardware, and poor manufacturing and development practices in the cybersecurity-related elements of the supply chain.
Here is how a supply chain attack works broadly:
- Attackers compromise a trusted vendor or component. For example, attackers may inject malicious code into widely-used open-source libraries.
- Malicious code is introduced in other vendors' products, software, or updates, allowing attackers unauthorized access. Organizations then include those compromised components in their software builds or other parts of their supply chain.
- Customers install or use the vendor's products, software, or updates. The malicious code propagates downstream to customers and other third parties.
- Attackers use that foothold to move laterally, escalate privileges, steal data, or disrupt operations. Because the compromised vendor or component is trusted, detection may be delayed, which allows attackers to do more damage. Many downstream customers might be impacted before remedial measures occur.

Types of supply chain attacks
Supply chain attacks take many forms, depending on where attackers insert themselves into the supply chain and at which stage of the lifecycle: design, development, manufacturing, processing, handling, and delivery.
Below are the most common types, each with real-world examples that show how these attacks unfold and why they are so difficult to detect.
1. Software update compromise
In this type of attack, an adversary infiltrates a software vendor's update environment to insert malicious code into otherwise legitimate software updates. Because these updates are trusted and often automatically applied, thousands of downstream customers can be compromised before anyone notices.
This technique gives attackers immediate access inside networks that would otherwise be difficult to penetrate.
Notable example: SolarWinds (2019)
Beginning in 2019, a nation-state adversary breached the computing networks of SolarWinds, eventually inserting malicious code into a software update for its network management and monitoring suite of products called Orion. This update was distributed to over 18,000 customers, including federal agencies and Fortune 500 companies. Once installed, the trojanized code provided the adversary with a backdoor to breach the infected systems of a smaller subset of high-value customers for the primary purpose of espionage.
To date, it remains one of the most widespread and sophisticated supply chain attacks ever conducted against the federal government and private sector.
2. Software development compromise
In this type of attack, attackers infiltrate a software vendor's development environment, such as CI/CD pipelines, build servers, or signing infrastructure, to inject malicious code into software before it is released. Typically, the attackers will use a common delivery mechanism like an email attachment or removable media to infiltrate the environment.
This type of attack is particularly dangerous because it originates upstream and abuses trusted developer workflows.
Notable example: Codecov (2021)
In 2021, attackers gained unauthorized access to the development environment of software testing firm Codecov and modified its Bash Uploader script, a tool used by more than 29,000 customers, including GoDaddy, Washington Post, and Royal Bank of Canada, in their CI/CD pipelines. The altered script silently exfiltrated sensitive information including environment variables containing secrets, credentials, and tokens from downstream customers' build systems for two months undetected.
Recent example: TeamPCP and the security scanner cascade (2026)
The 2026 LiteLLM compromise described above is the current reference case for this category, and it added a twist. The initial compromise hit vulnerability scanning tools running inside CI/CD workflows, then propagated into a widely used package, then harvested credentials from the pipelines of thousands of downstream organizations. Infiltrating a single upstream build component can expose thousands of organizations that rely on trusted development tools, and security tooling is not exempt from that.
3. Open-source dependency compromise
Modern software relies heavily on open-source libraries and code, which can introduce a serious design vulnerability in the acquisition process. Attackers can exploit this by injecting malicious code into widely used packages or by compromising maintainers directly, such as through credential theft or phishing.
Once compromised code is added to software builds, the malicious instructions propagate downstream to consumers. Because open-source code is so commonly used, this type of attack can impact millions.
Notable example: NPM maintainer compromise (2025)
In September 2025, attackers reportedly launched a targeted phishing campaign to compromise Node Package Manager (npm) maintainer accounts and inject malicious code into widely-used JavaScript packages. On average, these npm packages are downloaded over 2.6 billion times per week globally, making it one of the most significant attacks on the JavaScript ecosystem in recent memory and highlighting the growing supply chain risk in cloud-native development environments.
4. Third-party service provider breach
Instead of compromising the target organization's own software, attackers may breach a third-party contractor's software in order to gain unauthorized access to the target. Common victims are consulting firms, SaaS platforms, and managed service providers (MSPs). Since these integrate deeply with customer environments, a single breach can spread quickly and silently across hundreds of organizations.
Notable example: Workday (2025)
In August 2025, HR and finance software provider Workday suffered a data breach after fraudsters gained access to its third-party CRM platform through a targeted social engineering campaign. Attackers impersonated HR and IT staff via phone and text messages to trick employees into providing login access or their personal information in order to access customers' business contact information.
While no customer tenant data was compromised, the incident highlights how attackers increasingly target the extended ecosystem around major SaaS providers to try to access vast amounts of sensitive business data.
For DIB contractors, this category carries specific compliance weight. If an external service provider handles your CUI, that provider is in scope for your assessment, and outsourcing does not transfer the obligation.
5. Hardware tampering or substitution
While software supply chain attacks are prominent in news headlines and cybersecurity efforts, hardware also poses a serious threat. Attackers can intercept legitimate hardware and replace it with faulty counterfeits, tamper with it when it is being packaged, shipped, or transferred to contractors, or embed malicious functionality during procurement, maintenance, or upgrades.
Because compromised hardware often appears authentic and functions normally at first, it can remain undetected until triggered by remote signals, timers, or environmental changes. This type of attack can undermine entire supply chains and is especially dangerous in critical infrastructure and defense sectors.
Example: Cisco counterfeit hardware scheme (2013 to 2022)
Between 2013 and 2022, criminal distributors imported counterfeit Cisco networking equipment from China and Hong Kong and resold it through dozens of storefronts, falsely marketed as new and genuine. The devices were deployed across U.S. hospitals, schools, and highly sensitive military systems, including platforms supporting F-15, F-18, and F-22 fighter jets, Apache helicopters, and B-52 bombers.
The case illustrates how hardware substitution can infiltrate mission-critical environments, erode trust in global supply chains, and create long-term national security risks. It is also the clearest argument for the provenance tracing contemplated in EO 14415: counterfeit components reached combat platforms precisely because no one could trace parts back to their origin.
Recommended reading
2026's Biggest Cybersecurity Threats: Analyzing Recent Attacks and How to Defend Against Them
How to prevent supply chain attacks
Supply chain attacks are difficult to detect because they exploit trusted relationships: between organizations and their vendors, software providers, or contractors. But while these attacks are complex, there are proven ways to reduce your exposure and limit their potential impact.
The recommendations below combine recent statistics with technical, procedural, and organizational best practices to help protect your business from the most current supply chain threats.
These align with requirements from major federal and commercial security frameworks, including NIST 800-53, which has an entire control family around supply chain risk management, plus NIST SP 800-171, CMMC, ISO 27001:2022, SOC 2, PCI DSS, GDPR, Microsoft SSPA, and TISAX. Implementing them can mitigate supply chain risks, strengthen your overall security and compliance posture, and maintain your subcontracts and place in supply chains.
1. Establish a supply chain risk management policy
Organizations face an average of 12 third-party breaches per year, or about one per month, according to ProcessUnity’s State of Third-Party Risk Assessments 2026 report. Having a policy in place is the first step to mitigating increasing supply chain risk.
Before they begin evaluating vendors, organizations need a formal Supply Chain Risk Management (SCRM) policy that defines how they identify, assess, onboard, monitor, and offboard third-party suppliers. This policy ensures that all relevant information security requirements are documented, agreed upon, and enforced with every vendor that stores, processes, transports, or otherwise touches your data or IT infrastructure.
An SCRM policy should outline:
- expected security controls
- evidence requirements
- contractual obligations
- incident notification timelines
- consequences for noncompliance
This policy is foundational to frameworks like NIST 800-53, NIST 800-171, CMMC, ISO 27001:2022, and SOC 2, which all require clear supply chain governance. For defense contractors, it is also the document the forthcoming EO 14415 vetting requirements will most likely build on, so writing it now is not wasted effort.

Supply Chain Risk Management Policy Template
Our Supply Chain Risk Management Policy Template can help you meet core requirements across frameworks like CMMC, SOC 2, and ISO 27001 and strengthen third-party controls before a breach or security incident hits.
2. Map your supply chain before you assess it
You cannot vet suppliers you have not inventoried. 78% of companies say that less than half of their total supply chain is currently overseen by their internal cybersecurity program, and 35% of respondents revealed that only 1% to 10% of their supply chain is covered.
Start by mapping all third-party providers, from cloud and software vendors to managed service providers and contractors. Record what each one touches: which systems, which data, which level of access. For software specifically, that means knowing your dependencies, including transitive ones, since the LiteLLM compromise reached organizations that never chose to install it.
This step is particularly important for defense contractors trying to scope their CMMC assessment correctly or prepare for requirements proposed by EO 14415.
3. Conduct thorough vendor and supplier due diligence
Strengthening vendor compliance management and due diligence is a priority for operational continuity, and increasingly for contract eligibility.
Evaluate suppliers' security controls before granting access to your environment. Request compliance reports and attestations for frameworks like SOC 2, ISO/IEC 27001, or CMMC, and require security clauses in contracts to ensure vendors maintain adequate protections.
Reviewing audit reports, penetration testing results, and incident response capabilities can also help you identify potential weak links before they become exploitable.
If you handle CUI, add two questions to your standard diligence: whether the supplier has a current SPRS score on file, and whether any export-controlled or ITAR data is flowing down to them. Both come up in prime flowdown reviews well before any government assessment does.
4. Close the vulnerability remediation gap
Vulnerability exploitation is now the top breach entry point at 31%, per the 2026 DBIR, and AI has compressed the time from disclosure to weaponization from months to hours. That changes the math on patching: a remediation cycle measured in weeks is no longer a conservative posture, it is an exposed one.
Prioritize by exploitability rather than by CVSS score alone. Track known exploited vulnerabilities in the components you actually run, including those inside vendor products and build tooling, and set separate service levels for internet-facing systems. Where a system genuinely cannot be patched, which is common in OT environments, compensate with segmentation and monitoring rather than accepting the risk silently.
5. Secure your build and deployment pipelines
Build systems are prime targets for software supply chain attackers, and the 2026 incidents show why: a single compromised package reached thousands of CI runners holding cloud credentials and API tokens.
Protect them by implementing least-privilege access, code signing, and strict change management controls. Require multifactor authentication (MFA) for all build servers and use dedicated credentials for automation systems.
Pin your dependencies and build from locked manifests. Incorporate security testing, including static and dynamic analysis, dependency scanning, and integrity verification, into your continuous integration and continuous deployment (CI/CD) pipeline. And treat the credentials available to your build environment as compromised-by-default in planning: rotate them on a schedule, scope them narrowly, and make sure you can revoke them quickly.
6. Implement continuous vendor monitoring
Due diligence should not stop at onboarding or be a point-in-time activity. Yet 67% still list static security audits as their top risk-assessment method and 46% rely on periodic assessments conducted monthly or quarterly for monitoring. As a result of this reliance on manual and inconsistent assessments, only about a third of suppliers (36%) are being assessed.
More frequent and automated continuous monitoring allows you to track changes in a vendor's security posture over time and quickly respond to emerging risks. AI and automation tools can alert you to new vulnerabilities, expiring certificates, or reported breaches that might impact your organization.
Establish a third-party risk assessment process that includes automated detection of high-risk vendor activity and tiering of vendors or escalation based on criticality and data sensitivity. Point-in-time attestation tells you what was true on the day of the audit, which is a weak signal in an environment where a vendor's exposure can change in 40 minutes.
Recommended reading
Supply Chain Risk Assessment: How to Actually Evaluate Third-Party Risk in 2026 + Template
7. Strengthen access controls and network segmentation
Only 38% of organizations in 2026 said they implement proactive breach prevention controls, meaning most programs are reactive and ad-hoc. Maturing these programs requires standardized and repeatable policies, tools, and remediation processes, starting with access controls and segmentation.
Vendors and contractors often require access to your systems, but that access should be as limited and monitored as possible. As part of your vendor access management program, enforce the principle of least privilege and apply just-in-time access for sensitive environments.
Segment vendor access from your core network, monitor all third-party sessions, and require secure methods of connection such as zero-trust network access (ZTNA) or VPN with strong MFA. If a vendor is breached, these safeguards can prevent lateral movement and limit the blast radius of an attack.
Segmentation deserves particular attention where IT and OT converge. The 2026 water sector attacks reached controllers that were exposed to the open internet, often with default credentials still in place. The FBI's guidance for operators emphasizes the fundamentals: change default credentials, take industrial machines off the public internet, separate them from business networks, and put access controls and firewalls in front of them.
8. Prepare an incident response plan that includes vendors
When a supply chain attack occurs, quick action matters. Yet 60% of organizations say that a critical vendor needs over a week to resolve a high-severity security issue, over half still rely on time-consuming communication methods like calls, meetings, emails, or key business contacts during remediation.
To improve your response capabilities, develop an incident response plan that clearly defines how to contact and coordinate with affected vendors, contain the compromise, and communicate with customers or regulators.
Conduct tabletop exercises that include third-party breach scenarios, and ensure vendor contracts specify notification timelines and cooperation expectations. Defense contractors should build the DFARS 252.204-7012 72-hour cyber incident reporting requirement directly into that plan, including scenarios where the incident originated at a supplier rather than in your own environment.
9. Build the right supply chain security expertise
Even the best processes fall short without the right people trained to execute them.
Provide supply chain and anti-counterfeit training to procurement, logistics, and vendor-management staff, a key requirement in NIST 800-53's SR controls. This helps teams identify red flags early, spot counterfeit or tampered components, and respond quickly to signs of vendor compromise.
Extend that training to cover voice and text-based social engineering, given that mobile-centric pretexting is now succeeding at a rate 40% higher than email phishing, and both the M&S and Workday incidents began with attackers calling people.
Organizations should also consider assigning a dedicated supply chain security lead or team to oversee supplier risk, coordinate assessments, and manage incident response across vendors and contractors.
Recommended reading
Third-Party Security: 8 Steps To Assessing Risks And Protecting Your Ecosystem
How Secureframe helps protect against supply chain attacks
Supply chain attacks represent a growing and unique threat vector. Because attackers increasingly target trusted vendors, software build pipelines, hardware manufacturers, and service providers, companies must shift from an insular approach to security toward securing the entire chain of trust.
Secureframe can help companies make this shift. With Secureframe, you can:
- Automate compliance management to cybersecurity frameworks like SOC 2, NIST 800-53, NIST 800-171, CMMC, and FedRAMP that include overlapping and unique supply chain security controls, enabling organizations to meet requirements efficiently.
- Continuously monitor your infrastructure, applications, and vendor ecosystem to detect misconfigurations and vulnerabilities in real time.
- Detect misconfigurations or issues through real-time dashboards and assign remediation tasks via Slack, Jira, email, or directly within the platform.
- Automate remediation of security misconfigurations with step-by-step guidance or infrastructure-as-code fixes generated automatically by Comply AI.
- Streamline third-party risk management (TPRM) by integrating with your suppliers, retrieving security documentation, and automating supplier risk assessments.
- Enhance software integrity by verifying vendor security postures, tracking risk assessments, and managing supplier compliance documentation.
- Integrate your cloud platform and developer tools to see all of your vulnerabilities from services like AWS Inspector and GitHub in one place.
- Get guidance and answers from compliance managers and a partner network of trusted auditors and pen testing firms.
For contractors in the Defense Industrial Base, Secureframe Defense adds the CMMC-specific layer: automated evidence collection against all 110 NIST 800-171 requirements, SSP and POA&M generation, real-time SPRS scoring, and continuous monitoring that keeps documentation current as your environment changes. That matters most for the part of supply chain security that never ends, which is proving to your DoW contracting officer, primes, or assessor that your controls were working the whole time and not just on assesment day.
Ready to secure your supply chain? Schedule a demo with Secureframe today to learn how we can help you improve supply chain risk management and operational resilience.
This post was originally published in November 2025 and has been updated for accuracy and comprehensiveness.
FAQs
What are supply chain attacks?
Supply chain attacks exploit the ecosystem of suppliers, third-party services, software vendors, and hardware manufacturers that organizations rely on in order to breach a target organization. Rather than attacking the target directly, adversaries compromise a trusted link in the chain, either because that link is easier to hack or because the intrusion is harder to detect.
What percentage of breaches involve a third party?
48%, according to Verizon's 2026 Data Breach Investigations Report, which analyzed breaches occurring in 2025. That represents a 60% increase over the prior year and makes third-party involvement one of the largest single categories Verizon tracks.
What are software supply chain attacks?
Software supply chain attacks are a subset of supply chain attacks that target software during the development, build, packaging, update, or distribution stages, such as when malicious code is inserted into a library, software update, or build pipeline.
How do supply chain attacks work?
A supply chain attack typically works like this:
- An adversary compromises a vendor or library.
- The adversary inserts malicious code or components to gain unauthorized access to a system.
- The compromised product, component, or update is distributed, propagating access to downstream or upstream systems.
- The adversary deepens access to customers' or other networks in order to steal data, disrupt operations, or otherwise cause damage.
Does the July 2026 executive order create new cybersecurity requirements for defense contractors right now?
Not yet. Executive Order 14415 directs the Department of War to develop policies within 180 days and implementing regulations within 90 days after that. Contractors will have obligations once those regulations are issued, not before. The order does signal the direction: supply chain mapping down to raw-material origin, written supplier vetting procedures covering foreign ownership and cyber risk, and reporting of significant risks within 15 days of completing vetting.
Is an indentured bill of materials the same as an SBOM?
No. An SBOM inventories software components and their dependency relationships. The indentured BOM described in EO 14415 would be broader, connecting software and firmware dependencies to physical components, manufacturers, suppliers, maintenance records, countries of origin, and raw-material sources in a single traceable artifact.
Do defense contractors still need to meet NIST 800-171 requirements while CMMC Phase 2 is on hold?
Yes. The pause affects the CMMC assessment and verification layer, not the underlying security requirements. DFARS 252.204-7012 still requires implementation of NIST SP 800-171, SPRS score submission and annual affirmations still apply, and primes continue to enforce flowdown on their own schedules regardless of where the government rollout stands.
Are attacks on operational technology considered supply chain attacks?
Sometimes, and the 2026 water sector attacks illustrate why. No single vendor was breached to reach those facilities. But thousands of independent operators run the same controllers from the same manufacturers, frequently integrated by the same service providers, so a single exposed device class produces simultaneous impact across hundreds of organizations. Shared technology dependency functions as a supply chain even when no supplier is the entry point.

Anna Fitzgerald
Senior Content Marketing Manager
Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.