Skip to main content
2/11/2026Insights

Software Supply Chain Failures

More than 90% of organizations have experienced a software supply chain incident in the past 12 months, according to research… Read more

Explore vulnerability-exploitation intelligence in the live cyber intelligence feed.

Explore

Related signal context

Open the classified signal themes connected to this analysis.

More than 90% of organizations have experienced a software supply chain incident in the past 12 months, according to research by Enterprise Strategy Group (ESG). Gartner even expects the costs of such attacks to rise to $138 billion annually worldwide by 2031. Multiple studies show similar figures.

The leading OWASP (The Open Worldwide Application Security Project) has placed software supply chain failures as a new category at number 3 in their 2025 Top 10. These are all signals to delve deeper into this development.

What are software supply chain failures?

A software supply chain failure occurs when a vulnerability, error, or malicious manipulation in the software chain leads to risks or incidents for consumers. This can happen at various points in the chain, for example

  • During software development (insecure code, vulnerable libraries)
  • In update processes (compromised updates)
  • Via third-party dependencies (open source packages, APIs)
  • Due to inadequate patch and vulnerability management by suppliers

The characteristic of this risk is that you are affected without directly doing anything 'wrong' yourself.

Why are these risks increasing?

Several developments are making software supply chain failures structurally more likely. Firstly, software is becoming increasingly modular. Modern applications consist of dozens to hundreds of external components and open-source libraries. Each additional dependency increases the risk.

Additionally, suppliers are automating their deployments and updates. This increases speed but makes exploitation more scalable; a malicious update spreads rapidly. Finally, attackers are increasingly targeting suppliers with many customers. The return on a single successful attack is simply greater than individually hacking end-user organizations.

Known Examples

If you consult search engines, you will find a long list of incidents. The following examples have received more than average extensive news coverage.

  • SolarWinds (2020): One of the most well-known examples, where attackers infiltrated the “Orion” network management software and installed a backdoor via an automatic update for thousands of customers, including U.S. government agencies.
  • Log4j / Log4Shell (2021): A critical vulnerability in a widely used, open-source Java logging library. Because this library was present in countless applications, attackers could take over servers on a large scale.
  • Ivanti has repeatedly been targeted by advanced attackers in recent years. In 2023 and 2024, critical vulnerabilities were actively exploited by state-sponsored actors. In 2025, new critical flaws were discovered to gain control over corporate devices without login credentials. Researchers point out that the exploitation stems from the way Ivanti implements open-source components and fails to keep them up-to-date.

The Impact on Organizations

The consequences of software supply chain failures for your organization naturally depend heavily on your organization's reliance on this software and the severity of the disruption.

The primary direct impact may sometimes seem small, while the consequential damage can be significant. In the case of the Ivanti exploitation at the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr), this even led to accountability in the House of Representatives.

For many organizations, it is particularly painful that they had little insight into the underlying software supply chain and only gained clarity after the damage had already been done.

Why Traditional Vendor Assessments Fall Short

Many organizations still rely on annual questionnaires, certifications, or contractual agreements. While useful, these methods fall short with dynamic software supply chains, which can change every few weeks.

Questionnaires are snapshots; they say little about current vulnerabilities and provide no insight into technical dependencies. Software supply chain risk requires continuous monitoring and objective signals, not just paperwork.

Effectively dealing with software supply chain failures requires a different approach:

  • Identify which software vendors are critical to your processes
  • Map technical dependencies and digital supply chains
  • Continuously monitor vendors for vulnerabilities and incidents
  • Combine technical signals with risk context
  • Ensure clear internal responsibilities

The goal is not to exclude every risk, but to recognize early warning signs and limit impact.

Software Supply Chain Failures and RiskStudio

Within RiskStudio, software vendors are an explicit part of supply chain monitoring. By continuously profiling companies and software vendors based on their digital profile, vulnerabilities, and incidents, an up-to-date picture of software supply chain risk emerges.

Instead of isolated assessments, RiskStudio offers continuous insights, benchmarking, and alerts, enabling organizations to react proactively when a software supply chain failure occurs.

Conclusion

Software supply chain failures are no longer exceptional incidents but a structural risk in modern digital ecosystems. Organizations that rely on static assessments are falling behind. Only with continuous monitoring, insight into dependencies, and context-driven risk analysis can true control over the software supply chain be achieved.

References and Sources:

Frequently Asked Questions

What is the difference between a data breach and a software supply chain failure?

A data breach is often the consequence, while a software supply chain failure can be the underlying cause, for example, through a vulnerable supplier.

Does this risk only concern large software vendors?

No, smaller niche vendors can be critical precisely because they are deeply integrated into business processes.

How often should you assess software vendors?

Ideally continuously, as vulnerabilities and incidents can arise daily.

Is software supply chain risk relevant for NIS2?

Yes, NIS2 explicitly emphasizes supply chain and vendor risks, including ICT and software vendors.

FAQ

Questions about this analysis

What does this article explain?

More than 90% of organizations have experienced a software supply chain incident in the past 12 months, according to research… Read more

How is this analysis connected to current intelligence?

Related signal context is selected from current published reporting using the article subject, content and topic tags.

Where can I find related analysis?

Follow the article tags or return to the analysis archive to browse other reporting on connected subjects.