
Software Supply Chain Failures
More than 90% of organizations have experienced a software supply chain incident in the past 12 months, according to research… Read more
Explore vulnerability-exploitation intelligence in the live cyber intelligence feed.
Explore
Related signal context
Open the classified signal themes connected to this analysis.
More than 90% of organizations have experienced a software supply chain incident in the past 12 months, according to research by Enterprise Strategy Group (ESG). Gartner even expects the costs of such attacks to rise to $138 billion annually worldwide by 2031. Multiple studies show similar figures.
The leading OWASP (The Open Worldwide Application Security Project) has placed software supply chain failures as a new category at number 3 in their 2025 Top 10. These are all signals to delve deeper into this development.
What are software supply chain failures?
A software supply chain failure occurs when a vulnerability, error, or malicious manipulation in the software chain leads to risks or incidents for consumers. This can happen at various points in the chain, for example
- During software development (insecure code, vulnerable libraries)
- In update processes (compromised updates)
- Via third-party dependencies (open source packages, APIs)
- Due to inadequate patch and vulnerability management by suppliers
The characteristic of this risk is that you are affected without directly doing anything 'wrong' yourself.
Why are these risks increasing?
Several developments are making software supply chain failures structurally more likely. Firstly, software is becoming increasingly modular. Modern applications consist of dozens to hundreds of external components and open-source libraries. Each additional dependency increases the risk.
Additionally, suppliers are automating their deployments and updates. This increases speed but makes exploitation more scalable; a malicious update spreads rapidly. Finally, attackers are increasingly targeting suppliers with many customers. The return on a single successful attack is simply greater than individually hacking end-user organizations.
Known Examples
If you consult search engines, you will find a long list of incidents. The following examples have received more than average extensive news coverage.
- SolarWinds (2020): One of the most well-known examples, where attackers infiltrated the “Orion” network management software and installed a backdoor via an automatic update for thousands of customers, including U.S. government agencies.
- Log4j / Log4Shell (2021): A critical vulnerability in a widely used, open-source Java logging library. Because this library was present in countless applications, attackers could take over servers on a large scale.
- Ivanti has repeatedly been targeted by advanced attackers in recent years. In 2023 and 2024, critical vulnerabilities were actively exploited by state-sponsored actors. In 2025, new critical flaws were discovered to gain control over corporate devices without login credentials. Researchers point out that the exploitation stems from the way Ivanti implements open-source components and fails to keep them up-to-date.
The Impact on Organizations
The consequences of software supply chain failures for your organization naturally depend heavily on your organization's reliance on this software and the severity of the disruption.
The primary direct impact may sometimes seem small, while the consequential damage can be significant. In the case of the Ivanti exploitation at the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr), this even led to accountability in the House of Representatives.
For many organizations, it is particularly painful that they had little insight into the underlying software supply chain and only gained clarity after the damage had already been done.
Why Traditional Vendor Assessments Fall Short
Many organizations still rely on annual questionnaires, certifications, or contractual agreements. While useful, these methods fall short with dynamic software supply chains, which can change every few weeks.
Questionnaires are snapshots; they say little about current vulnerabilities and provide no insight into technical dependencies. Software supply chain risk requires continuous monitoring and objective signals, not just paperwork.
Effectively dealing with software supply chain failures requires a different approach:
- Identify which software vendors are critical to your processes
- Map technical dependencies and digital supply chains
- Continuously monitor vendors for vulnerabilities and incidents
- Combine technical signals with risk context
- Ensure clear internal responsibilities
The goal is not to exclude every risk, but to recognize early warning signs and limit impact.
Software Supply Chain Failures and RiskStudio
Within RiskStudio, software vendors are an explicit part of supply chain monitoring. By continuously profiling companies and software vendors based on their digital profile, vulnerabilities, and incidents, an up-to-date picture of software supply chain risk emerges.
Instead of isolated assessments, RiskStudio offers continuous insights, benchmarking, and alerts, enabling organizations to react proactively when a software supply chain failure occurs.
Conclusion
Software supply chain failures are no longer exceptional incidents but a structural risk in modern digital ecosystems. Organizations that rely on static assessments are falling behind. Only with continuous monitoring, insight into dependencies, and context-driven risk analysis can true control over the software supply chain be achieved.
References and Sources:
- OWASP – OWASP Top10:2025
- ESG 2024 – Research Report: The Growing Complexity of Securing the Software Supply Chain
- Gartner 2024 – Leader’s Guide to Software Supply Chain Security
- Tweede Kamer – Incident at the Dutch Data Protection Authority and the Council for the Judiciary
Frequently Asked Questions
What is the difference between a data breach and a software supply chain failure?
A data breach is often the consequence, while a software supply chain failure can be the underlying cause, for example, through a vulnerable supplier.
Does this risk only concern large software vendors?
No, smaller niche vendors can be critical precisely because they are deeply integrated into business processes.
How often should you assess software vendors?
Ideally continuously, as vulnerabilities and incidents can arise daily.
Is software supply chain risk relevant for NIS2?
Yes, NIS2 explicitly emphasizes supply chain and vendor risks, including ICT and software vendors.