Supply chain risk management
Back to Blog
Security Intelligence

Supply Chain and Third-Party Risk Management

PublishedJune 1, 2026
Read time7 min read
Share
Originally reported viaCISA Software Supply Chain Security / Sonatype State of the Software Supply Chain

Software supply chain attacks tripled in 2025. The pattern is well understood: rather than targeting a hardened enterprise directly, adversaries compromise a trusted vendor and ride that trust relationship into hundreds of downstream victims simultaneously. SolarWinds, Log4j, the XZ Utils backdoor — each demonstrated that the supply chain is the most force-multiplied attack vector available.

How supply chain attacks are evolving in 2026

Three patterns dominate: software build pipeline compromise (injecting malicious code into signed release artifacts), open-source package hijacking via typosquatting and maintainer account takeovers, and SaaS-to-SaaS attack chains where one compromised platform pivots through legitimate API integrations into connected services.

Your MSP is your largest attack surface
Managed service providers with administrative access to your infrastructure represent the highest-risk third-party relationship most organisations have. Treat MSP access like privileged insider access — with the same MFA, monitoring, and session recording requirements.

Managing open-source dependency risk

An SBOM (Software Bill of Materials) for every application you build or buy is now essential infrastructure — it enables rapid response when a new CVE affects a dependency and is increasingly required by regulators. Tools like Syft, SPDX, and CycloneDX make SBOM generation tractable; the challenge is operationalising SBOM data into your vulnerability management workflow.

  • Tier vendors by access level and data sensitivity. Apply heightened controls to Tier 1 vendors with privileged access.
  • Require vendors to notify you of security incidents within 24–48 hours contractually.
  • Generate SBOMs for all in-house software and require them from software vendors.
  • Run dependency confusion and typosquatting checks against your package registries.
  • Continuously monitor critical vendors' external attack surfaces.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.