Just 28% of UK businesses formally assessed any supplier's cyber security controls in the past 12 months, new government data shows, even as third-party and supply-chain attacks have overtaken every other concern for the world's largest organisations.
As third-party attacks become the world's biggest cyber threat, we are warning UK organisations of a 21-point retreat in supplier cyber assurance
Department for Science, Innovation and Technology data shows that while 16% of UK organisations started carrying out supplier cyber checks during the year, 37% actually stopped doing so, a net 21-point retreat. The drop coincides with the World Economic Forum's Global Cybersecurity Outlook 2026, which found that 65% of the world's largest companies now cite third-party and supply-chain vulnerabilities as their biggest cyber challenge, up from 54% a year earlier.
The wider WEF research underlines just how exposed most organisations are. Only 27% of organisations globally simulate cyber incidents with their supply-chain partners, and just 33% comprehensively map their ecosystem of suppliers, vendors and software dependencies. Most businesses, in other words, do not know who sits inside their digital perimeter, let alone how those parties would respond to an attack.
Nasstar's own client experience reflects the pattern. Across our work with NHS Trusts, local government, professional services, and manufacturers, the most common starting point for a supplier cyber assurance programme is not a risk score, but a list. Supply-chain attacks have shown they can paralyse operations, leak sensitive data, and trigger regulatory action without the victim organisation ever being directly targeted.
Larger organisations are not insulated either. While they are more likely than smaller firms to carry out formal supplier checks, fewer than half do so, and many rely on one-off questionnaires completed at procurement rather than continuous monitoring of how supplier security posture changes over time.
The retreat in supplier assurance is happening at exactly the wrong time. The modern supply chain extends well beyond the named IT vendor list, into the SaaS tools that departments buy directly without procurement involvement, and into the long tail of freelancers and sub-contractors who hold system access. Most published breach analysis points to these as the areas where the risk now sits, and the assurance programmes most companies are running weren't built to see them.
Before reaching for tooling or new questionnaires, the work UK businesses need to do is more basic than it sounds. They need a current, ranked list of which suppliers hold which data, and what would happen to the business if any one of them was compromised tomorrow. That list is usually harder to produce than people expect, and there's no point investing in continuous monitoring or new questionnaire systems before it exists. Shared assurance frameworks like Cyber Essentials Plus only really pay off once that ranking is in place.
With the EU's NIS2 cyber security directive and the UK's incoming Cyber Security and Resilience Bill both putting supply-chain risk at the centre of their requirements, the regulatory pressure on UK businesses is about to intensify. Nasstar is calling on UK organisations to use the next 12 months to map, monitor, and pressure-test their supplier ecosystems before the rules force them to.




