Special Reports
A special report is content that is edited and produced by the special reports unit within The Irish Times Content Studio. It is supported by advertisers who may contribute to the report but do not have editorial control.

Reinforcing the weakest links in supply chains

Suppliers can create cyber risk because they often have privileged access to systems, data and critical business operations

A cybersecurity breach to a supplier’s system can quickly spread throughout the supply chain
A cybersecurity breach to a supplier’s system can quickly spread throughout the supply chain

Increasingly complex and integrated supply chains have led to a significant expansion of the cyberattack surface that organisations need to defend. A breach to a supplier’s system can quickly spread throughout the chain with often devastating results.

PwC Ireland cybersecurity director Will O’Brien notes that the World Economic Forum (WEF) Global Cybersecurity Outlook 2026 ranked the top supply-chain risks as inheritance risk – being unable to assure the integrity of third-party software, hardware and services; visibility – limited sight of the extended supply chain; and concentration risk – overdependence on a small number of critical providers.

“Recent incidents illustrate the impact – the September 2025 attack on European airport check-in systems and the Asahi disruption in October 2025 both showed how a single supplier compromise can cascade across operations, customers and even entire sectors,” he says.

Suppliers can create cyber risk because they often have privileged access to systems, data and critical business operations, says Puneet Kukreja, resilient nation leader and head of cyber at EY Ireland. “Many organisations rely on software, cloud services and AI tools developed by third parties, and this means a weakness in one supplier can cascade rapidly across many organisations, including customers, supply chains and essential services. The 2025 incidents affecting Marks & Spencer, Jaguar Land Rover and Collins Aerospace demonstrate how cyberattacks can interrupt retail services, halt manufacturing and disrupt airport operations.”

Puneet Kukreja, resilient nation leader and head of cyber, EY Ireland
Puneet Kukreja, resilient nation leader and head of cyber, EY Ireland

Agentic AI must also be considered. “For agentic AI, [the organisation] must also examine permission boundaries, tool and data access, external connectivity, human intervention and shutdown mechanisms,” Kukreja says.

“Suppliers should demonstrate that systems can remain contained, fail safely and recover predictably under realistic conditions. The EY Ireland Cyber Leaders Index found that while 68 per cent prioritise supply-chain protection, only 4 per cent have identified vendor risk as a principal concern.”

Closing this gap requires cyber, procurement, technology, legal and operations teams to test whether suppliers can fail safely and recover predictably, he adds.

The question for organisations is how they can trust their suppliers not to present cyber risks. “Confidence comes from evidence, not assurances,” says O’Brien. “The most resilient organisations in the WEF report treat supplier risk as a continuous discipline: 76 per cent involve their security function in procurement; 74 per cent assess supplier security maturity; and 44 per cent simulate cyber incidents with their ecosystem partners. That contrasts sharply with the wider market, where only 27 per cent run joint exercises and just 33 per cent map their supply chain in detail – a sign that third-party risk is still too often managed as a compliance checklist rather than an active, ongoing process.”

According to Kukreja, organisations need continuous visibility across suppliers, software components, AI models, data sources, subcontractors and concentration risk. “They should regularly assess how these providers test secure development, identity controls, model provenance, update processes, incident notification and recovery capability.”

Will O'Brien, cybersecurity director, PwC Ireland. Photograph: Gerard McCarthy
Will O'Brien, cybersecurity director, PwC Ireland. Photograph: Gerard McCarthy

Organisations should structure their response to the threat posed by third parties around three outcomes: prevention, containment and continuity, he advises. “For example, zero-trust architecture, strong identity controls, least-privilege access and continuous monitoring can help prevent or detect compromise across suppliers and AI agents. Measures such as segmentation, progressive releases, behavioural monitoring, rollback mechanisms and human intervention points help contain attacks, defective technology and AI systems outside their boundaries.”

Continuity requires mapping shared dependencies, reducing concentration risk, maintaining assured alternatives and rehearsing prolonged supplier disruption.

“The high-profile incidents over the past 24 months in particular highlight that cyber failure can quickly become operational and cause economic disruption,” Kukreja continues. “The objective is to sustain minimum viable operations and recover critical services at speed even when a trusted dependency or containment boundary fails.”

O’Brien identifies five key steps for organisations to take to manage and protect themselves against third-party cyber risk.

“Map critical dependencies: identify concentration risks and single points of failure across the ecosystem. Embed security into procurement: set clear standards before contracts are signed, not after. Adopt zero trust: as the WEF report puts it, treat every interaction as untrusted by default, with continuous verification and audit trails. Monitor continuously: move from point-in-time NCT style assessments to ongoing assurance of supplier posture. Test together: run joint incident and recovery exercises to build shared muscle memory before a real event occurs.”

Barry McCall

Barry McCall is a contributor to The Irish Times