Sharpen CISO Logo

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

Cyber compliance should no longer be a barrier to growth

Proving cyber maturity has become a hurdle to clear before a business can grow. For many organizations, compliance now sits on the critical path of every deployment, every tender, and every audit.

Three everyday situations show exactly how.

  • A project manager needs sign-off from the cyber team before deploying a new application — and that approval can take weeks if the right evidence isn’t already in place.
  • An IT vendor has to prove its security posture during a tender, typically through an ISO 27001 or SOC 2 certification — and one missing document can knock them out of the running.
  • An organization has to prove compliance to regulators, under frameworks like NIS2, DORA, or the CRA — each with its own evidence requirements and its own deadline.

A pace traditional methods can’t follow

Cyberattacks are accelerating. AI is rolling out everywhere. Regulatory requirements keep multiplying, often on the same team, at the same time.

As a result, security teams face more demands with the same limited resources. The frameworks themselves keep stacking, too: NIS2, DORA, and the CRA now overlap for many organizations, each with its own audit cadence and its own evidence trail.

Traditional approaches relied mainly on manual human review, and they simply can’t keep pace anymore. Spreadsheets, one-off audits, and point-in-time certifications suited a slower, more predictable risk environment — not continuous, AI-accelerated change.

Yet when companies innovate at the speed of AI, proving cyber compliance has to move at that same speed. Otherwise, compliance stops protecting the business and starts holding it back.

SharpenCISO: an augmented GRC platform

That’s exactly why we built SharpenCISO.

Our platform automates up to 80% of the manual work needed to demonstrate cyber compliance and manage risk in real time. This isn’t about removing people from the process. It’s about freeing your team from repetitive evidence-gathering, so their expertise goes where it creates the most value: judgment calls, risk decisions, and strategic conversations with the business.

Concretely, SharpenCISO automates the collection of cyber maturity evidence for four audiences at once:

  • Regulators, across frameworks like NIS2, DORA, and the CRA
  • Internal security (SSI) teams, who need continuous visibility instead of a once-a-year snapshot
  • Certification bodies, for standards like ISO 27001 or SOC 2
  • Client tenders and RFPs, where proof of security maturity now shapes business outcomes and risk decisions

One evidence base. Four audiences. No duplicated effort.

Turning cybersecurity into a competitive advantage

That’s our ambition. Proving cyber maturity should never slow an organization down.

Done right, it does the opposite. It builds trust with regulators and customers. It speeds up projects instead of gating them. And it opens doors — deals, partnerships, and markets — that used to stay closed until the paperwork caught up.

Compliance shouldn’t be the brake. It should be the accelerator.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement #SecureAI #AISecurity

While many organizations were still waiting for France’s transposition of NIS2, ANSSI published the ReCyF — Référentiel Cyber France (v2.5) in March 2026. This working document is now the regulatory backbone of what’s coming, well before the formal decree lands.

Here’s what you actually need to understand.

1. This is no longer an IT topic — it’s a leadership topic

The ReCyF is explicit about this: digital security governance now falls under the personal responsibility of the executive in charge. They approve the security policy. They answer for any gaps.

Concretely, that governance framework has to include four things: a defined organization, clear roles and responsibilities for digital security, a process for managing compliance, and a formal information security policy (PSSI). That PSSI isn’t a one-off document, either. Your organization has to review it at least once a year, and it must cover, at minimum, encryption use, physical and logical access control, and the review of security measures already in place.

Cybersecurity has moved up to the executive committee. This time, it’s staying there.

2. Are you an “Entité Importante” (EI) or an “Entité Essentielle” (EE)?

This isn’t just a vocabulary question. The first 15 security objectives apply to both categories equally. Objectives 16 through 20 — formal risk analysis, information system audits, dedicated administration, and security supervision — apply only to EEs.

There’s another distinction worth knowing: only essential entities (EE) must designate a named point of contact for ANSSI, responsible for security incidents and all related communications. Important entities (EI) face no such obligation. In short, your EI/EE status doesn’t just affect your paperwork — it directly determines your compliance workload.

3. The structure of the obligations: What vs. How

The ReCyF separates two levels, and the distinction matters:

  • Security objectives: mandatory. They define what you must achieve.
  • Acceptable means of compliance: recommended by ANSSI, not mandatory on their own. They define how you can demonstrate that achievement during a control.

Among those means, a valid ISO 27001:2022 certification can demonstrate several objectives at once — governance chief among them. But it only counts for the systems actually covered by the certification’s scope. A certification that covers one business unit doesn’t automatically cover the rest of the organization.

4. The 4 concrete pillars to address

The framework rests on four clear pillars:

  • Governance: mapping your information systems, defining your security policy, and controlling your supplier ecosystem.
  • Protection: physical access, architecture, identity management, encryption.
  • Defense: detecting and responding to incidents.
  • Resilience: business continuity and disaster recovery plans, crisis management, and regular exercises.

Each pillar maps to a specific set of the ReCyF’s 20 security objectives, and each objective ties back to an article of the NIS2 directive itself. Nothing here is arbitrary — it’s European law translated into operational requirements.

What this actually changes

Many organizations assumed they could wait. The ReCyF closes that option. It sets a precise framework, with requirements that differ by EI/EE status, ANSSI controls that can happen at any time, and named accountability for the executive in charge.

The question is no longer “do we need to comply?” It’s “where do we start?”

Evaluate your maturity in 15 minutes

Want to assess your maturity against the ReCyF ahead of NIS2? SharpenCISO automates multi-framework pre-audits. You get your report and a preliminary action plan in 15 minutes, not weeks.

🌐 www.sharpenciso.com ✉️ contact@sharpenciso.com

#SharpenCISO #GRC #Cybersecurity #Founders #CISO #RSSI #NIS2 #DORA #ISO27001 #NIST #Compliance #SecurityByDesign