UK Supply chains at risk as many businesses admit they don’t monitor cyber threats
UK businesses are leaving their supply chains vulnerable to cyber risks, according to recent research from leading audit, tax and consulting firm RSM UK.
The Supply Chain Integrity Survey found only 55% of businesses are actively monitoring cyber and technology risks across their supply chains, while just 39% of businesses feel ‘very confident’ they could withstand a cyber-attack. This is despite almost a quarter (22%) of the respondents experiencing a cyber-attack or data breach within the past year.
The stark findings come as the UK’s AI Security Institute says Anthropic and Open AI agents broke into third party software and sent emails attempting to steal personal credentials. This comes just days after Open AI recently admitted it suffered the first ever AI-powered cyber breach, when an AI agent broke out of its testing sandbox and hacked another tech company.
Despite advancements in AI and geopolitical threats increasing cyber risks, only 37% of businesses surveyed have considered the impact of a major cyber-attack affecting a critical supplier.

RSM UK’s national technology risk assurance lead, Sheila Pancholi said: “The findings are particularly concerning, given the recent AI-led breach at Open AI has now taken cyber risks into uncharted territory. It’s no longer enough for businesses to address risk in their own systems and processes, they need to be aware of potential risks from third parties and suppliers in every link of their supply chain. An attack on any one of these could potentially put the whole supply chain in jeopardy.”
Confidence to withstand an attack is higher among board and c-suite members, with 60% feeling confident they could withstand a cyber-attack, however this falls to just a third (33%) among operations staff and supply chain managers, illustrating a ‘confidence gap’ between senior leaders and those actively managing supply chains.
Of the companies that had experienced a cyber-attack or breach, 40% said it took less than three months to recover, while 35% said it took three to six months, and one in five (19%) took over six months, demonstrating the operational disruption and costs that follow a successful attack.
Sheila Pancholi concluded: “Building cyber-resilience in supply chains is essential to ensure businesses can continue to run smoothly. A cyber-attack can seriously hamper a businesses’ ability to operate for weeks if not months, and the reputational damage can last much longer. The threat landscape is changing rapidly, it’s therefore important businesses adopt a ‘when’ not ‘if’ mentality and stay informed of evolving risks so they can be one step ahead of would-be attackers.”
RSM UK’s cyber risk experts recommend the following to protect supply chains:
- Have a fully documented inventory of all key third party suppliers, ranked by the importance of the service provision to the business.
- Identify where potential cyber threats are, including AI related risks, in every element of the supply chain, not just within your own business.
- Ensure cyber resilience measures are as robust as possible, and stress test these regularly.
- Have an incident response plan ready, and ensure all stakeholders fully understand their role in the event of a cyber-attack through regular scenario testing.
- Keep offline digital copies of the plan in case systems are compromised and access is denied.
- Ensure all necessary regulatory and compliance reporting procedures are followed and recorded.

