Your business could be an easy target through a supplier you trust

Only 35% of businesses can see supplier cyber risk in real time, according to new Proxima research shared with Dynamic Business.

Yajush Gupta
Yajush Gupta
News · 9 Oct 2026 · 2 min read
Above Your business could be an easy target through a supplier you trust. Dynamic Business

Nearly half of Australian business leaders have experienced supply chain disruption caused by a cyber incident in the past 24 months, according to new research from Proxima. Despite that, only 35% of organisations have real-time visibility of the cyber risk posed by their critical suppliers, and 40% say an attack affecting a key supplier would put significant revenue at risk.

For CIOs and CTOs managing complex vendor ecosystems, cyber resilience cannot stop at the enterprise perimeter. It depends on knowing where supplier exposure sits, how it is changing, and what action is needed before disruption reaches the business.

Connor Linehan, APAC Technology Procurement Practice Lead at Proxima Australia, is urging businesses this Cyber Security Awareness Month to check whether they actually know the security posture of the vendors they depend on, alongside their own security controls.

"Supply chain cyber risk is a primary attack vector. A compromised vendor can become an entry point into your systems, your data, and your reputation," he said. "Most tech leaders are operating blind when it comes to vendor security across their full technology stack, less than 39% even stress-tested their vendor base in the past 12 months. You can't defend what you don't know.

"Cyber security assessments need to be real time, relevant and more than just a tick box exercise or annual supplier attestation."

The research points to AI as a way to scale visibility across dozens or hundreds of vendors, offering early warning signs for emerging threats. Adoption, though, is stalling. Businesses cited three main obstacles: data quality, flagged by 38% of respondents, with vendor data often fragmented, inconsistent and unreliable; skills gaps, cited by 30%, since not all cyber security teams have the data scientists or AI engineers needed to implement and manage AI monitoring systems; and a lack of clarity on return on investment, also cited by 30%, as it is far easier to measure the cost of a solution than to prove what it prevented.

"We found that 52% of tech leaders see measurable value in using AI to monitor supplier risk but AI is a double edged sword," Linehan said.

"It can be used for increased monitoring to identify vulnerabilities, but it can also be used to identify and exploit vulnerabilities.

"There have been several recent examples of this including AI finding ways around access restrictions to gain unauthorised access to confidential files. As such, it is more important than ever to know where vulnerabilities exist and build remediations."

Cyber Security Awareness Month typically centres on employee training, password hygiene and awareness campaigns. Linehan argues that tech leaders also need to use October to get the basics right while treating AI as a new attack surface in its own right. He points to three steps: auditing the internal and vendor landscape to understand current security posture, assessing where visibility gaps and vulnerabilities sit, and acting, whether through AI, vendor questionnaires or third party assessments, to build resilience and a business continuity plan in case a vendor is compromised, alongside strong identity and access controls.

"Supply chain risk is a business continuity and digital strategy issue. Start with getting visibility of vulnerabilities then action," Linehan said.

"Businesses can review the NIST Cyber AI Profile, which is structured around securing AI system components, conducting AI-enabled cyber defence and thwarting AI-enabled cyber attacks. Even though it's a US-agency developed guideline, it's a critical, strategic tool for Australian businesses.

"The question isn't whether you'll be targeted, it's whether you'll see it coming."

YG
Yajush Gupta
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

Tips | Advice ◆

Got five generations in your office? Here's what the data says to do

Just 9% of Australian workers aged 40 to 64 feel financially secure, new ADP Research data shows, well below the global average.

Yajush Gupta · 2 min
Expert ◆

From a teenage dive to a $500 million plan to clean the world's rivers

"You can't defend what you don't know" doesn't apply here, but this data on ocean plastic might change how it's funded.

subscriptions · 2 min
Founder Friday ◆

'I had to become a beginner again': Dr Queenie Wu on building Mindspace from a solo room

Dr Queenie Wu built Mindspace from a solo room in 2019. She tells Dynamic Business why growth sometimes means slowing down first.

Yajush Gupta · 2 min
0 people like this

Comments

Loading comments…