您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [BlueVoyant]:2025年全球供应链防御现状年度洞察报告 - 发现报告

2025年全球供应链防御现状年度洞察报告

信息技术 2026-06-12 BlueVoyant xx翔
报告封面

Annual Global InsightsReport 2025 Foreword Welcome to BlueVoyant’s sixth annual report on the State of Supply Chain Defense. Over the past five years, we’ve chronicled the ups and downs of third-party risk management (TPRM)as it evolved from an immature awareness program to the established operational function it is today.This year, we refined our survey methodology to better reflect evolving priorities across industries and It’s no longer a question of “should we build this program?” but now, “how do we do this effectively?”This year’s survey explores not only what organizations are doing, but how, why, and what gaps they’re The data reveals that as organizations invest heavily in tools, teams, and processes, the gap betweenprogram maturity and organizational commitment is widening. While there are bright spots, the overall This year’s report focuses on the following key themes: >Operational challenges:Despite growing maturity among surveyed organizations, TPRMprograms face a widening gap in internal support and alignment. The strategy may be there, buttactically it’s hard to execute without far-reaching support. To dive into this thought, we separated >Compliance over risk reduction:Organizations are building TPRM programs to check acompliance box and not necessarily reduce risk. Only 16% of respondents identified risk reductionas a primary program driver. Instead, they are motivated more by cyber insurance requirements,contractual obligations, and board mandates — all of which support compliance. While meetingminimum compliance requirements is critical, meaningfully reducing risk would lead to the same or >Scale:With 96% of organizations expecting to grow their vendor ecosystem over the next year, theattack surface continues to widen. But without organizational support and integration across tools One positive trend was the increase in organizations being proactive about working with their third-party vendors. While 19% of organizations rely on vendor attestation alone, 23% use external third-party monitoring, risk ratings, or threat intelligence feeds for verification. And with 45% of organizations Ninety-six percent of respondents expect their vendor ecosystems to grow in the next year. Thirty-two percent expect their ecosystem to grow by 11-15%, and 35% expect 6-10% growth. Here’s the In positive news, 95% of respondents estimated that their TPRM spending increased over the past 12months to further support this growth and continue maturing their program. We found that common challenges have shifted as priorities change. Organizations are fully aware ofthe risks their third-party vendors pose, but they’re less clear on how to tackle the problem because ofinconsistent organizational support. While the 2024 challenges were more tactical — knowing how topenalize vendors who don’t fix issues and meeting regulatory requirements — this year’s signal more When it comes to AI, organizations identify this technology as best suited for continuous monitoring,recognizing that automation will be essential for maintaining visibility as the attack surface expands. For six years now, the goal of this report has been to raise awareness and understanding for building aTPRM program. As organizational attitudes and priorities evolve, we’re excited to share our Methodology BlueVoyant commissioned its sixth annual survey undertaken by independent research organization,Opinion Matters, in September 2025. Eighteen hundred chief information officers (CIO), chief information security officers (CISO), chiefoperating officers (COO), chief security officers (CSO), chief technical officers (CTO), and chiefprocurement officers (CPO) responsible for supply chain and cyber risk management were surveyed.The respondents represented organizations with 1,000-plus employees across a range of industriesincluding: financial services, healthcare and pharmaceutical, utilities and energy, retail, manufacturing, 07 — At a Glance 11 — Financial Services12 — Healthcare and Pharmaceutical13 — Energy and Utilities14 — Retail 17 — Region-Specific Analysis 17 — Global insights: Program maturity19 — U.S. and Canada20 — U.K.21 — DACH (Germany, Austria, Switzerland)22 — APAC (Australia, Philippines, Japan, Malaysia,and Singapore) Table ofContents 23 — Final Thoughts24 — Data Appendix At a Glance 97%60%45%96% 97% of organizationswere negatively impactedby at least one breach in 45%** are workingdirectly with third partiesto remediate issues 96% of organizationsexpect their vendorecosystem to grow This represents a welcomeshift toward collaboration and Organizations understand thecriticality of TPRM programs yet As the attack surface expands, aneffective TPRM program is moreimportant than ever. Despite growing budgets andmaturity, this is a telling increasefrom 2024’s 81%. Key Findings Program maturity does not guarantee effectiveness. While nearly half (46%) of organizations report established andoptimized TPRM programs,