Inherited Risk: The New Reality of Cybersecurity Leadership
Why supply chain security is no longer about protecting your vendors—it’s about operating a business built on technology you don’t control.
There was a time when cybersecurity teams could reasonably understand most of what they were defending. Applications were developed internally, infrastructure lived inside company-owned data centers, and the technology stack was relatively contained. Security leaders focused on protecting assets they owned, controlled, and could inspect. Those days are over.
Today’s enterprise runs almost entirely on services someone else operates. Infrastructure is Infrastructure-as-a-Service. Applications are Software-as-a-Service. Identity depends on cloud providers. Security controls are delivered from the cloud. ERP platforms connect to payroll providers, banks, logistics companies, HR systems, suppliers, and thousands of APIs. Even the software we build ourselves is assembled from hundreds, sometimes thousands of open-source packages maintained by people we’ve never met. Modern business isn’t built anymore. It’s integrated.
The scale of that integration is staggering. Large enterprises routinely operate 500 to more than 1,000 SaaS applications, while relying on hundreds of additional cloud services and third-party integrations to support daily operations. A single business transaction may traverse infrastructure owned by a hyperscaler, an identity provider, multiple SaaS providers, payment processors, API gateways, container platforms, and dozens of open-source libraries before completing successfully. Every dependency creates another trust relationship, and every trust relationship expands the attack surface.
That reality has fundamentally changed the role of the CISO. We are no longer simply managing cyber risk inside our own organizations, we are managing inherited risk from an ecosystem we neither own nor control. Every critical business process now depends on software written by someone else, infrastructure operated by someone else, code maintained by someone else, and security decisions made by someone else. Our security posture is increasingly influenced by organizations we have no authority to direct and no ability to audit completely. That may be the single biggest change in enterprise cybersecurity over the last decade.
The Escalation We Should All Be Paying Attention To
The last six years have demonstrated exactly how dangerous supply chain dependency has become. More importantly, they reveal a clear evolution in attacker strategy. What began as isolated compromises of trusted software vendors has expanded into attacks targeting cloud providers, developer ecosystems, open-source maintainers, managed service providers, identity platforms, and the software factories that build the applications we all rely upon.
SolarWinds (2020). The modern supply chain era accelerated when the SolarWinds compromise exposed more than 18,000 customers through a malicious software update. The attack fundamentally changed how security leaders viewed trusted software distribution. Industry analysts estimated approximately $90 million in insured losses, while affected organizations often reported remediation costs exceeding $12 million after rebuilding infrastructure, rotating credentials, validating trusted environments, and restoring operational confidence. SolarWinds itself disclosed more than $40 million in direct incident-response costs within the first year of active remediation following the breach’s public disclosure.
Log4Shell (2021). Rather than compromising a software vendor directly, attackers exploited a vulnerability hidden inside an open-source logging library embedded within thousands of commercial products. Overnight, organizations realized they weren’t simply responsible for the software they purchased, they were responsible for understanding the software hidden inside that software.
MOVEit (2023). The MOVEit Transfer attacks demonstrated another evolution. A vulnerability inside one widely deployed managed file transfer platform cascaded into thousands of downstream organizations across government, healthcare, education, manufacturing, and financial services. Many victims had never heard of MOVEit until they discovered their data had been exposed through a trusted business partner.
XZ Utils (2024). The XZ Utils backdoor demonstrated the extraordinary patience of modern adversaries. Rather than exploiting an existing vulnerability, attackers spent years establishing credibility within an open-source project before attempting to introduce malicious code into Linux distributions. Fortunately, the compromise was detected before broad deployment, but it proved attackers were willing to invest years infiltrating trusted software projects if the downstream impact justified the effort.
The build pipeline (2025–2026). By 2025 and 2026, attention shifted even further upstream. Compromises involving GitHub Actions, CI/CD pipelines, package repositories, and developer tooling highlighted a new reality: attackers increasingly target the factories producing software rather than the finished applications themselves. A successful compromise inside a build pipeline can silently propagate malicious code into thousands of legitimate software releases.
Oracle and the identity layer. Recent events involving Oracle’s cloud ecosystem further reinforced how interconnected enterprise technology has become. Questions surrounding exposed authentication artifacts and customer credentials forced organizations to evaluate not only Oracle itself but every identity integration, synchronized account, API connection, and downstream system dependent upon that trust relationship. Even before every technical detail was fully understood, security teams were rotating credentials, validating identities, reviewing privileged access, and assessing downstream exposure.
The same pattern has emerged repeatedly across major enterprise technology providers. Whether vulnerabilities involve Microsoft Exchange, Ivanti, Cisco, VMware, SAP NetWeaver, or identity platforms supporting thousands of organizations, the operational challenge remains remarkably consistent. These are not technologies businesses can simply replace over a weekend. They are foundational infrastructure. Security teams must continue operating while vendors investigate, develop fixes, communicate with customers, and organizations work through remediation that frequently lasts weeks or months.
None of these incidents required customers to make poor security decisions. Most organizations were following accepted industry best practices. Most had mature security teams. Most had vendor risk programs. Many had completed successful audits only months earlier. That is precisely what makes supply chain security one of the defining cybersecurity challenges of our generation. Attackers are no longer trying to compromise one organization at a time. They’re looking for one trusted relationship that gives them thousands of victims.
We Buy Because We Have To
Every executive has heard the question: “Why don’t we just build it ourselves?”
The answer is simple. No enterprise can realistically build its own ERP platform, productivity suite, cloud infrastructure, endpoint protection platform, SIEM, networking equipment, collaboration software, identity provider, HR system, payment platform, analytics engine, and every supporting technology required to operate a global business. Buying software isn’t a convenience. It’s an operational necessity.
But modern procurement introduces another uncomfortable reality: your vendor has vendors. Their vendors have vendors. Those vendors depend on cloud providers, CI/CD platforms, certificate authorities, package repositories, managed services, contractors, AI services, and open-source projects maintained by developers you will never meet. Most organizations understand third-party risk. Far fewer understand fourth-party risk. Almost nobody fully understands fifth-party risk. Yet those dependencies increasingly determine the resilience of the modern enterprise.
The Illusion of Due Diligence
Security questionnaires matter. SOC reports matter. Penetration testing matters. Contracts matter. None of them eliminate inherited risk.
A vendor can complete every security questionnaire flawlessly while unknowingly shipping software containing a vulnerable dependency discovered months later. A SOC 2 report cannot validate every open-source library embedded inside a commercial product. A penetration test cannot identify malicious code that has not yet been activated. An ISO certification cannot guarantee an uncompromised software build pipeline. Traditional third-party risk management measures governance. Supply chain attacks exploit engineering. Those are fundamentally different problems.
IBM’s 2025 Cost of a Data Breach Report reinforces this reality. Supply chain and third-party compromises account for roughly 15% of all breaches, averaging $4.9 million globally, while requiring 267 days to identify and contain, the longest detection-and-containment window of any attack vector IBM tracks. By the time many organizations discover the compromise, attackers have often spent months leveraging trusted relationships already inside the environment. And the trend line is moving the wrong direction: third-party involvement in breaches doubled year over year, according to Verizon’s 2025 Data Breach Investigations Report, from 15% to roughly 30% of all incidents.
Open Source: Our Greatest Strength and Our Greatest Weakness
Modern software would not exist without open source. Industry estimates suggest 70–90% of today’s application code originates from open-source components. Innovation has never moved faster. Neither has inherited risk.
Critical software supporting global enterprises is often maintained by remarkably small teams. Attackers understand those economics better than anyone. Rather than attacking billion-dollar companies directly, they increasingly target developer ecosystems where one successful compromise can ripple through thousands of commercial products. The return on investment is extraordinary.
Accepting That Control Is an Illusion
One of the hardest lessons for today’s security leaders is accepting that complete control no longer exists. For decades, cybersecurity programs were built on the assumption that stronger controls produced stronger outcomes: better visibility, better endpoint protection, better identity, better governance, better monitoring. Those investments remain essential.
But none of them prevent your ERP vendor from introducing a critical vulnerability. None prevent an open-source maintainer from having an account compromised. None prevent a cloud provider from experiencing an identity incident. None stop an undisclosed fourth-party supplier from becoming the weakest link. That doesn’t mean those investments were misplaced, it means the objective has changed. Cybersecurity is no longer about eliminating uncertainty. It is about operating effectively despite uncertainty.
Supply Chain Security Is Now a Board-Level Conversation
This is no longer simply a cybersecurity issue. It is an enterprise risk issue. IBM estimates the average U.S. data breach now exceeds $10 million, and third-party compromises consistently rank among the most operationally disruptive events organizations experience. Every significant supply chain incident quickly becomes a board discussion involving legal, finance, procurement, communications, operations, investor confidence, regulatory obligations, and business continuity.
That reality should fundamentally change procurement. Vendor evaluations can no longer focus primarily on features, functionality, and price. Security leaders should evaluate secure development practices, SBOM maturity, dependency management, code signing, incident response transparency, vulnerability disclosure history, and how vendors manage their own suppliers. Procurement has become one of cybersecurity’s first security controls.
So What Actually Works?
The question is no longer “How do I prevent my vendors from being compromised?” The better question is “How quickly can we detect, understand, contain, and continue operating through a vendor compromise?” That changes everything.
Organizations need deeper visibility into critical dependencies not only direct vendors, but significant fourth-party relationships, cloud platforms, open-source dependencies, externally hosted services, and the business processes relying upon them. Identity becomes the primary containment strategy. Segmentation reduces blast radius. Executive response plans become just as important as incident response plans.
Perhaps the hardest truth every modern CISO must accept is this: we are no longer evaluating vendors based on whether they will eventually experience a security incident. Statistically, many will. The differentiator has become how quickly they detect compromise, how transparently they communicate, how effectively they recover, and whether they built their own supply chain with the same discipline they expect from their customers.
The New Definition of Cyber Resilience
Supply chain attacks expose something many CISOs have quietly understood for years: perfect security was never achievable, and perfect control no longer exists. We cannot inspect every dependency, audit every developer, rebuild every platform ourselves, or maintain redundant versions of every critical system. Modern business simply doesn’t work that way.
The organizations that will outperform over the next decade will not be the ones that avoid every supply chain incident. That is no longer a realistic objective. The winners will be the organizations that discover compromises faster, understand their dependencies better, isolate affected systems more quickly, communicate more effectively with executive leadership, and recover with the least amount of operational disruption.
That requires a different mindset. It requires security leaders to stop measuring success by the number of vulnerabilities they eliminate and start measuring success by how resilient the business remains when trusted relationships inevitably fail.
Because in an Everything-as-a-Service economy, trust has become both our greatest competitive advantage and our greatest operational risk. The modern CISO is no longer protecting a network. They’re protecting a business built almost entirely on someone else’s technology. And that may be the defining cybersecurity challenge of the next decade.


