Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BlueVoyant’s 2024 survey found that 81% of respondents said supply-chain breaches had negatively affected their organization in the prior 12 months. That is a survey-reported impact figure—not a finding that researchers independently confirmed breaches at 81% of all organizations. BlueVoyant’s later 2025 survey reported 97%, so 81% is no longer the latest result.

What the 81% figure actually measures

BlueVoyant’s November 4, 2024 announcement says 81% of organizations reported negative impacts from supply-chain breaches over the preceding 12 months, compared with 94% in its 2023 survey. The wording matters: respondents reported negative impacts. The figure is not an independently verified count of organizations breached, nor does it establish that 81% of organizations worldwide experienced a confirmed incident. BlueVoyant’s 2024 survey announcement describes the result.

The survey was conducted in July 2024 with Opinion Matters and included more than 2,100 industry leaders. Respondents represented sectors including business services, financial services, healthcare, manufacturing, utilities, energy and defense, and came from the US, Canada, Europe, APAC and other regions. The public summary does not provide enough methodological detail to independently assess how representative the sample was or validate each reported incident.

Is 81% still the latest result?

No. In a separate announcement dated November 20, 2025, BlueVoyant said 97% of surveyed organizations reported negative impacts from supply-chain breaches over the prior 12 months. The announcement also said 95% increased their third-party risk management budgets and identified tool integration as a leading operational challenge. These are results from a later annual survey, not proof of a controlled year-over-year change: comparing the editions fully would require comparable methodology and respondent populations. BlueVoyant’s 2025 announcement reports those findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to read the survey figures

Finding What it says Source and qualification
81% Respondents reported negative impacts from supply-chain breaches over the previous 12 months. BlueVoyant’s 2024 annual survey; fielded in July 2024. Respondent-reported, not independently confirmed prevalence.
94% Respondents reported negative impacts in the preceding survey year. BlueVoyant’s 2023 result, as cited in its 2024 comparison.
97% Respondents reported negative impacts over the prior 12 months. BlueVoyant’s distinct 2025 annual survey; not a controlled trend comparison by itself.
99% Analyzed Global 2000 firms were directly connected to at least one vendor with a confirmed breach. Cyentia Institute and SecurityScorecard study summary; a different population and method, with publication year not stated on the page.
17 times Median financial losses for multi-party incidents were higher than for traditional single-firm incidents. Cyentia Institute and SecurityScorecard study summary; different study population and method, publication year not stated on the page.

The Cyentia Institute and SecurityScorecard figures add a separate ecosystem-risk perspective; they do not confirm BlueVoyant’s survey percentage. Their analysis covered 331 confirmed breaches and Global 2000 third-party ecosystems. The study summary describes its results.

Why third-party risk is an operational problem

A supplier can create exposure through its access, systems, software or services, so managing third-party cyber risk (TPRM) requires more than establishing a policy or launching a program. BlueVoyant’s 2024 announcement quotes Joel Molinoff, its global head of Supply Chain Defense, saying that organizations’ focus had shifted toward the “operational, day-to-day challenges of managing an effective program.” The 2025 announcement’s mention of tool integration reinforces that operational emphasis, though neither finding proves that any one control or product is effective.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can focus on

The survey findings point to a practical evaluation framework, not a guaranteed fix. Organizations reviewing their supplier cyber-risk monitoring or TPRM processes can ask:

  • Visibility: Which suppliers and connected services are in scope, and what monitoring coverage exists for them?
  • Remediation: When a concern is identified, who owns the response, how is it prioritized, and how quickly can the supplier and internal teams act?
  • Workflow integration: Can findings reach the enterprise risk, security and procurement workflows where decisions and follow-up happen?
  • Effectiveness: Does the program track remediation and changes in risk, or mainly completion of assessments and compliance activity?

These questions help distinguish an operational risk-management process from a checklist exercise. The cited survey announcements do not establish which vendor product performs best.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.