Trustlinks free webinar: Turning regulation into resilience – Register now

Get useful tips, learn best practices and read the latest newsThe Trustlinks Blog

Why supply chain attacks are driving new cyber regulations

From MOVEit to Landrover - why supply chain attacks are driving new cyber regulations.

Supply chain attacks have become one of the most disruptive and costly forms of cyber risk. A single compromised supplier can expose hundreds or even thousands of organisations, including those with strong internal security. This shift in threat dynamics is one of the main reasons why regulations such as DORA and NIS2 place far greater emphasis on third-party risk management, operational resilience and evidence-based oversight. Regulators are responding to a simple reality: organisations are only as resilient as the weakest link in their supply chain. 

Below are four well-documented supply chain attacks that together illustrate why structured risk management is no longer optional, regardless of size: 

  • MOVEit Transfer (2023): over 2,600 organisations and 90 million individuals affected through a single zero-day vulnerability in a widely used file transfer tool 
     
  • Kaseya VSA (2021): ransomware spread to approximately 1,500 businesses through a compromised remote management platform used by managed service providers 
     
  • JBS (2021): the world’s largest meat supplier was forced to shut down operations across the US, Australia and Canada following a ransomware attack 
     
  • Jaguar Land Rover (2025): a direct cyberattack on the manufacturer halted production for around six weeks, costing an estimated £485 million in a single quarter 
     

MOVEit Transfer supply chain attack (2023) 

The MOVEit breach is one of the most damaging supply chain incidents in recent years. MOVEit, a widely used file transfer tool, was compromised through a previously unknown zero-day vulnerability. Attackers exploited the flaw to access sensitive data held by MOVEit customers across multiple sectors, with high-profile victims including the BBC, British Airways, Shell and several US federal agencies. More than 2,600 organisations were affected in total, with over 90 million individuals impacted. The CISA advisory on the incident remains one of the most comprehensive public accounts of how the attack unfolded. 

What made the MOVEit breach particularly significant is that many affected organisations had strong internal security. That offered little protection when the risk sat in a third-party tool. This is exactly the type of cascading failure that DORA and NIS2 are designed to address. 

Kaseya VSA ransomware attack (2021) 

The Kaseya attack is a clear example of how supply chain incidents disproportionately affect smaller organisations. Kaseya, a provider of remote management software for managed service providers, was compromised through vulnerabilities in its VSA product. The breach allowed ransomware to spread rapidly to approximately 1,500 downstream businesses across retail, logistics, manufacturing and professional services. CISA issued guidance specifically for affected organisations and their service providers in the days that followed. 

The Kaseya incident highlights a critical point: third-party weaknesses quickly become your weaknesses. Smaller organisations are often more exposed because they rely heavily on external providers and lack the resources to continuously assess supplier risk. This is precisely why regulators now expect documented supplier assessments, ongoing monitoring and clear accountability. 

JBS ransomware attack (2021) 

The attack on JBS, the world’s largest meat supplier, showed how quickly a cyberattack can escalate from an IT issue into a national resilience concern. Ransomware forced operations to shut down across the US, Australia and Canada, disrupting global food supply chains and resulting in significant recovery costs. As Reuters reported at the time, the White House confirmed the attack originated from a criminal organisation likely based in Russia, drawing comparisons to the Colonial Pipeline incident that had occurred just weeks earlier. 

Food supply is considered critical infrastructure, which explains why authorities have since strengthened resilience, reporting and risk management requirements under frameworks such as NIS2. 

Jaguar Land Rover cyberattack (2025) 

In August 2025, Jaguar Land Rover suffered a direct cyberattack that forced the company to shut down production across its UK facilities for around six weeks. As Computer Weekly reported, the company posted a loss of £485 million for the quarter in which the attack occurred, compared to a profit of £398 million in the same period the previous year. The wider economic cost to the UK was estimated at £1.5 billion. Thousands of workers were sent home, suppliers struggled to receive payments, and the knock-on effects spread across the entire automotive supply chain. 

The JLR incident underlines how a cyberattack on a single organisation can cascade rapidly across an entire ecosystem of suppliers, partners and logistics providers — and why understanding those dependencies is now a regulatory expectation, not just a best practice. 

Why these incidents matter for NIS2 and DORA compliance 

These five incidents all point to the same conclusion: cyber resilience no longer stops at your own systems. It depends on every supplier and service provider you rely on. Under DORA and NIS2, organisations are expected to identify and assess third-party suppliers, document and monitor supply chain risks, ensure continuity even when a supplier is compromised, and maintain clear processes and evidence of oversight. These are areas where many organisations struggle, particularly those without dedicated compliance or security teams. 

Supply chain risk management is one of the most demanding aspects of DORA and NIS2 compliance. Trustlinks is designed to bring structure and clarity to this challenge, with guided workflows for supplier risk assessments, centralised documentation, automated reminders for reviews and renewals, and regulatory requirements mapped directly to the actions your organisation needs to take. One platform, full oversight, always audit-ready. 

Looking for a secure and user-friendly compliance solution?Share your details, and we’ll contact you to discuss how Trustlinks can help.

Talk with Territory Manager
Annelie Demred

WHISTLELINK BLOGWhat to read next...​

The rising compliance challenge for small and medium-sized organisations 
NIS2 – New obligations for management board members in 2026 
What is DORA? A simple guide to the EU’s new Digital Operational Resilience Law

Book a meeting

Send us a message and our team will get back to you shortly.
Trustlinks logo white.

Talk to Sales

Have questions about pricing, frameworks, or how Trustlinks fits your organisation? Our team is here to help you find the right approach.

→ Or explore our Frequently Asked Questions

Get Product Support

Need help using the platform or experiencing an issue? Our support team is ready to assist you.

Contact us