Trustlinks free webinar: Turning regulation into resilience – Register now
Supply chain attacks have become one of the most disruptive and costly forms of cyber risk. A single compromised supplier can expose hundreds or even thousands of organisations, including those with strong internal security. This shift in threat dynamics is one of the main reasons why regulations such as DORA and NIS2 place far greater emphasis on third-party risk management, operational resilience and evidence-based oversight. Regulators are responding to a simple reality: organisations are only as resilient as the weakest link in their supply chain.
Below are four well-documented supply chain attacks that together illustrate why structured risk management is no longer optional, regardless of size:
The MOVEit breach is one of the most damaging supply chain incidents in recent years. MOVEit, a widely used file transfer tool, was compromised through a previously unknown zero-day vulnerability. Attackers exploited the flaw to access sensitive data held by MOVEit customers across multiple sectors, with high-profile victims including the BBC, British Airways, Shell and several US federal agencies. More than 2,600 organisations were affected in total, with over 90 million individuals impacted. The CISA advisory on the incident remains one of the most comprehensive public accounts of how the attack unfolded.
What made the MOVEit breach particularly significant is that many affected organisations had strong internal security. That offered little protection when the risk sat in a third-party tool. This is exactly the type of cascading failure that DORA and NIS2 are designed to address.
The Kaseya attack is a clear example of how supply chain incidents disproportionately affect smaller organisations. Kaseya, a provider of remote management software for managed service providers, was compromised through vulnerabilities in its VSA product. The breach allowed ransomware to spread rapidly to approximately 1,500 downstream businesses across retail, logistics, manufacturing and professional services. CISA issued guidance specifically for affected organisations and their service providers in the days that followed.
The Kaseya incident highlights a critical point: third-party weaknesses quickly become your weaknesses. Smaller organisations are often more exposed because they rely heavily on external providers and lack the resources to continuously assess supplier risk. This is precisely why regulators now expect documented supplier assessments, ongoing monitoring and clear accountability.
The attack on JBS, the world’s largest meat supplier, showed how quickly a cyberattack can escalate from an IT issue into a national resilience concern. Ransomware forced operations to shut down across the US, Australia and Canada, disrupting global food supply chains and resulting in significant recovery costs. As Reuters reported at the time, the White House confirmed the attack originated from a criminal organisation likely based in Russia, drawing comparisons to the Colonial Pipeline incident that had occurred just weeks earlier.
Food supply is considered critical infrastructure, which explains why authorities have since strengthened resilience, reporting and risk management requirements under frameworks such as NIS2.
In August 2025, Jaguar Land Rover suffered a direct cyberattack that forced the company to shut down production across its UK facilities for around six weeks. As Computer Weekly reported, the company posted a loss of £485 million for the quarter in which the attack occurred, compared to a profit of £398 million in the same period the previous year. The wider economic cost to the UK was estimated at £1.5 billion. Thousands of workers were sent home, suppliers struggled to receive payments, and the knock-on effects spread across the entire automotive supply chain.
The JLR incident underlines how a cyberattack on a single organisation can cascade rapidly across an entire ecosystem of suppliers, partners and logistics providers — and why understanding those dependencies is now a regulatory expectation, not just a best practice.
These five incidents all point to the same conclusion: cyber resilience no longer stops at your own systems. It depends on every supplier and service provider you rely on. Under DORA and NIS2, organisations are expected to identify and assess third-party suppliers, document and monitor supply chain risks, ensure continuity even when a supplier is compromised, and maintain clear processes and evidence of oversight. These are areas where many organisations struggle, particularly those without dedicated compliance or security teams.
Supply chain risk management is one of the most demanding aspects of DORA and NIS2 compliance. Trustlinks is designed to bring structure and clarity to this challenge, with guided workflows for supplier risk assessments, centralised documentation, automated reminders for reviews and renewals, and regulatory requirements mapped directly to the actions your organisation needs to take. One platform, full oversight, always audit-ready.
Get expert guidance on risk and compliance
— no commitment.
Trustlinks values your privacy. We will only contact you about our solutions.
Have questions about pricing, frameworks, or how Trustlinks fits your organisation? Our team is here to help you find the right approach.
→ Or explore our Frequently Asked Questions
Need help using the platform or experiencing an issue? Our support team is ready to assist you.