← Back to Blog
Risk ManagementCyberCover Team7 min read20 May 2026

Supply Chain Cyber Attacks: Why Your Vendor's Breach Is Your Problem

Why Your Vendor's Security Is Your Problem

When people think about cyber attacks, they typically imagine an attacker targeting their own systems directly. The reality of how most serious incidents unfold is often quite different. Supply chain attacks — where criminals compromise a supplier, software vendor, or service provider and use that access to reach the vendor's clients — have become one of the most prevalent and consequential cyber attack vectors affecting businesses.

The logic for attackers is straightforward: a single successful compromise of a widely-used IT service provider can provide simultaneous access to hundreds or thousands of client environments. The return on investment is dramatically higher than attacking individual organisations, and the third-party access that clients have granted their providers often bypasses the security controls the client has implemented on its own systems.

How Supply Chain Attacks Work

Supply chain attacks typically unfold in one of three ways. In the software supply chain variant, attackers compromise the software development pipeline of a widely-deployed application, embedding malicious code into an update that is then pushed to all installations. Because the update appears to come from the legitimate vendor and is delivered through normal update channels, it bypasses many security controls. The 2020 SolarWinds attack — which affected thousands of organisations globally — is the canonical example of this type.

In the IT service provider variant, attackers compromise a managed service provider or IT support firm that has administrative access to client networks. Using stolen administrator credentials, they can access client environments, deploy ransomware, or exfiltrate data while appearing to operate through legitimate channels. The attacker effectively inherits the access rights the MSP had been granted — which in many cases is extensive.

In the software-as-a-service variant, a cloud platform or SaaS application that holds client data is compromised, exposing that data without the client's own systems ever being touched. The client is a victim of the breach but had no control over the environment that was attacked.

Real-World Impact on NZ Businesses

Multiple supply chain incidents affecting businesses have been documented in recent years. The MOVEit file transfer software breach in 2023, the Okta customer support system compromise, and several large managed IT service provider incidents collectively affected organisations across multiple industries and geographies. In each case, affected organisations suffered real-world consequences — data exposure, regulatory obligations, and in some cases operational disruption — despite having done nothing wrong themselves.

What Gets Exposed in Supply Chain Attacks

The exposure from a supply chain attack depends entirely on what the compromised vendor accessed on your behalf. IT service providers with remote monitoring and management access can expose administrative credentials, internal systems, and all network-attached data. HR and payroll software providers can expose employee personal information, bank account details, and tax records. Legal practice management software can expose client files, correspondence, and privileged communications. Cloud storage platforms can expose whatever files were stored in them.

Does Cyber Insurance Cover Supply Chain Incidents?

Coverage for supply chain incidents has become one of the most important — and variable — aspects of cyber insurance policy design. Modern cyber policies typically include technology service provider failure coverage (sometimes called contingent business interruption), which responds to losses caused by a failure or breach of a third-party technology provider. However, the scope and sub-limits of this coverage vary significantly between policies.

When reviewing a cyber insurance policy, pay specific attention to whether technology service provider failure coverage requires the named provider to have suffered a covered cyber event, or whether it also responds to accidental outages. Also examine the sub-limit — some policies apply a significantly lower limit to TPF claims than to direct attacks. If your business is highly dependent on one or two critical SaaS platforms or an MSP, this is worth discussing specifically with your broker.

Managing Supply Chain Risk Before an Incident

Insurance is the financial backstop — the upstream risk management is vendor due diligence. Before granting any third-party provider access to your systems or data, it is worth asking whether they hold relevant security certifications (ISO 27001 is the most widely recognised), whether they carry their own cyber insurance (ask for a certificate of currency), what their incident notification obligations are if they suffer a breach affecting your data, and what contractual remedies you have if they cause a loss through inadequate security. These questions are increasingly standard in enterprise procurement — and worth asking even if you are not a large enterprise.

About the Author

CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.

Ready to Get Protected?

Get tailored cyber insurance quotes from licensed NZ brokers. Free advice, no obligation.

Get Your Free Cyber Insurance Quote

Free advice. No obligation. Licensed NZ brokers respond within 1 business day.