According to ABN Amro, one in five Dutch organizations suffered harm from cyberattacks in 2024. Often these incidents were not direct hacks into the company itself but came through suppliers and partners. A supply chain is only as strong as its weakest link, and in an interconnected economy that link can expose thousands of organizations downstream.
When a supplier is compromised, you do not just inherit their weakness. You inherit their consequences.
What supply chain attacks actually are
At their core they are a form of third-party risk. Rather than targeting you directly, attackers compromise one of your suppliers, vendors or service providers, and use that position as a stepping stone into your environment.
A supply chain attack occurs when adversaries exploit the trust placed in third parties, whether software providers, managed service providers, logistics partners or hardware manufacturers, to gain unauthorized access or deliver a malicious payload.
Typical modes of compromise:
- Compromised vendor devices. Laptops, service tools or remote access accounts misused to reach your systems.
- Software dependencies. Malicious updates in open-source libraries.
- Leaked supplier credentials. Attackers log in through the front door of a critical environment.
- Third-party services. Cloud platforms, managed providers or outsourced IT breached upstream.
- Phishing the maintainers. Tricking the people who manage systems or software to gain widespread access.
Recent cases show how this plays out. In 2021 a ransomware hit on logistics provider Bakker Logistiek left Albert Heijn stores without stock. In 2024 Russian hackers reached sensitive police data by exploiting trusted third-party connections. Earlier this year the Shai-Hulud worm spread through more than 100 npm packages, affecting Dutch businesses that relied on them.
Why this is suddenly the topic
Supply chain and third-party risk have become central to both security strategy and regulation. At Cybersec Netherlands, speaker after speaker stressed that resilience across the chain is a requirement rather than an option.
Part of that is regulatory. The NIS2 Directive, in force between 2024 and 2026, explicitly obliges organizations in critical sectors to demonstrate control over their suppliers and partners. The latest edition of ISO/IEC 27001 does something similar, with updated controls requiring structured management of third-party risk.
The message is the same in both: you can no longer afford to assume your suppliers are secure. Without monitoring and accountability, regulators and attackers will find the gap at roughly the same time.
It reaches enterprise and SME alike
Supply chain risk is often framed as an enterprise problem. Large organizations do face the most immediate exposure: reputational damage, regulatory fines and costly disruption if they fail to secure a large ecosystem of suppliers. For them this is a board-level obligation.
The impact does not stop at the top. SMEs are drawn in, not because they are targeted at the same scale, but because their enterprise clients demand assurance. Larger organizations no longer want to carry the risk of weaker partners, which means SMEs must show they can withstand and recover from an incident, in tenders, in contract negotiations and in ongoing vendor assessments.
What was a multinational’s problem is now an expectation for smaller businesses too. If you want to stay in the chain, you have to show you are not the weakest link.
Signs of trouble in your chain
- Unexplained system anomalies or downtime traced back to a third party.
- Breaches disclosed by suppliers that may touch your data.
- Unmonitored connections from vendors into your network.
- No evidence that suppliers patch vulnerabilities in reasonable time.
How to strengthen it
A structured approach keeps this from overwhelming a small team.
- Map your dependencies. Keep an inventory of suppliers, service providers and partners that touch your critical processes or data.
- Segment and restrict access. Apply least privilege to supplier connections.
- Demand transparency. Ask vendors for security certifications, audit results and policies.
- Monitor continuously. Do not rely on an annual questionnaire. Watch exposures and leaked credentials in real time.
- Rehearse scenarios. Treat a supply chain attack like any other incident and run the tabletop exercise.

