Bitsight has released a report detailing the cyber risks associated with foreign-linked providers in the U.S. supply chain. Based on an analysis of 500,000 organizations and their relationships with over 12,000 providers, the findings indicate that many of these providers have ties to Chinese military-linked companies.
Key findings from the report reveal that one-third of the U.S. supply chain relies on software or services from companies designated by the Department of Defense as “Chinese Military Companies.” Furthermore, two-thirds depend on firms with ties to Chinese state-linked entities, raising concerns about data security and potential espionage.
Significantly, ByteDance Group, the parent company of TikTok, is connected to 35.4% of the U.S. market, highlighting how firms under scrutiny maintain substantial use across industries. The analysis underscores the challenges organizations face in securing their digital supply chains against foreign influence, as regulatory efforts continue to grapple with the entrenched position of Chinese state-linked firms.
The report also addresses the risks posed by less prominent software providers, referred to as “Hidden Pillars,” which support critical sectors such as energy and finance. While larger firms often receive attention in security discussions, smaller companies can exert considerable influence on supply chain safety. Findings suggest that a security failure at one of these smaller companies could have widespread repercussions.
Organizations in the supply chain also face unique cybersecurity challenges, as providers often have larger attack surfaces and more complex vendor relationships. Key findings indicate that providers have 2.5 times more products in use and ten times more internet-facing assets than their consumers, making them more susceptible to cyber threats.
Ben Edwards, Principal Research Scientist at Bitsight, stated, “Over the past year, we've seen several highly visible security incidents that highlight how incidents in the digital supply chain can have a massive ripple effect across the global economy.” He emphasizes the need for organizations to continuously evaluate their vendor relationships.
The complete report includes extensive findings on the landscape of the digital supply chain and risk assessment factors, along with anonymized examples of high-risk software providers globally.
Comments