Bitsight’s 2025 report shows that global digital supply chains are vast, deeply interconnected, and concentrated around a relatively small set of critical providers that often sit behind major industries and markets. It also finds that provider organizations generally have a larger attack surface and weaker security posture than consumers, while some high-market-share providers still have long-lived vulnerabilities and elevated exposure. #Bitsight #Microsoft #Google #Oracle #jQuery #Cloudflare #CrowdStrike #SolarWinds #ByteDance #Alibaba #Tencent #Huawei
Keypoints
- Annual supply chain cybersecurity reports typically begin with an introduction that explains why supply chain risk matters, outlines the research scope, and defines the key terms used in the analysis.
- They usually include a methodology section describing the data sources, sample size, and analytical approach, followed by core findings broken into themes such as supply chain size, critical suppliers, security posture, and concentration risk.
- In this report, Bitsight analyzed more than 500,000 consumer organizations, 12,000 providers, 42,600 products, and nearly 61.5 million relationships to map the digital supply chain.
- The report emphasizes that a typical organization uses hundreds of products from dozens of providers, while providers themselves have 2.5x larger supply chains than consumers, creating a much larger attack surface.
- Providers also have 2.4x more providers, 26% broader product-category portfolios, and 10x more internet-facing assets than consumers on median.
- A recurring theme is that the supply chain is not a simple chain but a complex network, meaning disruptions can cascade across multiple paths and through nth-party dependencies.
- The report identifies “hidden pillars” as providers that serve a small number of companies but represent a large share of market revenue, making them critically important despite not appearing dominant by raw customer count.
- Market-share weighting reveals that some providers are far more important than company-count metrics suggest; for example, many tech and infrastructure firms support major portions of the global economy.
- The top 99 providers by revenue-weighted market share include highly pervasive names such as jQuery, Microsoft, Google, Oracle, Meta, F5, AWS, Apple, Cloudflare, and Let’s Encrypt.
- Some niche providers dominate specific industries, such as digital lending platforms for financial institutions, infrastructure software for utilities, and property management platforms for real estate, showing that criticality can be sector-specific.
- The report also highlights geographic concentration, noting that certain providers have outsized importance within specific countries or regions even if their global share is smaller.
- It finds that 33% of the US supply chain relies on companies listed by the US Department of Defense as “Chinese Military Companies,” with two-thirds of the US supply chain relying on the broader set of Chinese providers discussed in the report.
- Among top Chinese providers serving the US supply chain are Alibaba, Baidu, ByteDance, Tencent, China Telecom, Qihoo 360, Huawei, and others, raising policy and national-security concerns.
- The report shows that provider size and digitization correlate with market share, but the relationship is weak enough that small teams can still control highly critical software or frameworks.
- Examples include open-source and framework ecosystems such as Angular and React, which have relatively few custodians but broad supply-chain reach.
- On security performance, providers generally score slightly worse than consumers, with differences of up to 20% in 16 of 22 Bitsight risk vectors analyzed.
- Providers do better in several email and domain-security controls, including DMARC, SPF, DKIM, and DNSSEC, suggesting stronger baseline hygiene in some defensive areas.
- The report notes that large providers are often worse than the overall population of monitored organizations, not just smaller peers, indicating that scale does not guarantee better security.
- Specific high-risk examples include organizations with large market share, large attack surfaces, and long remediation timelines, such as a manufacturing company with long-standing vulnerabilities and over 181,000 internet-facing assets, and a data center company taking more than a year to fix typical vulnerabilities.
- Event-rate analysis shows weak correlation between market share and the number of new security findings, meaning critical providers can be either well maintained or persistently exposed.
- Examples cited include providers with high botnet infection rates, insecure system rates, open-port findings, and long vulnerability lifetimes, illustrating that systemic risk is unevenly distributed.
- A major takeaway is that some providers with greater than 25% market share also have large attack surfaces, many open vulnerabilities, and slow remediation, creating a potentially severe supply-chain failure point.
- The conclusions recommend that organizations enumerate their supply chains, evaluate provider criticality, assess provider security posture, communicate findings to vendors, examine fourth-party dependencies, and assess their own role as a potential critical supplier.
- Overall, the report’s central message is that concentration, digitization, and weak security posture combine to make certain providers disproportionately important to the stability of the global digital economy.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)