Skip to content

// Directive: X0483

A New Contagion: Hybrid Threats in The Global Supply Chain_

By SIRM

  • Risk Management
Copy to clipboard

Part One

a Billion dollar dilemma

Supply chain attacks have emerged as one of the most significant security threats in recent years. Their impact can have global effects; mounting tension between neighbouring states as well as billions of dollars wiped off the markets in one single act. While these attacks have traditionally focused on software, hardware, and service providers, a worrying trend has emerged in the maritime sector. Oil tankers, crucial to global energy supply chains, have become a frequent target for sabotage, with numerous incidents reported this year alone.

At SIRM, we examine the intersection of these types of supply chain threats and offer tailored solutions to minimise risk. By analysing the increasing sophistication of supply chain attacks, their impact on organisations, SIRM provides strategic recommendations for mitigating these risks.


Part two

Sophistication and Guile

The concept of supply chain security has expanded beyond the traditional scope of IT networks and digital infrastructure. The rise of sophisticated supply chain attacks, such as those seen with software providers like SolarWinds, and the alarming uptick in targeted attacks on oil tankers, has forced organisations to rethink their approach to risk management.

In 2025, the maritime oil transport sector has experienced a surge in sabotage attacks against commercial vessels, particularly oil tankers. These attacks are a stark reminder of the physical and cyber risks that organisations face in securing their supply chains.


Part three

The Nature of Supply Chain Attacks

Software Supply Chain Attacks

Supply chain attacks in the digital realm often exploit vulnerabilities in the software development and distribution processes. A prime example of this is the SolarWinds attack, where hackers compromised software updates from a trusted vendor to infiltrate thousands of organisations globally. These attacks are difficult to detect and can go unnoticed for long periods, allowing attackers to gain persistent access to sensitive data and systems.

Hardware and Service Provider Attacks

Similarly, hardware-based attacks, such as the insertion of malicious components during manufacturing or distribution, can compromise the integrity of critical systems. Service provider attacks, such as the Kaseya VSA attack, target third-party managed service providers (MSPs), gaining access to the networks of their clients.

Maritime Oil Tanker Sabotage

This year, five separate attacks have targeted oil tankers. These attacks, typically involving the use of limpet mines or similar explosives to disable the vessel, have disrupted operations, leading to significant financial and reputational damage. The most recent attack on the Vilamoura, a Greek-owned tanker, occurred off the coast of Libya in June 2025, causing an explosion in the engine room. Fortunately, there were no casualties, but the incident highlights the increasing risk to physical infrastructure in the global supply chain.


Part four

Emerging Trends

The landscape of supply chain attacks is constantly evolving, with attackers adopting new methods and targeting increasingly complex and interconnected systems. Several key trends have emerged in recent years:

Rise of Ransomware and Double Extortion

Ransomware attacks are a growing threat, especially when delivered through compromised software updates or service providers. In a double extortion attack, attackers not only encrypt data but also steal sensitive information and threaten to release it if the ransom is not paid.

Targeting Critical Infrastructure

Attacks on critical infrastructure, including energy, healthcare, and financial sectors, are on the rise. These industries often rely on complex networks of suppliers and service providers, making them prime targets for cybercriminals and nation-state actors.

Geopolitical Influence and Maritime Sabotage

In addition to traditional cyber threats, geopolitical tensions are increasingly manifesting in the form of physical attacks on supply chains. The rise in sabotage incidents targeting oil tankers, particularly in the context of global energy transport, reflects this trend. The Vilamoura attack, along with others this year, highlights the vulnerabilities in the maritime sector, which is vital for the global flow of energy.

Use of Advanced Persistent Threats (APTs)

APTs, often associated with nation-state actors, are increasingly targeting supply chains. These attacks are typically long-term and aimed at espionage or intellectual property theft. APTs in the supply chain often remain undetected for months, exploiting trust relationships and gaining access to sensitive information.


Part Five

The Risk Management Response

In today’s increasingly interconnected business environment, supply chain attacks pose a significant and growing threat. At SIRM, we recognise that managing this risk demands a proactive, end-to-end approach that encompasses both digital and physical security domains. Our comprehensive solutions are designed to address the full lifecycle of supply chain risk management. Key focus areas include:

Third-Party Risk Assessment

Effective supply chain security begins with a clear understanding of third-party risk. We offer in-depth vendor risk assessment frameworks that evaluate the cybersecurity maturity, regulatory compliance, and resilience strategies of all third-party entities—vendors, service providers, and partners alike. By ensuring alignment with your organisation’s security policies and industry best practices, we help reduce exposure from external dependencies.

Enhancing Cybersecurity Posture

A resilient digital supply chain demands a multi-layered cybersecurity approach. We implement advanced solutions such as Zero Trust architectures, real-time threat detection, and AI-powered intrusion prevention systems. Our services also include continuous vulnerability assessments to ensure rapid threat identification and response.

Strengthening Physical Security in Maritime Operations

With maritime supply chains increasingly targeted, we provide robust physical security solutions for shipping operations. These include deployment of advanced surveillance systems, crew security training, and port infrastructure protection strategies.

Diversification of Supply Routes

Geographic diversification is a critical risk mitigation tactic. We assist organisations in identifying and evaluating alternative supply chain routes, leveraging geopolitical risk intelligence to support informed decision-making. Our strategic advisory services help clients build more agile and resilient logistics networks that can withstand regional disruptions.

Crisis Management and Communication

Preparedness is key to effective response. Our crisis management planning services include the development of incident response playbooks, stakeholder communication protocols, and coordination mechanisms with regulatory and law enforcement bodies. We facilitate tabletop exercises and simulations to ensure readiness for real-world events.

Real-Time Monitoring and Incident Response

Continuous visibility across digital and physical assets is essential for mitigating evolving threats. Our integrated monitoring solutions provide real-time insights into network traffic, third-party connections, and physical infrastructure status. Combined with a tailored incident response plan, we help organisations swiftly contain and recover from supply chain incidents, minimising operational and reputational impact.


Part Six

Confronting the threat

The rise of supply chain attacks, both digital and physical, presents a significant and evolving threat to global organisations. The recent spate of maritime oil tanker attacks highlights the vulnerabilities in physical infrastructure, while the continued prevalence of cyber-attacks on software providers demonstrates the growing complexity of the threat landscape.

Organisations must take a comprehensive, proactive approach to risk management, addressing both digital and physical security threats. By strengthening third-party risk assessments, implementing robust cybersecurity measures, and enhancing physical security protocols, organisations can better protect themselves against the growing threat of supply chain attacks.

At SIRM, we play a crucial role in helping organisations navigate these risks, offering expert advice, strategies, and solutions that safeguard the integrity of their supply chains and protect them from future disruptions.

Interested?

Want to learn more?

Let's start a conversation

Related insights