Security & Risk

Cyber risk, compliance and governance

87 analyses

Security & Risk7 min

The New Invisible Threat: Software Supply Chain Attacks More than Double in 2025

Incidents of software supply chain attacks more than doubled globally in 2025, exposing critical gaps in enterprise preparedness. The attack on tj-actions in March 2025 compromised CI/CD pipelines in thousands of repositories. The XZ Utils case from 2024, where an attacker spent two years building trust before inserting a backdoor, set the standard for the modern threat.

Read analysis →
Security & Risk7 min

Zero Trust in Practice: Why 35% of Implementations Fail and What Separates Those That Work

63% of organisations worldwide have implemented Zero Trust at least partially. However, 35% of initiatives reported failures that harmed the organisation. Gartner projects that 75% of US federal agencies will struggle to implement Zero Trust policies by the end of 2026. Organisations with mature programmes report 50% fewer breaches and reduce the average cost of a breach by 43%.

Read analysis →