الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Qualified cybersecurity staff shortage in the Middle East among key obstacles in curbing supply chain risks

A new global Kaspersky study has identified the lack of qualified IT security workers (44%) and the need for global organizations to prioritize various security tasks to mitigate the risk of supply chain and trusted relationship attacks (42%), cited by respondents in the Middle East.
Kaspersky’s recent study* on supply chain and trusted relationship risks showed that supply chain attacks have emerged as a top threat for businesses, with every third organization hit by such an attack over the past year. The severity and frequency of supply chain attacks necessitate uncovering the key reasons preventing them from addressing the risks successfully.
According to the survey, one of the key barriers to reducing supply chain and trusted relationship risks is the lack of a qualified workforce. This shortage leaves organizations without the capacity to consistently access and monitor possible third-party vulnerabilities across their ecosystems. Among other primary obstacles, respondents noted the need to juggle multiple cybersecurity priorities. This reflects the fact that security teams are stretched across too many tasks at once, which might leave supply chain threats unaddressed.
Beyond resource constraints, respondents also point to structural issues: 34% say their contracts lack clear IT security obligations for contractors. Further 35% note that nonIT security staff often do not fully understand these risks.
Globally, according to the survey, an overwhelming 83% of businesses admit their organizations need to upgrade protection against supply chain and trusted relationship risks, with only 17% of enterprises considering their current security measures effective.
At the same time, the results of the survey showed that current mitigation practices for third-party risks remain fragmented, with no way of protection getting more than 41% of current adopters. Even the most common protective measure, two-factor authentication, is used by only 39% of respondents. In addition, only 41% of organizations conduct regular reviews of contractors’ cybersecurity postures. As a result, nearly two thirds of businesses lack ongoing visibility into the security of their partners, leaving them exposed to evolving vulnerabilities across their ecosystems.
It’s noteworthy, that companies that have already experienced supply chain and trusted relationship attacks, tend to adopt stronger security habits. Global results have shown that those hit by supply chain incidents are more likely to request penetration test results (56%), while victims of trusted relationship breaches prioritize checks on compliance with industry standards (56%) and their contractors’ own supply chain policies (53%).
“When security teams are overstretched, understaffed and have to prioritize urgent tasks over long term resilience priorities, organizations are left exposed to threats that can move silently through their provider ecosystem. To break this cycle, the industry needs to adopt more unified and consistent mitigation strategies, from standardized contractor assessments to stronger cross team awareness. Supply chain security should become a shared, enforceable responsibility across the entire business network,” comments Sergey Soldatov, Head of Security Operations Center at Kaspersky.
Only by implementing preventive measures across the organization and approaching partnerships with suppliers and contractors strategically can companies reduce supply chain risks and ensure the resilience of their business.
For mitigating such risks, Kaspersky recommends the following:
• Adopt managed security services. For organizations lacking dedicated cybersecurity resources, the best solution is to resort to outsourcing. Use such services as Kaspersky Managed Detection and Response (MDR) and / or Incident Response, which cover the entire incident management cycle – from threat identification to continuous protection and remediation.
• Invest in additional cybersecurity courses. Enhance the cybersecurity knowledge of your employees with practically-oriented self-guided or live Kaspersky Cybersecurity Training. These educational programs help security professionals advance their hard skills and protect companies against sophisticated attacks.
• Thoroughly evaluate suppliers before entering a deal. Check their cybersecurity policies, information about past incidents and compliance with industry security standards. For software and cloud services, it’s also recommended to review vulnerability data and penetration test results.
• Implement contractual security requirements. Contracts with suppliers should include specific information security requirements, such as regular security audits, compliance with your organization’s relevant security policies, and incident notification protocols.
• Collaborate with suppliers on security issues. Strengthen protection on both sides and make it a shared priority.
More recommendations along with other findings on supply chain risks mitigation are available via the link.
*For the report, Kaspersky internal market research center commissioned a survey, questioning 1,714 technical experts, ranking from C-level employees and vice-presidents to team leads and senior specialists from enterprises with more than 500 employees. The study covered 16 countries, including Germany, Spain, Italy, Brazil, Mexico, Colombia, Singapore, Vietnam, China, India, Indonesia, Saudi Arabia, Turkey, Egypt, the United Arab Emirates and Russia.

Related Posts:

Rixos to open first all-inclusive resort in Thailand

Türkiye’s summer isn’t just about the beach, it’s about what’s on the table next to it

وزير الخارجية يشارك في الاجتماع السنوي لرؤساء البعثات الدبلوماسية الرومانية

Saudi Arabia’s Smart Home Shift Gains Momentum as Dreame Launches X60 Ultra Complete

AMAK Strengthens Growth Pipeline with Major Jabal Qaran Mineral Resource in Najran

HUAWEI nova 15 Max: 8500mAh Battery and Durable Design for Students

RcrutAI Launches Panther AI for Real Estate Development

TikTok for Entrepreneurs Launches Second Edition in Egypt

آخر الأخبار
هبة عبد العزيز تهنئ الشعب التركي بعيد النصر وتقدّر جهود السفير صالح موتلو شن في تعزيز التقارب بين ال... ١٣ مليون و ٧٤٢ ألف جنيه حصيلة البيع بجلسة مزاد ٣ سبتمبر ٢٠٢٦ لسيارات جمرك مطار القاهرة وسفاجا وبضائع... رئيس الوزراء يشهد توقيع مذكرة تفاهم لإقامة قاعدة لتخطيط وإنشاء مصانع السيارات ووسائل النقل في مصر وزير الاستثمار: توحيد البيانات وقواعد المعلومات العربية يدعم المستثمرين ويسهل توسعهم وانتقالهم بين ا... بلاك دايموند تعزز شراكتها مع سفارة عُمان بملتقيات الاستثمار ميلينيوم وكوبثورن تعزز محفظة مشاريعها بـ29 مشروعًا مدفوعة بنموذج المالك والمشغّل لدعم النمو الإقليمي وزيرة التنمية المحلية تبحث مع وزير البيئة والطاقة الإيطالي مجالات التعاون المشترك البحرين توقّع عقد مشاركتها رسمياً في إكسبو 2030 الرياض «الرقابة المالية» توضح موقفها من «حوالة الحق» في عقود المطورين العقاريين "كومفولت" تؤكد أهمية المرونة السيبرانية لمواكبة توسع السعودية في استخدام التقنيات السحابية والذكاء ا... شركة " URBAN EXPANSIONS " تعيّن باسم نصري رئيسًا للقطاع التجاري لدعم خطط النمو والتوسع سال ومايكروسوفت تستكشفان فرص التعاون في التحول الرقمي والخدمات اللوجستية الرقمية خلال "ليب 2026" أرتيفاكت ووزارة الاتصالات في السعودية تطلقان «اكاديمية أرتيفاكت للذكاء الاصطناعي والبيانات» "الزراعة" تواصل حملاتها المكثفة للتفتيش على مراكز بيع وتداول المستحضرات البيطرية عاجل.. الرئيس السيسي يتلقى اتصالًا هاتفيًا من الأمير محمد بن سلمان ولي عهد السعودية «الصحة» تحذر من الشركات غير المرخصة لمكافحة الحشرات وتنشر قائمة الشركات المعتمدة مجلس الوزراء يوافق على 11 قرارا خلال اجتماعه الأسبوعى اليوم.. تعرف عليهم تنظيم الاتصالات يطرح الرقم 600 للشركات في مزاد علني هيئة سلامة الغذاء تكثف حملاتها الرقابية على مياه الشرب المعبأة بمختلف محافظات الجمهورية «التعمير والإسكان» يعزز جاهزيته لمواجهة الهجمات السيبرانية بتدريب تفاعلي بالتعاون مع Unit 42