Kaspersky flags talent gap in UAE supply chain security
A shortage of skilled cybersecurity talent is limiting organisations’ ability to monitor third-party vulnerabilities consistently
24 March, 2026
TT
16
A new global study by Kaspersky has highlighted key gaps in how organisations are addressing supply chain and trusted relationship cyber risks, with UAE respondents pointing to skills shortages and competing priorities as major challenges.
According to the findings, 40 per cent of respondents in the UAE cited a lack of qualified IT security professionals as a primary barrier, while 47 per cent said organisations are struggling to prioritise security tasks effectively to mitigate risks linked to third-party ecosystems.
The study shows that supply chain attacks have become a significant threat globally, with one in three organisations reporting an incident over the past year. Despite this, many companies continue to face structural and operational challenges in strengthening their defences.
A shortage of skilled cybersecurity talent is limiting organisations’ ability to monitor third-party vulnerabilities consistently, while overstretched security teams are often forced to focus on immediate threats rather than long-term resilience.
Beyond workforce constraints, the report highlights governance gaps. Around 37 per cent of respondents said contracts lack clear IT security obligations for contractors, while 38 per cent noted that non-IT staff often lack sufficient awareness of supply chain risks.
Globally, 78 per cent of organisations acknowledged the need to strengthen protection against supply chain and trusted relationship threats, with only 22 per cent considering their current measures effective.
The study also found that mitigation strategies remain fragmented. No single security measure is used by more than 40 per cent of organisations, with even widely adopted tools such as two-factor authentication implemented by only 40 per cent of respondents. Additionally, just 38 per cent conduct regular reviews of contractors’ cybersecurity posture, leaving many organisations with limited visibility into third-party risks.
Companies that have previously experienced supply chain or trusted relationship attacks tend to adopt stronger security practices. These organisations are more likely to request penetration testing results and assess compliance with industry standards and supplier security policies.
Sergey Soldatov, Head of Security Operations Center at Kaspersky, said: “When security teams are overstretched, understaffed and have to prioritize urgent tasks over long term resilience priorities, organizations are left exposed to threats that can move silently through their provider ecosystem. To break this cycle, the industry needs to adopt more unified and consistent mitigation strategies, from standardized contractor assessments to stronger cross team awareness. Supply chain security should become a shared, enforceable responsibility across the entire business network.”
Kaspersky said organisations can reduce supply chain risks by adopting a more structured approach to cybersecurity, including implementing managed security services, strengthening employee training, and embedding clear security requirements into supplier contracts.
The company also recommended closer collaboration with suppliers to ensure shared accountability for cybersecurity, alongside more rigorous due diligence when selecting partners, including reviewing past incidents, compliance standards and vulnerability assessments.
The study was based on a survey of 1,714 technical professionals across 16 countries, including the UAE, Saudi Arabia, India and Germany, covering organisations with more than 500 employees.
Read: Kaspersky deepens Saudi footprint with university partnership





















