When the Supplier Becomes the Entry Point: Supply Chain Ransomware Under NIS2 and DORA

Stefan Röthlisberger
Founder & CEO, IRONATE
The European ransomware landscape in 2026 can be distilled into three converging forces: rising ransomware volumes, suppliers as the entry point, and a European legal framework that holds organizations liable for the security of their third parties (data basis: 2026 Europe Cyber Risk Report, Black Kite). While the first point makes headlines, the second is structurally the more dangerous one, and the third turns it from an IT issue into a boardroom issue. This article dissects the supply chain dimension and its regulatory consequences for Switzerland.
64 organizations, one supplier: the anatomy of the cascade
Across its 31-country dataset, the report identifies 64 European organizations that were pulled into a ransomware or data extortion incident not through their own systems but through a supplier. The truly unsettling part: 34 of these 64 cases, more than half, trace back to a single event, the compromise of the Swedish software supplier Miljödata on the weekend of August 23, 2025.
Miljödata provides HR systems for roughly 80% of Swedish municipalities. Exactly this market penetration turned a single breach into a national disruption: around 200 municipalities and regions were affected, about 250 customers contacted the Swedish data protection authority, and the data of more than one million people was published online, even though none of these organizations had experienced a direct breach of their own systems.
The report's methodology makes the picture even conservative: cascades through a single supplier are counted as one incident in the volume statistics. The report explicitly states that the 34 named Miljödata victims are only a subset of a far larger affected population. The real reach of such incidents is therefore greater than any incident count suggests.
Salesforce, Drift and the brand-name victims
Miljödata is not an isolated case, just the largest one. Through the compromise of the Salesforce and Drift ecosystem, seven more European organizations were drawn into incidents, including names such as Chanel, Pandora, Air France-KLM and Stellantis (via Salesforce environments) as well as Esker, Sophos and ContentSquare (via the connected Drift integration). The pattern is identical: it was not the target company that was hacked, but a shared platform it used.
Collins Aerospace: when shared infrastructure grounds airports
How physical this effect can become was demonstrated in September 2025: a ransomware attack on the MUSE platform from Collins Aerospace, a shared check-in and boarding infrastructure, forced the airports of Heathrow, Brussels, Berlin, Dublin and Cork into manual processing for days. The incident was claimed by the Everest group and confirmed by ENISA. One supplier, five countries, one visible standstill.
Why IT service providers are the most attractive target
Behind these cases lies a logic the report backs with hard numbers: Computer Systems Design and Related Services, classic IT service providers, is Europe's most attacked subindustry at 5.4% of all incidents. That is no coincidence. An IT service provider sits inside its customers' processes, networks and identities. Whoever compromises it gains not one target but a portfolio.
This is aggravated by a structural dependency: according to the report, the EU sources more than 80% of its essential digital products, services, infrastructure and intellectual property from outside the EU. The report points to the political goal of cutting this dependency significantly (to around 40%) by 2030, a direction also taken up by the EU Tech Sovereignty Package presented in June 2026. For Switzerland, a closely interconnected non-EU market, this means the supply chain almost always extends beyond its own jurisdiction.
How likely is a supplier incident? The RSI score
Supply chain risk can be quantified. For this, the report uses Black Kite's Ransomware Susceptibility Index (RSI), which models the likelihood of a ransomware attack on a scale from 0.0 to 1.0, fed by technical exposure (exploitable vulnerabilities, exposed remote access, leaked credentials) and intrinsic factors (industry, location, size). The relationship is anything but linear.
The message is clear: a single supplier with poor hygiene, poorly patched, exposed services, leaked credentials, is not an abstract risk but a measurably increased probability of an incident. This is exactly where continuous attack surface monitoring comes in, as delivered by RECON.
The new liability: NIS2, DORA and the CER Directive
The decisive difference from earlier years is not technical but legal. Under the European regime, managing supplier security is no longer a voluntary best practice but a statutory obligation whose violation is sanctioned.
NIS2 (Directive (EU) 2022/2555) anchors a supply chain security obligation in Article 21 and explicitly places the responsibility for it with executive management. It applies to 18 critical sectors. Violations are punishable for essential entities with up to EUR 10 million or 2% of global annual revenue, and for important entities with up to EUR 7 million or 1.4%. The transposition deadline was October 17, 2024; by early 2026, around 20 of the 27 member states had transposed NIS2 into national law, and on May 7, 2025 the European Commission opened infringement proceedings against 19 lagging states.
DORA (Regulation (EU) 2022/2554) has been applicable since January 17, 2025 and addresses roughly 20 types of financial entities. It requires continuous management of ICT third-party risk, including a contractual right to ongoing monitoring. Critical ICT third-party providers fall under a direct EU oversight regime and risk periodic penalty payments of up to 1% of their average global daily revenue (for up to six months); financial entities face fines of up to 2% of global annual revenue. The picture is completed by the CER Directive (EU 2022/2557), which requires a risk assessment including supplier dependency for 11 critical sectors.
| Regulation | Scope | Reporting deadline | Sanctions |
|---|---|---|---|
| NIS2 (EU) 2022/2555 | 18 critical sectors (EU) | 24 h / 72 h / 1 month | up to EUR 10M / 2% (essential); EUR 7M / 1.4% (important) |
| DORA (EU) 2022/2554 | Financial sector, ~20 entity types | 4 h / 24 h / 72 h / 1 month | up to 2% of annual revenue; critical ICT providers up to 1% of daily revenue |
| CER (EU) 2022/2557 | 11 critical sectors | national requirements | set by member states |
| revDSG CH, since Sep 1, 2023 | all processors of personal data | "as quickly as possible" (Art. 24) | fines up to CHF 250,000 (against responsible individuals) |
| ISG reporting obligation CH, since Apr 1, 2025 | critical infrastructures | 24 h | up to CHF 100,000 for failure to report (from Oct 1, 2025) |
And Switzerland? revDSG, FINMA and the reporting obligation
Switzerland stands outside NIS2 and DORA, but by no means outside the obligations. Three points are central for Swiss organizations. First: the revised Swiss Data Protection Act (revDSG, in force since September 1, 2023) requires in Art. 24 that breaches of data security be reported to the Swiss Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible. Since ransomware almost always comes with data exfiltration, this obligation applies even when systems were restored from backup; the Radix case demonstrated this vividly.
Second: operators of critical infrastructures have been subject to a 24-hour reporting obligation to the Swiss Federal Office for Cybersecurity (BACS) since April 1, 2025. Non-compliance can be sanctioned with fines of up to CHF 100,000 since October 1, 2025. Third: in the financial sector, FINMA (circulars on operational risks and cyber risks) expects active management of outsourcing and ICT third parties, in effect a DORA-like standard even without formal DORA applicability.
For a Swiss company with EU customers, EU subsidiaries or in the role of supplier to an EU-regulated entity, one more thing holds: the European obligations reach into Switzerland by contract. Whoever supplies a NIS2- or DORA-regulated customer will find that customer's due diligence duties reflected as contract clauses.
From point-in-time audits to continuous monitoring
NIS2 and DORA converge on one point the report also names precisely: both require continuous monitoring of third parties instead of a snapshot. An annual supplier questionnaire is accurate exactly on the day it is filled out, and outdated afterwards. Cyber risks move faster than audit cycles. What an organization cannot see, it cannot control.
Frequently Asked Questions
What is supply chain ransomware?
Ransomware and extortion incidents in which organizations are hit through a compromised supplier instead of through their own systems. The report counts 64 such European cases, 34 of them through the software supplier Miljödata alone.
Is a company liable for its suppliers under NIS2?
Yes. NIS2 (EU 2022/2555, Art. 21) requires supply chain security management and holds executive management responsible. Fines: up to EUR 10 million or 2% of revenue (essential entities), EUR 7 million or 1.4% (important entities).
What does DORA require regarding IT service providers?
DORA (applicable since January 17, 2025) requires continuous management of ICT third-party risk, including a contractual monitoring right. Critical ICT third-party providers fall under direct EU oversight and penalty payments of up to 1% of daily revenue.
Do I have to report in Switzerland if I restore from backup?
Yes, as soon as personal data has been exfiltrated. The revDSG (Art. 24) requires notification of the FDPIC regardless of payment or recovery. Critical infrastructures have had to report within 24 hours since April 1, 2025, with fines of up to CHF 100,000 since October 1, 2025.
How do you reduce supply chain ransomware risk?
Through continuous visibility instead of point-in-time audits: attack surface monitoring (RECON), network- and identity-based detection (NDR, DNS, UEBA) and automated incident response that meets the reporting deadlines.
summarize Summary / Key Takeaways
- check_circle64 European organizations were pulled into ransomware incidents through suppliers, 34 of them through the software supplier Miljödata alone (more than 1 million exposed personal data records).
- check_circleIT service providers are the most attacked subindustry (5.4%) because, as suppliers, they sit inside their customers' processes. The EU sources more than 80% of essential digital goods from outside.
- check_circleThe Ransomware Susceptibility Index (RSI, Black Kite) shows: a vendor with a score above 0.8 is 96 times more likely to be a ransomware target than one below 0.2.
- check_circleNIS2, DORA and CER make supply chain security a legal obligation with fines of up to EUR 10 million / 2% of revenue. In Switzerland, the revDSG, the ISG reporting obligation (CHF 100,000) and FINMA expectations apply.
- check_circlePoint-in-time audits are no longer enough. What is required is continuous attack surface monitoring (RECON), detection (NDR / DNS / UEBA) and deadline-compliant, automated response.
Sources & References
- • Black Kite: 2026 Europe Cyber Risk Report - blackkite.com (Third-Party Risk, Regulatory Accountability, Next Steps)
- • European Commission: NIS2 Directive & transposition status - digital-strategy.ec.europa.eu
- • EUR-Lex: Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2557 (CER) - eur-lex.europa.eu
- • FDPIC (Swiss Federal Data Protection and Information Commissioner): revised Swiss Data Protection Act (revDSG), Art. 24 - edoeb.admin.ch
- • CMS: "Failure to report cyberattacks on critical infrastructure" (CH, ISG, CHF 100,000) - cms.law
- • BleepingComputer: "Switzerland says government data stolen in ransomware attack" (Radix) - bleepingcomputer.com
- • ENISA: situation report on the Collins Aerospace/MUSE disruption - enisa.europa.eu
Know your supply chain exposure before a lawyer does
RECON maps your attack surface continuously; NDR, DNS Shield and UEBA detect the attack even when it comes through a supplier. Swiss sovereignty, on-premises, compliant with the Swiss Data Protection Act.
Request a no-obligation consultation arrow_forward