Home NDR Monitoring DNS Shield UEBA Analytics RECON Scanner Blog Company Deutsch (DE) Contact
arrow_back Back to blog
Third-Party Risk / Compliance13 min read• June 29, 2026

When the Supplier Becomes the Entry Point: Supply Chain Ransomware Under NIS2 and DORA

Stefan Röthlisberger

Stefan Röthlisberger

Founder & CEO, IRONATE

The European ransomware landscape in 2026 can be distilled into three converging forces: rising ransomware volumes, suppliers as the entry point, and a European legal framework that holds organizations liable for the security of their third parties (data basis: 2026 Europe Cyber Risk Report, Black Kite). While the first point makes headlines, the second is structurally the more dangerous one, and the third turns it from an IT issue into a boardroom issue. This article dissects the supply chain dimension and its regulatory consequences for Switzerland.

64 organizations, one supplier: the anatomy of the cascade

Across its 31-country dataset, the report identifies 64 European organizations that were pulled into a ransomware or data extortion incident not through their own systems but through a supplier. The truly unsettling part: 34 of these 64 cases, more than half, trace back to a single event, the compromise of the Swedish software supplier Miljödata on the weekend of August 23, 2025.

Miljödata provides HR systems for roughly 80% of Swedish municipalities. Exactly this market penetration turned a single breach into a national disruption: around 200 municipalities and regions were affected, about 250 customers contacted the Swedish data protection authority, and the data of more than one million people was published online, even though none of these organizations had experienced a direct breach of their own systems.

Cascade effect of the Miljödata compromise A single compromised supplier (Miljödata) hit around 200 Swedish municipalities and regions, about 25 companies and several universities, and exposed more than one million personal data records. 34 of 64 European supplier-driven victims trace back to this incident. One supplier, one cascade: the Miljödata case (Aug. 2025) ~200 Municipalities & regions ~25 Companies several universities 1M+ personal records exposed Miljödata 1 supplier 34 of 64 European supplier-driven victims trace back to this one incident.
Figure 1: Blast radius of the Miljödata compromise. Source: Black Kite, 2026 Europe Cyber Risk Report (Third-Party Risk); BleepingComputer. Graphic: IRONATE.

The report's methodology makes the picture even conservative: cascades through a single supplier are counted as one incident in the volume statistics. The report explicitly states that the 34 named Miljödata victims are only a subset of a far larger affected population. The real reach of such incidents is therefore greater than any incident count suggests.

Salesforce, Drift and the brand-name victims

Miljödata is not an isolated case, just the largest one. Through the compromise of the Salesforce and Drift ecosystem, seven more European organizations were drawn into incidents, including names such as Chanel, Pandora, Air France-KLM and Stellantis (via Salesforce environments) as well as Esker, Sophos and ContentSquare (via the connected Drift integration). The pattern is identical: it was not the target company that was hacked, but a shared platform it used.

Collins Aerospace: when shared infrastructure grounds airports

How physical this effect can become was demonstrated in September 2025: a ransomware attack on the MUSE platform from Collins Aerospace, a shared check-in and boarding infrastructure, forced the airports of Heathrow, Brussels, Berlin, Dublin and Cork into manual processing for days. The incident was claimed by the Everest group and confirmed by ENISA. One supplier, five countries, one visible standstill.

Why IT service providers are the most attractive target

Behind these cases lies a logic the report backs with hard numbers: Computer Systems Design and Related Services, classic IT service providers, is Europe's most attacked subindustry at 5.4% of all incidents. That is no coincidence. An IT service provider sits inside its customers' processes, networks and identities. Whoever compromises it gains not one target but a portfolio.

This is aggravated by a structural dependency: according to the report, the EU sources more than 80% of its essential digital products, services, infrastructure and intellectual property from outside the EU. The report points to the political goal of cutting this dependency significantly (to around 40%) by 2030, a direction also taken up by the EU Tech Sovereignty Package presented in June 2026. For Switzerland, a closely interconnected non-EU market, this means the supply chain almost always extends beyond its own jurisdiction.

How likely is a supplier incident? The RSI score

Supply chain risk can be quantified. For this, the report uses Black Kite's Ransomware Susceptibility Index (RSI), which models the likelihood of a ransomware attack on a scale from 0.0 to 1.0, fed by technical exposure (exploitable vulnerabilities, exposed remote access, leaked credentials) and intrinsic factors (industry, location, size). The relationship is anything but linear.

Ransomware likelihood by RSI score (source: Black Kite) Relative to the baseline (RSI below 0.2), vendors with RSI 0.2 to 0.4 are 2.5 times, 0.4 to 0.6 11.6 times, 0.6 to 0.8 17.6 times and above 0.8 96 times more frequently hit by ransomware. Ransomware likelihood by RSI score Relative to the baseline (RSI < 0.2 = 1x) RSI < 0.2 RSI 0.2–0.4 2.5× RSI 0.4–0.6 11.6× RSI 0.6–0.8 17.6× RSI > 0.8 96× A vendor with an RSI above 0.8 is 96 times more likely to be a target than one below 0.2.
Figure 2: Relative ransomware likelihood by RSI risk band. Source: Black Kite, 2026 Europe Cyber Risk Report (Regulatory Accountability). Graphic: IRONATE.

The message is clear: a single supplier with poor hygiene, poorly patched, exposed services, leaked credentials, is not an abstract risk but a measurably increased probability of an incident. This is exactly where continuous attack surface monitoring comes in, as delivered by RECON.

The new liability: NIS2, DORA and the CER Directive

The decisive difference from earlier years is not technical but legal. Under the European regime, managing supplier security is no longer a voluntary best practice but a statutory obligation whose violation is sanctioned.

Regulatory milestones 2023 to 2025: EU and Switzerland revDSG in force September 2023, NIS2 transposition deadline October 2024, DORA applicable January 2025, Swiss reporting obligation for critical infrastructures April 2025, European Commission opens 19 infringement proceedings May 2025, Swiss fines up to CHF 100000 from October 2025. Regulatory milestones 2023–2025 EU Switzerland Sep. 2023 revDSG Oct. 2024 NIS2 deadline Jan. 17, 2025 DORA applicable Apr. 1, 2025 CH reporting duty CI May 7, 2025 19 EU proceedings Oct. 1, 2025 CH fines 100k
Figure 3: Key regulatory milestones in the EU and Switzerland. Sources: European Commission (NIS2 transposition), EUR-Lex, BACS, Information Security Act (ISG). Graphic: IRONATE.

NIS2 (Directive (EU) 2022/2555) anchors a supply chain security obligation in Article 21 and explicitly places the responsibility for it with executive management. It applies to 18 critical sectors. Violations are punishable for essential entities with up to EUR 10 million or 2% of global annual revenue, and for important entities with up to EUR 7 million or 1.4%. The transposition deadline was October 17, 2024; by early 2026, around 20 of the 27 member states had transposed NIS2 into national law, and on May 7, 2025 the European Commission opened infringement proceedings against 19 lagging states.

DORA (Regulation (EU) 2022/2554) has been applicable since January 17, 2025 and addresses roughly 20 types of financial entities. It requires continuous management of ICT third-party risk, including a contractual right to ongoing monitoring. Critical ICT third-party providers fall under a direct EU oversight regime and risk periodic penalty payments of up to 1% of their average global daily revenue (for up to six months); financial entities face fines of up to 2% of global annual revenue. The picture is completed by the CER Directive (EU 2022/2557), which requires a risk assessment including supplier dependency for 11 critical sectors.

Regulation Scope Reporting deadline Sanctions
NIS2
(EU) 2022/2555
18 critical sectors (EU)24 h / 72 h / 1 monthup to EUR 10M / 2% (essential); EUR 7M / 1.4% (important)
DORA
(EU) 2022/2554
Financial sector, ~20 entity types4 h / 24 h / 72 h / 1 monthup to 2% of annual revenue; critical ICT providers up to 1% of daily revenue
CER
(EU) 2022/2557
11 critical sectorsnational requirementsset by member states
revDSG
CH, since Sep 1, 2023
all processors of personal data"as quickly as possible" (Art. 24)fines up to CHF 250,000 (against responsible individuals)
ISG reporting obligation
CH, since Apr 1, 2025
critical infrastructures24 hup to CHF 100,000 for failure to report (from Oct 1, 2025)

And Switzerland? revDSG, FINMA and the reporting obligation

Switzerland stands outside NIS2 and DORA, but by no means outside the obligations. Three points are central for Swiss organizations. First: the revised Swiss Data Protection Act (revDSG, in force since September 1, 2023) requires in Art. 24 that breaches of data security be reported to the Swiss Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible. Since ransomware almost always comes with data exfiltration, this obligation applies even when systems were restored from backup; the Radix case demonstrated this vividly.

Second: operators of critical infrastructures have been subject to a 24-hour reporting obligation to the Swiss Federal Office for Cybersecurity (BACS) since April 1, 2025. Non-compliance can be sanctioned with fines of up to CHF 100,000 since October 1, 2025. Third: in the financial sector, FINMA (circulars on operational risks and cyber risks) expects active management of outsourcing and ICT third parties, in effect a DORA-like standard even without formal DORA applicability.

For a Swiss company with EU customers, EU subsidiaries or in the role of supplier to an EU-regulated entity, one more thing holds: the European obligations reach into Switzerland by contract. Whoever supplies a NIS2- or DORA-regulated customer will find that customer's due diligence duties reflected as contract clauses.

From point-in-time audits to continuous monitoring

NIS2 and DORA converge on one point the report also names precisely: both require continuous monitoring of third parties instead of a snapshot. An annual supplier questionnaire is accurate exactly on the day it is filled out, and outdated afterwards. Cyber risks move faster than audit cycles. What an organization cannot see, it cannot control.

travel_explore
Map the attack surface continuously (RECON): RECON detects exposed services, unpatched endpoints and leaked credentials automatically and continuously: exactly the factors that feed a high RSI score. The MSP-ready multi-tenant portal makes it possible to observe your own and your suppliers' exposure across multiple tenants instead of asking once a year.
smart_toy
Meet reporting deadlines through automation: 24 hours (NIS2, ISG), 72 hours, four hours (DORA): these deadlines are barely achievable without automation. Whoever defines isolation, escalation and reporting in advance as a playbook, and includes the supplier incident scenario in it, meets them even at night and over the weekend. Without this groundwork, the deadline remains a statement of intent.
radar
Detection when the supplier is the vector (NDR, DNS, UEBA): If the attack comes through a service provider with legitimate access, classic perimeter logic fails. NDR detects anomalous lateral movement, DNS Shield blocks C2 and exfiltration channels, and UEBA sees when a supplier account suddenly behaves atypically.

Frequently Asked Questions

What is supply chain ransomware?

Ransomware and extortion incidents in which organizations are hit through a compromised supplier instead of through their own systems. The report counts 64 such European cases, 34 of them through the software supplier Miljödata alone.

Is a company liable for its suppliers under NIS2?

Yes. NIS2 (EU 2022/2555, Art. 21) requires supply chain security management and holds executive management responsible. Fines: up to EUR 10 million or 2% of revenue (essential entities), EUR 7 million or 1.4% (important entities).

What does DORA require regarding IT service providers?

DORA (applicable since January 17, 2025) requires continuous management of ICT third-party risk, including a contractual monitoring right. Critical ICT third-party providers fall under direct EU oversight and penalty payments of up to 1% of daily revenue.

Do I have to report in Switzerland if I restore from backup?

Yes, as soon as personal data has been exfiltrated. The revDSG (Art. 24) requires notification of the FDPIC regardless of payment or recovery. Critical infrastructures have had to report within 24 hours since April 1, 2025, with fines of up to CHF 100,000 since October 1, 2025.

How do you reduce supply chain ransomware risk?

Through continuous visibility instead of point-in-time audits: attack surface monitoring (RECON), network- and identity-based detection (NDR, DNS, UEBA) and automated incident response that meets the reporting deadlines.

summarize Summary / Key Takeaways

  • check_circle64 European organizations were pulled into ransomware incidents through suppliers, 34 of them through the software supplier Miljödata alone (more than 1 million exposed personal data records).
  • check_circleIT service providers are the most attacked subindustry (5.4%) because, as suppliers, they sit inside their customers' processes. The EU sources more than 80% of essential digital goods from outside.
  • check_circleThe Ransomware Susceptibility Index (RSI, Black Kite) shows: a vendor with a score above 0.8 is 96 times more likely to be a ransomware target than one below 0.2.
  • check_circleNIS2, DORA and CER make supply chain security a legal obligation with fines of up to EUR 10 million / 2% of revenue. In Switzerland, the revDSG, the ISG reporting obligation (CHF 100,000) and FINMA expectations apply.
  • check_circlePoint-in-time audits are no longer enough. What is required is continuous attack surface monitoring (RECON), detection (NDR / DNS / UEBA) and deadline-compliant, automated response.

Sources & References

  • • Black Kite: 2026 Europe Cyber Risk Report - blackkite.com (Third-Party Risk, Regulatory Accountability, Next Steps)
  • • European Commission: NIS2 Directive & transposition status - digital-strategy.ec.europa.eu
  • • EUR-Lex: Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2557 (CER) - eur-lex.europa.eu
  • • FDPIC (Swiss Federal Data Protection and Information Commissioner): revised Swiss Data Protection Act (revDSG), Art. 24 - edoeb.admin.ch
  • • CMS: "Failure to report cyberattacks on critical infrastructure" (CH, ISG, CHF 100,000) - cms.law
  • • BleepingComputer: "Switzerland says government data stolen in ransomware attack" (Radix) - bleepingcomputer.com
  • • ENISA: situation report on the Collins Aerospace/MUSE disruption - enisa.europa.eu

Know your supply chain exposure before a lawyer does

RECON maps your attack surface continuously; NDR, DNS Shield and UEBA detect the attack even when it comes through a supplier. Swiss sovereignty, on-premises, compliant with the Swiss Data Protection Act.

Request a no-obligation consultation arrow_forward