As German retailers expand their digital ecosystems with SaaS providers and logistics partners, trusted third parties are increasingly becoming the weakest link in cybersecurity defenses. New data from ManageEngine reveals how supply chain attacks and vendor vulnerabilities threaten even well-protected businesses.
German retailers face a growing paradox: while investing heavily in cybersecurity, many remain exposed through the very partners they rely on to operate efficiently. According to a recent ManageEngine study, three-quarters of retailers experienced a cybersecurity incident in the past year, with third-party and supply chain attacks ranking among the most significant threats.
The Rising Threat of Third-Party Vulnerabilities
Retailers are under constant pressure from familiar attack vectors. Phishing and compromised credentials remain dominant, followed by exploitation of existing vulnerabilities and data leaks. Personal data — names, addresses, emails, and payment details — fuels sophisticated follow-on attacks like targeted phishing and identity fraud. The financial impact often surfaces long after the initial breach.
ManageEngine’s study on operational resilience in German companies highlights that 74.8% of surveyed businesses faced at least one cybersecurity incident in the past 12 months. In retail specifically, 75% reported incidents. Supply chain and third-party attacks accounted for a notable share, underscoring how interconnected digital ecosystems expand the attack surface.
“Even companies with strong internal IT security measures can be compromised through trusted third-party providers,” said Praveen Das, Technical Head at ManageEngine. As retailers integrate more SaaS solutions and logistics partners, every new connection potentially widens their exposure.
Response Gaps: Policy Over Technical Action
A striking finding is the mismatch between incidents and effective response. While most companies conduct structured post-incident analyses (94.7%), many prioritize regulatory compliance and internal policy updates over critical technical measures such as patch management, vulnerability remediation, and access rights reviews.
This approach limits real risk reduction. Retailers need continuous visibility into IT assets, digital identities, and third-party access to detect and contain threats before customer data is exposed. Although 75% of retail respondents recognize heavy dependence on IT systems for operations and security, only 58% feel confident in handling expected incidents over the next one to two years.
Teams struggle with too many manual processes, budget constraints, and fragmented tools — challenges exacerbated by skills gaps and alert fatigue.
Broader Context: German Companies Under Pressure
The study, which surveyed 302 German IT and security professionals, paints a wider picture. Key threats include phishing/social engineering (56%), malware/ransomware (35.4%), data breaches (35%), and supply chain attacks (32.7%). Impacts range from team-level disruptions to enterprise-wide outages.
On the positive side, German companies demonstrate discipline in post-incident processes and maintain solid backup strategies. However, board-level engagement in cybersecurity remains largely reactive, and long-term strategic transformation following incidents is inconsistent.
Looking ahead, AI-powered attacks top the list of future risks, followed by complex attack methods and human error. Investment priorities center on AI preparedness, staff training, and threat detection.
Path Forward: Stronger Third-Party Oversight
Cyber resilience now depends heavily on careful partner selection, rigorous vetting, and ongoing monitoring of third parties. Effective identity governance, comprehensive visibility into the operational environment, consistent vulnerability management, and strict third-party controls are essential.
Retailers that combine these elements will be better positioned to withstand evolving threats in an increasingly interconnected and AI-driven threat landscape.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de