Key Takeaways
- In 2023, 15% of payment card data breaches involved supply chain compromises
- Supply chain attacks accounted for 25% of all PCI-related incidents in 2022
- 40% of PCI DSS non-compliant entities were due to third-party supply chain failures in 2021
- 9% PCI compliance rate drop due to supply chain audits in 2022 surveys
- Only 57% of payment processors have full supply chain PCI DSS compliance 2023
- 72% of merchants fail supply chain vendor assessments per PCI SSC 2022
- Average cost of PCI supply chain breach: $4.45 million in 2023
- Supply chain PCI incidents cost 20% more than direct breaches 2023
- $9.44 million average mega-breach cost involving PCI supply chain 2023
- 60% of third-party vendors pose PCI supply chain risks per surveys 2023
- 83% of payment firms use 100+ supply chain vendors 2023
- Only 42% of PCI vendors undergo regular security audits 2022
- Adoption of SBOMs in PCI supply chain vendors: 22% in 2023
- 67% of PCI orgs implemented supply chain risk management platforms 2023
- Zero-trust adoption in PCI supply chains: 39% in 2023
Supply chain attacks are now a major source of payment card industry data breaches.
Breach Incidents
Breach Incidents Interpretation
Compliance Rates
Compliance Rates Interpretation
Cost Statistics
Cost Statistics Interpretation
Mitigation Strategies
Mitigation Strategies Interpretation
Vendor Risks
Vendor Risks Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2IBMibm.comVisit source
- Reference 3PCICOMPLIANCEGUIDEpcicomplianceguide.orgVisit source
- Reference 4RISKIQriskiq.comVisit source
- Reference 5FIREEYEfireeye.comVisit source
- Reference 6MANDIANTmandiant.comVisit source
- Reference 7REUTERSreuters.comVisit source
- Reference 8OKTAokta.comVisit source
- Reference 9HEALTHCAREDIVEhealthcaredive.comVisit source
- Reference 10AKAMAIakamai.comVisit source
- Reference 11PONEMONponemon.orgVisit source
- Reference 12PROGRESSprogress.comVisit source
- Reference 13SYNOPSYSsynopsys.comVisit source
- Reference 14BLOGblog.pcisecuritystandards.orgVisit source
- Reference 15SECURITYWEEKsecurityweek.comVisit source
- Reference 16PCISECURITYSTANDARDSpcisecuritystandards.orgVisit source
- Reference 17VISAvisa.comVisit source
- Reference 18DELOITTEwww2.deloitte.comVisit source
- Reference 19MASTERCARDmastercard.comVisit source
- Reference 20ITGOVERNANCEitgovernance.co.ukVisit source
- Reference 21AMERICANBANKERamericanbanker.comVisit source
- Reference 22PAYPALOBJECTSpaypalobjects.comVisit source
- Reference 23ENISAenisa.europa.euVisit source
- Reference 24NISTnist.govVisit source
- Reference 25GARTNERgartner.comVisit source
- Reference 26MARSHmarsh.comVisit source
- Reference 27SECURITYMETRICSsecuritymetrics.comVisit source
- Reference 28ALLIANZallianz.comVisit source
- Reference 29KREBSONSECURITYkrebsonsecurity.comVisit source
- Reference 30IDCidc.comVisit source
- Reference 31MCKINSEYmckinsey.comVisit source
- Reference 32PWCpwc.comVisit source
- Reference 33ACCENTUREaccenture.comVisit source
- Reference 34FORRESTERforrester.comVisit source
- Reference 35CROWDSTRIKEcrowdstrike.comVisit source
- Reference 36ZSCALERzscaler.comVisit source
- Reference 37MICROSOFTmicrosoft.comVisit source
- Reference 38NETSKOPEnetskope.comVisit source
- Reference 39BCGbcg.comVisit source
- Reference 40TENABLEtenable.comVisit source
- Reference 41FS-ISACfs-isac.orgVisit source






