CNI organisations are experiencing high levels of repeated supply chain compromise and credential theft, while almost four in 10 organisations only monitor supplier access after an incident 

AI SOC platform and service provider, e2e-assure, today unveiled new research revealing that Critical National Infrastructure (CNI) organisations are facing disproportionately high levels of supply chain compromise as attackers increasingly exploit trusted third-party access to gain entry into operational technology (OT) environments.

The research found that 76 per cent of CNI organisations report repeated supply chain compromise, while 75 per cent also cite repeated credential theft*, making them among the sectors most heavily targeted through trusted supplier relationships. Meanwhile, 54 per cent* of CNI organisations believe engineering workstations and historic servers are now among the systems most likely to be targeted, highlighting attackers’ growing focus on operational assets capable of disrupting critical services.

This growing reliance on third-party access is reflected across industry. The research found that over 40* per cent of organisations now provide remote OT access to 6 or more external suppliers or service providers, despite 39 per cent admitting they only review or monitor third-party access after a security incident has already occurred.

The findings indicate that organisations are creating significant blind spots around trusted third-party access. While remote vendor connections have become essential for maintaining industrial systems, many organisations continue to monitor those connections reactively rather than continuously, reducing their ability to detect suspicious activity before an incident occurs.

Dominic Carroll, Director of Portfolio & Marketing, e2e-assure, commented – “The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but attackers have adapted. They’re increasingly targeting legitimate remote access, compromised credentials and trusted third parties because they know these routes often receive far less scrutiny.

“The real concern is that almost four in ten organisations only review that access after something has gone wrong. In OT environments, by the time you’re investigating, the operational impact may already have occurred.”

This reactive stance is creating a massive backdoor into the UK’s critical systems. Mid-sized organisations (employing between 1,500 and 2,499 people) are feeling the brunt of this trend, with 21 per cent experiencing four or more supply chain-specific attacks in the last 12 months. Attackers are increasingly favouring trusted routes, exploiting vendor credentials to gain long-term, undetected exposure across OT environments.

Additionally, approximately 70 per cent* of organisations have integrated cloud-connected environments into their OT security strategies, increasing the number of potential third-party access pathways. Positively, 40 per cent of organisations have implemented dedicated third-party monitoring tools or agents for cloud assets.

Regardless, the findings point to a significant visibility gap, where organisations continue to trust external connections without continuously monitoring activity taking place across them. In industrial environments, where cyber incidents can translate directly into operational disruption, delayed detection can significantly increase both business and operational risk.

The research also highlights a growing security divide in the supply chain. While 68 per cent of large enterprises (employing between 5,000 and 10,000) are increasing their budgets for third-party risk management tools, nearly a third (32%) of smaller suppliers (employing between 250 and 499 people) expect their spending in this area to decrease. This leaves major contractors vulnerable to risks originating from their smaller, less-resilient partners.

As industrial organisations continue to digitise operations and rely on increasingly interconnected supply chains, governance expectations are also changing. Frameworks such as the Cyber Assessment Framework (CAF) and the forthcoming Cyber Security and Resilience Bill (CSRB) are placing greater emphasis on board-level accountability for cyber resilience, including oversight of third-party risk and supplier assurance. Despite this, 82 per cent of manufacturing organisations and 70 per cent of CNI organisations are not yet compliant with CSRB in particular.

Organisations should move beyond periodic supplier reviews and adopt continuous monitoring of all third-party access into operational environments. Combining real-time visibility, privileged access controls and managed detection and response enables organisations to identify suspicious behaviour before attackers are able to exploit trusted connections and move laterally across industrial networks.

Carroll concluded – “Supply chain resilience is no longer just about assessing suppliers once a year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected. Without that visibility, supplier access becomes one of the largest blind spots in industrial cybersecurity, and one of the simplest paths for attackers to exploit.”

https://e2e-assure.com/ 

Footnotes 

 (1) 1 to 4 or more security incidents combined

(2) “Much more likely to be targeted than before” and “Somewhat more likely to be targeted than before” answers combined.

(3) “6-10”, “11-20”, and “More than 20” answers combined.

(4) “Fully integrated, cloud activity is monitored alongside IT and/or OT” and “Largely integrated, cloud activity is monitored alongside IT and/or OT but there are gaps” answers combined.