Brian Sims
Editor

Over 70% of CNI organisations report “repeated supply chain compromise”

NEW RESEARCH conducted by e2e-assure reveals that Critical National Infrastructure (CNI) organisations are facing disproportionately high levels of supply chain compromise as attackers increasingly exploit trusted third party access to gain entry into operational technology (OT) environments.

The research finds that 76% of CNI organisations report repeated supply chain compromise, while 75% also cite repeated credential theft, making them among the sectors most heavily targeted through trusted supplier relationships.

Meanwhile, 54% of CNI organisations believe that engineering workstations and historic servers are now among the systems most likely to be targeted, highlighting attackers’ growing focus on operational assets that are capable of disrupting critical services.

This growing reliance on third party access is reflected across industry. The research suggests that over 40% of organisations now provide remote OT access to six or more external suppliers or service providers. That’s despite 39% of organisations surveyed admitting they only review or monitor third party access after a security incident has already occurred.

The findings indicate that organisations are creating significant blind spots around trusted third party access. While remote vendor connections have become essential for maintaining industrial systems, many organisations continue to monitor those connections reactively rather than continuously, reducing their ability to detect suspicious activity before an incident occurs.

Trusted supplier connections

Dominic Carroll, director of portfolio and marketing at e2e-assure, commented: “The easiest way into a critical environment is no longer breaking through the front door. It’s walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but the attackers have adapted. They’re increasingly targeting legitimate remote access, compromised credentials and trusted third parties as they know these routes often receive far less scrutiny.”

Carroll continued: “The real concern is that almost four in every ten organisations only review that access after something has gone wrong. In OT environments, by the time you're investigating, the operational impact may already have occurred.”

This reactive stance is creating a massive back door into the UK’s critical systems. Mid-sized organisations (ie those employing between 1,500 and 2,499 members of staff) are feeling the brunt of this trend, with 21% experiencing four or more supply chain-specific attacks in the last 12 months. Attackers are increasingly favouring trusted routes, exploiting vendor credentials to gain long-term and undetected exposure across OT environments.

In addition, approximately 70% of organisations have integrated cloud-connected environments into their OT security strategies, thereby increasing the number of potential third party access pathways. Positively, 40% of organisations have implemented dedicated third party monitoring tools or agents for cloud assets.

The study findings point to a significant visibility gap whereby organisations continue to trust external connections without continuously monitoring activity taking place across them. In industrial environments, where cyber incidents can translate directly into operational disruption, delayed detection can significantly increase both business and operational risk.

Security divide

The research also highlights a growing security divide in the supply chain. While 68% of large enterprises (ie those employing between 5,000 and 10,000 members of staff) are increasing their budgets for third party risk management tools, nearly one-third (32%) of smaller suppliers (employing between 250 and 499 people) expect their spending in this area to decrease. This leaves major contractors somewhat vulnerable to risks originating from their smaller and less-resilient business partners.

As industrial organisations continue to digitise operations and rely on increasingly interconnected supply chains, governance expectations are also changing. Frameworks such as the Cyber Assessment Framework and the Cyber Security and Resilience Bill are placing greater emphasis on Board-level accountability for cyber resilience, including oversight of third party risk and supplier assurance. Despite this, 82& of manufacturing organisations and 70% of CNI organisations are not yet compliant with CSRB in particular.

Organisations should move beyond periodic supplier reviews and adopt continuous monitoring of all third party access into operational environments. Combining real-time visibility, privileged access controls and managed detection and response enables organisations to identify suspicious behaviour before attackers are able to exploit trusted connections and then move laterally across industrial networks.

Dominic Carroll concluded: “Supply chain resilience is no longer just about assessing suppliers once every year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected. Without that visibility, supplier access becomes one of the largest blind spots in industrial cyber security and one of the simplest paths for attackers to exploit.”

*Further information is available online at www.e2e-assure.com

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up