More than three quarters of critical national infrastructure organisations have experienced repeated supply chain compromise, according to research from e2e-assure, as attackers increasingly use trusted supplier access and stolen credentials to enter operational technology.
The study found that 76% of CNI organisations reported repeated supply chain compromise, while 75% experienced repeated credential theft. Engineering workstations and historic servers were identified by 54% as systems increasingly likely to be targeted.
More than 40% of organisations now provide remote operational technology access to six or more suppliers or service providers. Despite the number of external connections, 39% said third party access was reviewed or monitored only after a security incident.
Remote support has become an established part of industrial maintenance, allowing equipment manufacturers, control specialists, software providers, and engineering contractors to diagnose faults, update systems, tune processes, and support sites without permanent specialist staff.
Those connections reduce travel and can shorten downtime, but they also create an authenticated route towards systems responsible for physical operations. An attacker holding a legitimate supplier account may not need to defeat the operator’s external perimeter directly.
Dominic Carroll, Director of Portfolio and Marketing at e2e-assure, said: “The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection.”
Credential misuse can be difficult to distinguish from normal engineering activity where monitoring lacks operational context. A valid account connecting through an approved service may initially appear legitimate even when the user, device, location, timing, or actions are abnormal.
Engineering workstations provide particularly valuable access because they can contain configuration software, project files, network information, passwords, and privileged routes to controllers or supervisory systems. Historic servers may remain connected because they support equipment that cannot readily be upgraded or replaced.
Legacy systems frequently have limited logging, unsupported operating systems, hard coded dependencies, and applications that respond poorly to conventional security software. Operators may avoid changes where an outage could interrupt power, water, transport, manufacturing, healthcare, or communications.
The research found that 21% of organisations employing between 1,500 and 2,499 people had experienced at least four supply chain attacks during the previous 12 months. Mid sized operators may combine substantial connectivity and industrial complexity without the security staffing available to larger enterprises.
Cloud integration is widening the number of possible access routes, with around 70% of organisations incorporating cloud connected environments into their operational security strategies. Forty per cent have deployed dedicated third party monitoring tools or agents for cloud assets.
Cloud platforms can centralise analytics, maintenance, and management across distributed operations, while connecting identity services, remote support tools, industrial data, and supplier systems across organisational boundaries. Access governance and event correlation become more difficult as those dependencies grow.
Security budgets also vary considerably through the supply chain. Sixty eight per cent of large organisations employing between 5,000 and 10,000 people are increasing expenditure on third party risk tools, while 32% of suppliers with 250 to 499 employees expect spending to fall.
A major operator can impose contractual requirements and request annual evidence, but protection of an essential function still depends on smaller partners maintaining their identities, devices, remote tools, and monitoring throughout the contract.
Annual questionnaires provide only a snapshot, since supplier personnel change, permissions accumulate, software is updated, companies are acquired, and subcontractors enter delivery arrangements between formal assessments.
Continuous assurance requires an accurate inventory of third party connections, named ownership, time limited permissions, strong authentication, session logging, and rapid removal when access is no longer required. Privileged sessions may also be restricted to approved assets, commands, and working periods.
The Cyber Security and Resilience Bill will extend the UK’s Network and Information Systems regime to additional digital infrastructure, managed service providers, data centres, large load controllers, and designated critical suppliers.
The National Cyber Security Centre’s Cyber Assessment Framework states that organisations remain accountable for essential functions when external technologies and services are used. Its supply chain principle calls for visibility of third party connections, contractual security obligations, and confidence that dependencies are being managed.
The Cumulo sovereign IT and OT security operations platform combines event monitoring across corporate and industrial environments, addressing attacks that move through identity, cloud services, remote access, and engineering systems rather than remaining within one network layer.
The research found that 82% of manufacturing organisations and 70% of CNI organisations were not yet compliant with the forthcoming legislation. Final duties will depend on regulatory scope, but supplier oversight is moving beyond procurement assessment into continuous operational control.
Remote support will remain necessary for complex industrial equipment, particularly where faults require knowledge held by the original manufacturer or specialist integrator. Each connection must be visible, limited, attributable, monitored, and capable of being disabled without waiting for an incident investigation.
Carroll added: “Supply chain resilience is no longer just about assessing suppliers once a year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected.”



