Trusted supplier access drives repeated CNI breaches

Trusted supplier connections are driving repeated compromise across critical infrastructure. New research identifies stolen credentials, remote vendor access, ageing operational assets, and reactive monitoring as persistent weaknesses across industrial supply chains.


IN Brief:

  • Seventy six per cent of CNI respondents reported repeated supply chain compromise.
  • More than 40% of organisations give at least six external suppliers remote OT access.
  • Thirty nine per cent review or monitor third party access only after a security incident.

e2e-assure has found that 76% of critical national infrastructure respondents have experienced repeated supply chain compromise as attackers increasingly use trusted supplier connections to enter operational technology environments.

Repeated credential theft was reported by 75% of CNI respondents, while 54% said engineering workstations and historian servers were among the assets becoming more likely to be targeted.

More than 40% of the organisations surveyed provide remote OT access to at least six suppliers or service providers. Despite the number of external connections, 39% review or monitor third party access only after a security incident has occurred.

The study was conducted by Censuswide among 250 cyber security decision makers working in companies and public bodies with between 250 and 10,000 employees. Fieldwork took place from 5 to 9 January 2026.

Respondents represented food and discrete manufacturing, critical infrastructure, automotive, aerospace, energy, utilities, transport and logistics, retail, pharmaceuticals, medical manufacturing, electronics, chemicals, metals, telecommunications, government, defence, and life sciences.

Mid sized organisations employing between 1,500 and 2,499 people recorded a particularly high frequency of attacks, with 21% experiencing at least four supply chain specific incidents during the previous 12 months.

Cloud connectivity is adding further access routes into operational environments. Approximately 70% of respondents have incorporated cloud connected systems into their OT security strategy, while 40% have deployed dedicated third party monitoring tools or agents for cloud assets.

Dominic Carroll, Director of Portfolio and Marketing at e2e-assure, said: “The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection.”

He added that attackers are increasingly targeting legitimate remote access, compromised credentials, and trusted third parties because those routes frequently receive less scrutiny than the organisation’s external perimeter.

Carroll said: “The real concern is that almost four in ten organisations only review that access after something has gone wrong. In OT environments, by the time you’re investigating, the operational impact may already have occurred.”

Remote maintenance requires continuous control

External connections are embedded throughout industrial operations. Equipment manufacturers, systems integrators, maintenance contractors, software providers, and specialist engineers use them to diagnose faults, update systems, and support assets without sending staff to site.

Removing access entirely can increase downtime and maintenance cost, while leaving it permanently available without detailed oversight creates an approved route into sensitive systems. Stolen supplier credentials can appear legitimate because the attacker uses the same account and remote tool as an authorised engineer.

Monitoring must therefore examine behaviour after login, including the time of access, systems reached, commands used, data transferred, and attempts to move into other parts of the network. Authentication alone cannot establish whether an approved account is being used for an approved purpose.

Engineering workstations and historian servers add particular exposure because they can contain configurations, production data, and direct or indirect links to operational systems. Many run older software or cannot be patched easily without interrupting the plant or service they support.

e2e-assure’s Cumulo platform was developed to connect IT and OT monitoring through human supervised AI. Its combination of analyst agents and operational security oversight reflects the growing requirement to analyse activity across environments that were previously managed separately.

The survey also identifies a widening spending divide. Sixty eight per cent of organisations employing between 5,000 and 10,000 people are increasing budgets for third party risk tools, while 32% of suppliers with 250 to 499 employees expect expenditure in the area to decline.

A large operator can consequently strengthen its own monitoring while remaining exposed through contractors with fewer resources. Contractual requirements offer limited protection when suppliers lack the staff, systems, or commercial capacity needed to comply consistently.

Cyber pressure across industrial operations has become closely connected to production continuity and physical service delivery. Increasing attacks on industrial environments can affect availability, quality, safety, and the movement of goods long before an organisation has completed its technical investigation.

Governance expectations are also increasing through the Cyber Assessment Framework and the forthcoming Cyber Security and Resilience Bill. The research found that 82% of manufacturing respondents and 70% of CNI respondents were not yet compliant with the anticipated CSRB requirements.

Supplier assurance must extend beyond annual questionnaires. Organisations need an accurate inventory of external connections, named owners, approved access windows, privileged controls, session records, rapid credential revocation, and alerts when activity moves beyond the authorised task.

Periodic assessment can establish whether a supplier had suitable controls at a particular point, but continuous monitoring covers the months in which credentials, personnel, systems, and attacker behaviour change. As remote maintenance becomes more deeply integrated with industrial operations, supplier access must be controlled with the same discipline as the operational assets it can reach.


Stories for you


  • Trusted supplier access drives repeated CNI breaches

    Trusted supplier access drives repeated CNI breaches

    Trusted supplier connections are driving repeated compromise across critical infrastructure. New research identifies stolen credentials, remote vendor access, ageing operational assets, and reactive monitoring as persistent weaknesses across industrial supply chains.


  • CILT urges logistics priority in new skills pathway

    CILT urges logistics priority in new skills pathway

    CILT wants logistics placed inside Britain’s new skills growth pathway. The institute supports earlier work experience and vocational learning but is seeking national coordination, flexible funding, and stronger recognition for transport and freight.