CNI firms report repeated supplier breaches, study finds
Wed, 29th Jul 2026 (Today)
e2e-assure has published research showing that 76 per cent of Critical National Infrastructure organisations report repeated supply chain compromise, while 75 per cent report repeated credential theft.
The findings point to sustained pressure on operators of critical services as attackers use trusted third-party access routes to reach operational technology environments. More than half of the CNI organisations surveyed said engineering workstations and legacy servers are now among the systems most likely to be targeted.
That focus on operational assets comes as remote supplier access becomes more common in industrial settings. More than 40 per cent of organisations now provide remote OT access to six or more external suppliers or service providers.
At the same time, 39 per cent said they review or monitor third-party access only after a security incident has taken place, suggesting many still rely on reactive oversight rather than continuous scrutiny.
Trusted routes
Dominic Carroll, Director of Portfolio & Marketing at e2e-assure, said attackers are increasingly exploiting accepted access channels instead of attempting direct intrusion.
"The easiest way into a critical environment is no longer breaking through the front door; it's walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but attackers have adapted. They're increasingly targeting legitimate remote access, compromised credentials and trusted third parties because they know these routes often receive far less scrutiny. The real concern is that almost four in ten organisations only review that access after something has gone wrong. In OT environments, by the time you're investigating, the operational impact may already have occurred," Carroll said.
The data also indicates that medium-sized organisations account for a notable share of these incidents. Among businesses employing between 1,500 and 2,499 people, 21 per cent reported four or more supply chain-specific attacks in the past 12 months.
Researchers also found that about 70 per cent of organisations have integrated cloud-connected environments into their OT security strategies, increasing the number of possible access paths for suppliers and service providers into industrial systems.
Some organisations are adding more direct oversight. Forty per cent have implemented dedicated third-party monitoring tools or agents for cloud assets, though the overall picture still points to uneven visibility across supplier connections.
Budget divide
The research highlights a widening spending gap between larger enterprises and smaller suppliers. While 68 per cent of businesses employing between 5,000 and 10,000 people are increasing budgets for third-party risk management tools, 32 per cent of suppliers with 250 to 499 employees expect spending in that area to fall.
That contrast may leave larger contractors exposed to weaknesses elsewhere in their supply chains, particularly where smaller partners have fewer resources to monitor access or respond to threats. In sectors that depend on interconnected industrial systems, supplier weaknesses can create openings far beyond a single company.
The report also examined preparedness for changing governance requirements, finding that 82 per cent of manufacturing organisations and 70 per cent of CNI organisations are not yet compliant with the Cyber Security and Resilience Bill.
Board-level accountability for cyber resilience and supplier assurance is becoming more prominent in policy and regulation, especially in sectors tied to essential services. That is increasing attention on how organisations track external access into OT environments and how quickly they can detect misuse of legitimate credentials.
e2e-assure's survey was conducted by Censuswide among 250 cybersecurity decision-makers at organisations with 250 to 10,000 employees across sectors including Critical National Infrastructure, manufacturing, energy, utilities, transport, telecoms, defence and government.
Carroll said organisations need to change how they oversee supplier risk in industrial networks.
"Supply chain resilience is no longer just about assessing suppliers once a year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected. Without that visibility, supplier access becomes one of the largest blind spots in industrial cybersecurity, and one of the simplest paths for attackers to exploit," Carroll said.