AI SOC platform and service provider, e2e-assure, today unveiled new research revealing that Critical National Infrastructure (CNI) organisations are facing disproportionately high levels of supply chain compromise as attackers increasingly exploit trusted third-party access to gain entry into operational technology (OT) environments.
The research found that 76 per cent of CNI organisations report repeated supply chain compromise, while 75 per cent also cite repeated credential theft , making them among the sectors most heavily targeted through trusted supplier relationships. Meanwhile, 54 per cent of CNI organisations believe engineering workstations and historian servers are now among the systems most likely to be targeted, highlighting attackers' growing focus on operational assets capable of disrupting critical services.
This growing reliance on third-party access is reflected across industry. The research found that over 40 per cent of organisations now provide remote OT access to 6 or more external suppliers or service providers, despite 39 per cent admitting they only review or monitor third-party access after a security incident has already occurred.
The findings indicate that organisations are creating significant blind spots around trusted third-party access. While remote vendor connections have become essential for maintaining industrial systems, many organisations continue to monitor those connections reactively rather than continuously, reducing their ability to detect suspicious activity before an incident occurs.
Dominic Carroll, Director of Portfolio & Marketing, e2e-assure, commented - "The easiest way into a critical environment is no longer breaking through the front door; it's walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but attackers have adapted. They're increasingly targeting legitimate remote access, compromised credentials and trusted third parties because they know these routes often receive far less scrutiny.
"The real concern is that almost four in ten organisations only review that access after something has gone wrong. In OT environments, by the time you're investigating, the operational impact may already have occurred."
This reactive stance is creating a massive backdoor into the UK's critical systems. Mid-sized organisations (employing between 1,500 and 2,499 people) are feeling the brunt of this trend, with 21 per cent experiencing four or more supply chain-specific attacks in the last 12 months. Attackers are increasingly favouring trusted routes, exploiting vendor credentials to gain long-term, undetected exposure across OT environments.
Additionally, approximately 70 per cent of organisations have integrated cloud-connected environments into their OT security strategies, increasing the number of potential third-party access pathways. Positively, 40 per cent of organisations have implemented dedicated third-party monitoring tools or agents for cloud assets.
Regardless, the findings point to a significant visibility gap, where organisations continue to trust external connections without continuously monitoring activity taking place across them. In industrial environments, where cyber incidents can translate directly into operational disruption, delayed detection can significantly increase both business and operational risk.
The research also highlights a growing security divide in the supply chain. While 68 per cent of large enterprises (employing between 5,000 and 10,000) are increasing their budgets for third-party risk management tools, nearly a third (32%) of smaller suppliers (employing between 250 and 499 people) expect their spending in this area to decrease. This leaves major contractors vulnerable to risks originating from their smaller, less-resilient partners.
As industrial organisations continue to digitise operations and rely on increasingly interconnected supply chains, governance expectations are also changing. Frameworks such as the Cyber Assessment Framework (CAF) and the forthcoming Cyber Security and Resilience Bill (CSRB) are placing greater emphasis on board-level accountability for cyber resilience, including oversight of third-party risk and supplier assurance. Despite this, 82 per cent of manufacturing organisations and 70 per cent of CNI organisations are not yet compliant with CSRB in particular.
Organisations should move beyond periodic supplier reviews and adopt continuous monitoring of all third-party access into operational environments. Combining real-time visibility, privileged access controls and managed detection and response enables organisations to identify suspicious behaviour before attackers are able to exploit trusted connections and move laterally across industrial networks.
Carroll concluded - "Supply chain resilience is no longer just about assessing suppliers once a year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected. Without that visibility, supplier access becomes one of the largest blind spots in industrial cybersecurity, and one of the simplest paths for attackers to exploit."
About e2e-assure
e2e-assure is the UK’s only 100% sovereign AI-native SOC platform and managed service with IT and OT connectivity.
Cumulo, e2e-assure’s AI native SOC platform, uses over 22 analyst agents managed by SC-cleared expert human analysts, and connects with over 50 different security tools. Providing an agile human-in-the-loop managed service that can detect and respond to zero-day threats across both IT and OT environments.
Trusted for over 13 years with e2e-assure’s UK data sovereignty guarantee, government and CNI organisations have confidence in their reduced business and cyber risk; evidenced by the companies NPS score of 88+.
Methodology
The research was conducted by Censuswide, among a sample of 250 Cybersecurity DMs in businesses with 250-10,000 employees across the following industries: Food manufacturing, Discrete manufacturing, Critical National Infrastructure, Automotive manufacturing, Aerospace, Energy & Renewables, Utilities, Transport and Logistics, Retail (e-commerce, supermarkets, department stores, electronics, health & beauty etc), Pharmaceutical Manufacturing, Medical manufacturing, Electronic manufacturing, Chemical manufacturing, Metal Manufacturing, Telecomms, Central government, Local government, Defence, and Life Sciences. The data was collected between 05.01.2026 - 09.01.2026. Censuswide abides by and employs members of the Market Research Society and follows the MRS code of conduct and ESOMAR principles. Censuswide is also a member of the British Polling Council.