Summary
- e2e-assure says 76% of CNI organisations report repeated supply chain compromise and 75% report repeated credential theft.
- More than 40% of organisations provide remote OT access to six or more external suppliers or service providers, according to the research.
- The findings point to a visibility gap around trusted access into operational environments, where delayed detection can become service disruption.
e2e-assure research indicates that UK critical national infrastructure organisations are experiencing high levels of repeated supply chain compromise and credential theft as attackers exploit trusted third party access into operational technology environments.
The company says 76% of CNI organisations report repeated supply chain compromise, while 75% report repeated credential theft. Its research also found that 54% of CNI organisations believe engineering workstations and historian servers are now among the systems most likely to be targeted, putting attacker attention closer to operational assets that can affect service continuity.
The exposure is tied to remote access. According to the research, more than 40% of organisations now provide remote OT access to six or more external suppliers or service providers. At the same time, 39% admit they only review or monitor third party access after a security incident has occurred.
Remote vendor connections are often necessary for maintenance, diagnostics, upgrades, and specialist support. They also create trusted paths into networks that may have been designed before continuous supplier access was normal. When credentials are compromised or supplier systems are misused, attackers can move through access channels that defenders may initially treat as legitimate activity.
Dominic Carroll, director of portfolio and marketing at e2e-assure, said: “The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but attackers have adapted. They’re increasingly targeting legitimate remote access, compromised credentials and trusted third parties because they know these routes often receive far less scrutiny.”
The findings arrive as UK cyber policy moves toward more explicit oversight of critical suppliers. The Cyber Security and Resilience Bill factsheets describe plans to designate critical suppliers and require them to meet statutory cyber security requirements where their services create serious risk to essential services. The NCSC’s Cyber Assessment Framework gives organisations a structured method for assessing whether risks to essential functions are being managed effectively.
The research also describes a budget divide across the supply chain. e2e-assure says 68% of large enterprises with 5,000 to 10,000 employees are increasing budgets for third-party risk management tools, while 32% of smaller suppliers with 250 to 499 employees expect spending in this area to decrease. That mismatch puts larger operators under pressure to understand the resilience of smaller partners that provide specialised maintenance, engineering, and support.
Cloud connectivity adds further complexity. Around 70% of organisations have integrated cloud-connected environments into OT security strategies, increasing the number of supplier access paths into industrial settings. While 40% have implemented dedicated third party monitoring tools or agents for cloud assets, the findings suggest that trusted access is still often reviewed after problems have already occurred.
Industrial operators need continuous visibility of which suppliers can connect, what credentials and privileges they use, which systems they can reach, and whether their activity is normal. Privileged access controls, session recording, behavioural monitoring, just-in-time access, and managed detection can reduce the chance that a legitimate supplier connection becomes an unnoticed route into essential operations.




