Cybersecurity
Supply Chain Attacks in OT: The Vector That Bypasses the Physical Perimeter
Supply chain attacks are among the hardest to detect and prevent. In industrial OT, the supplier chain is often long, poorly monitored, and holds privileged access to control systems.

The Vendor Problem in OT: Privileged Access and Limited Control
A modern industrial plant depends on dozens of specialized vendors: the PLC manufacturer, the system integrator who designed the line, the SCADA software provider, the service provider for preventive maintenance, the consultant who performed the last upgrade. Each of these actors has had, has, or will have access to critical systems.
The characteristic that makes supply chain attacks particularly insidious in OT is this: the attacker does not need to overcome the target organization's defenses. They only need to compromise one of its vendors — which often has weaker defenses — and use it as a bridge.
The result is that perimeter security measures (firewalls, IDS, network segmentation) are useless against access that arrives through an authorized channel, used by a vendor with legitimate credentials, performing apparently normal operations.
How Attacks Work: From Compromised Firmware to Maintenance Software
Supply chain attacks in OT follow different patterns, often combined:
Compromised firmware: firmware for OT devices (PLCs, RTUs, industrial gateways) is typically provided by the manufacturer and installed during commissioning or updates. An attacker who compromises the manufacturer's firmware distribution process can deliver malicious software to end devices without ever directly accessing the plant.
Maintenance and engineering software: PLC programming tools, drive configuration software, SCADA platforms — these are often installed by vendor technicians on engineering machines and OT workstations. Compromising the update mechanism of these tools is an effective and hard-to-detect access vector.
Vendor remote access: automation vendors often maintain remote access to the systems they installed for support and maintenance. These access points, if not adequately controlled, are open doors. Compromising a vendor technician's account gives immediate access to all the customer plants that company serves.
Compromised hardware: in some cases documented by intelligence agencies, hardware has been modified before delivery — additional components added, firmware modified at the physical level. This is the hardest vector to detect and requires physical integrity checks.
Real Cases: What Has Happened
The SolarWinds attack, though primarily affecting IT environments, showed the possible scale of supply chain attacks: compromising a single software update reached thousands of organizations simultaneously.
In the OT world specifically, several incidents have originated in the supply chain. Attack campaigns such as Havex and BlackEnergy used compromised legitimate software to gain initial access to OT networks. Security researchers have documented industrial automation devices with preinstalled backdoors discovered after years of use.
The common pattern: initial access occurs through a trust channel — an update, an installation, a support remote access session. Once inside, the attacker moves slowly, without making noise, often waiting months before acting.
Supply Chain Risk Management: Frameworks and Practices
There is no solution that eliminates supply chain risk. The approach is to manage it through a combination of governance, technology, and monitoring.
Vendor inventory and classification: not all vendors have the same access level and therefore the same risk profile. A vendor with remote access to control systems is far more critical than a consumables supplier. The inventory must include: which systems they can access, how frequently, and with what type of access.
Due diligence on critical vendors: for vendors with privileged access to OT systems, evaluating their security posture should be part of the qualification process. This is not just a contractual matter — it means verifying that technician credentials are managed with MFA, that their internal systems are monitored, and that they have an incident response program.
Software and firmware integrity: verify cryptographic signatures of updates before installing them. Maintain a formal process for approving any software installed on OT systems. Do not install software from unofficial channels.
Vendor behavior monitoring: during and after every vendor intervention, monitor the activities performed. What was installed, what commands were executed, what network connections were opened. Anomalies from expected behavior for that type of intervention are signals to investigate.
Contracts, Audits, and Continuous Monitoring
Supply chain risk management in OT is not only technical — it also requires a contractual and governance framework.
Contracts with critical vendors should include: explicit cybersecurity requirements (MFA, credential management, incident notification), audit rights on the vendor's security posture, and immediate notification obligations in the event of a vendor system compromise.
Periodic auditing of critical vendors — verifying that contractual requirements are actually met — closes the governance loop. Requiring compliance is not sufficient; it must be verified.
Continuous network traffic monitoring during and after vendor interventions is the technical control that makes it possible to detect anomalous behavior even when preventive measures fail. A compromised vendor acting through their own legitimate access still leaves traces in network traffic — if you know what to look for.
The MON5 Angle
Monitoring vendor behavior during interventions requires a reference baseline: without knowing the plant's normal traffic, the anomalous activity of a compromised vendor goes unnoticed. MON5 builds this baseline in the PROTECT phase, with continuous monitoring and ML anomaly detection on OT traffic, passively and out-of-band, without touching production systems.
A maintenance session that opens unexpected connections or reaches systems outside its scope emerges as a deviation — even if the credentials used are legitimate. To understand where to start, consider an OT assessment that maps your vendors' access and traffic flows.
Related articles

Cybersecurity
Anomaly detection in OT: building the baseline and managing false positives
OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.
Cybersecurity
How Attackers Cross the IT-OT Boundary: Techniques and Detection Signals
The pivot from IT into the OT network is the critical phase of nearly every documented industrial attack. Understanding the techniques used to cross this boundary is the first step to detecting it early.
Cybersecurity
MITRE ATT&CK for ICS: How to Use It to Build Concrete Detection Rules
MITRE ATT&CK for ICS is not a document to skim once and file away. Turning its techniques into concrete detection rules means knowing what you can really see on your network and what stays out of reach without endpoint visibility.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.