Over three-quarters of CNI organisations report repeated supply chain compromise, e2e-assure research reveals

Image credit: Photo of Dom Carroll supplied courtesy of e2e-assure

Editorial Brief
At a glance: AI-assisted overview, optimised for journalists, search & news aggregators

Research by e2e-assure reveals that 76% of Critical National Infrastructure (CNI) organisations have experienced repeated supply chain compromises, with attackers exploiting trusted third-party access to target operational technology environments. This highlights a significant security risk, as many organisations only monitor third-party access reactively, leaving them vulnerable to attacks. The findings stress the need for continuous monitoring of third-party access to enhance cybersecurity and prevent operational disruptions.

EDITORIAL INSIGHT: Context, industry insight and market perspectives of this news story

As cyber threats continue to evolve, supply chain vulnerabilities have emerged as a critical concern for operators of essential services. The latest research from e2e-assure highlights the extent to which attackers are leveraging trusted third-party relationships to breach critical national infrastructure, a trend that is placing mounting pressure on organisations to rethink how they manage and monitor external access to operational technology environments.

For businesses responsible for maintaining vital infrastructure, the findings point to a growing disconnect between the need for remote supplier access and the ability to oversee it effectively. With regulatory scrutiny increasing and the operational risks of cyber incidents rising, organisations face a pressing challenge to move from reactive to proactive management of third-party connections. The research also underscores the importance of continuous monitoring and investment in third-party risk management, especially as digital transformation and cloud integration expand the attack surface across industrial sectors.

This issue has gained added urgency with the introduction of new frameworks and impending legislation, such as the Cyber Security and Resilience Bill, which demand higher standards of governance and board-level accountability for supply chain risk. As compliance expectations rise, organisations that delay improvements to their monitoring and assurance processes may find themselves exposed not only to cyber threats but also to regulatory penalties and reputational harm.

Press Release

Abingdon, U.K., 29 July 2026

AI SOC platform and service provider, e2e-assure, today unveiled new research revealing that Critical National Infrastructure (CNI) organisations are facing disproportionately high levels of supply chain compromise as attackers increasingly exploit trusted third-party access to gain entry into operational technology (OT) environments.

The research found that 76 per cent of CNI organisations report repeated supply chain compromise, while 75 per cent also cite repeated credential theft[1], making them among the sectors most heavily targeted through trusted supplier relationships. Meanwhile, 54 per cent[2] of CNI organisations believe engineering workstations and historian servers are now among the systems most likely to be targeted, highlighting attackers’ growing focus on operational assets capable of disrupting critical services.

This growing reliance on third-party access is reflected across industry. The research found that over 40[3] per cent of organisations now provide remote OT access to 6 or more external suppliers or service providers, despite 39 per cent admitting they only review or monitor third-party access after a security incident has already occurred.

The findings indicate that organisations are creating significant blind spots around trusted third-party access. While remote vendor connections have become essential for maintaining industrial systems, many organisations continue to monitor those connections reactively rather than continuously, reducing their ability to detect suspicious activity before an incident occurs.

Dominic Carroll, Director of Portfolio & Marketing, e2e-assure, commented – “The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection. Organisations have invested heavily in perimeter security, but attackers have adapted. They’re increasingly targeting legitimate remote access, compromised credentials and trusted third parties because they know these routes often receive far less scrutiny.

“The real concern is that almost four in ten organisations only review that access after something has gone wrong. In OT environments, by the time you’re investigating, the operational impact may already have occurred.”

This reactive stance is creating a massive backdoor into the UK’s critical systems. Mid-sized organisations (employing between 1,500 and 2,499 people) are feeling the brunt of this trend, with 21 per cent experiencing four or more supply chain-specific attacks in the last 12 months. Attackers are increasingly favouring trusted routes, exploiting vendor credentials to gain long-term, undetected exposure across OT environments.

Additionally, approximately 70 per cent[4] of organisations have integrated cloud-connected environments into their OT security strategies, increasing the number of potential third-party access pathways. Positively, 40 per cent of organisations have implemented dedicated third-party monitoring tools or agents for cloud assets.

Regardless, the findings point to a significant visibility gap, where organisations continue to trust external connections without continuously monitoring activity taking place across them. In industrial environments, where cyber incidents can translate directly into operational disruption, delayed detection can significantly increase both business and operational risk.

The research also highlights a growing security divide in the supply chain. While 68 per cent of large enterprises (employing between 5,000 and 10,000) are increasing their budgets for third-party risk management tools, nearly a third (32%) of smaller suppliers (employing between 250 and 499 people) expect their spending in this area to decrease. This leaves major contractors vulnerable to risks originating from their smaller, less-resilient partners.

As industrial organisations continue to digitise operations and rely on increasingly interconnected supply chains, governance expectations are also changing. Frameworks such as the Cyber Assessment Framework (CAF) and the forthcoming Cyber Security and Resilience Bill (CSRB) are placing greater emphasis on board-level accountability for cyber resilience, including oversight of third-party risk and supplier assurance. Despite this, 82 per cent of manufacturing organisations and 70 per cent of CNI organisations are not yet compliant with CSRB in particular.

Organisations should move beyond periodic supplier reviews and adopt continuous monitoring of all third-party access into operational environments. Combining real-time visibility, privileged access controls and managed detection and response enables organisations to identify suspicious behaviour before attackers are able to exploit trusted connections and move laterally across industrial networks.

Carroll concluded – “Supply chain resilience is no longer just about assessing suppliers once a year or ensuring contracts include security policies. Organisations need continuous assurance that every trusted connection is behaving as expected. Without that visibility, supplier access becomes one of the largest blind spots in industrial cybersecurity, and one of the simplest paths for attackers to exploit.”

Notes to editors

Methodology

The research was conducted by Censuswide, among a sample of 250 Cybersecurity DMs in businesses with 250-10,000 employees across the following industries: Food manufacturing, Discrete manufacturing, Critical National Infrastructure, Automotive manufacturing, Aerospace, Energy & Renewables, Utilities, Transport and Logistics, Retail (e-commerce, supermarkets, department stores, electronics, health & beauty etc), Pharmaceutical Manufacturing, Medical manufacturing, Electronic manufacturing, Chemical manufacturing, Metal Manufacturing, Telecomms, Central government, Local government, Defence, and Life Sciences. The data was collected between 05.01.2026 – 09.01.2026. Censuswide abides by and employs members of the Market Research Society and follows the MRS code of conduct and ESOMAR principles. Censuswide is also a member of the British Polling Council.

Footnotes

  1. 1 to 4 or more security incidents combined.
  2. “Much more likely to be targeted than before” and “Somewhat more likely to be targeted than before” answers combined.
  3. “6-10”, “11-20”, and “More than 20” answers combined.
  4. “Fully integrated, cloud activity is monitored alongside IT and/or OT” and “Largely integrated, cloud activity is monitored alongside IT and/or OT but there are gaps” answers combined.

About e2e-assure

e2e-assure is the UK’s only 100% sovereign AI-native SOC platform and managed service with IT and OT connectivity.

Cumulo, e2e-assure’s AI native SOC platform, uses over 22 analyst agents managed by SC-cleared expert human analysts, and connects with over 50 different security tools. Providing an agile human-in-the-loop managed service that can detect and respond to zero-day threats across both IT and OT environments.

Trusted for over 13 years with e2e-assure’s UK data sovereignty guarantee, government and CNI organisations have confidence in their reduced business and cyber risk; evidenced by the companies NPS score of 88+.

Get more news like this

Get more news like this on Google. Set News By Wire as a ‘Preferred News Source’ to get quicker access to news that’s important.

All done!
Thank you for subscribing.

Email Subscription