Creating manufacturing facilities, power plants, processing plants, or other production facilities requires a substantial amount of manpower to bring them into operation. To accomplish this, third-party contractors are often utilized to handle various tasks and maintain specific portions of the operations. Some of this equipment may come with the capability for remote management, allowing for easier access by a third party. This leads to another path in which a threat actor could compromise the system.

As these facilities grow in complexity, it becomes more common to rely on external vendors not just for installation and maintenance, but also for ongoing monitoring, software updates, and remote troubleshooting. These third parties often have legitimate reasons for needing access, but that access also introduces a layer of risk. If a vendor’s system is compromised or if access is misconfigured, it can open a direct path into critical parts of the network.

In many cases, the systems these vendors interact with are not reviewed regularly from a security standpoint. They may operate on separate networks or use outdated software, making them vulnerable to exploitation. Without proper controls in place, what starts as a convenience for maintenance can quickly become an entry point for attackers. This risk must be considered when designing, deploying, and managing any operational environment that relies on third-party involvement.

Third Party/Supply Chain Compromise

Below are a few real-world examples of third-party and supply chain attacks, highlighting why this is a serious threat that demands attention.

  • SolarWinds Supply Chain Attack (2020):
    A threat actor compromised SolarWinds, a vendor that provides IT monitoring tools and services. The attackers inserted malicious code into Orion software updates, which were then distributed to thousands of clients, including U.S. government agencies and Fortune 500 companies.
    Although this example isn’t specific to an OT environment, it highlights how a compromise of trusted software could easily spread into production systems. A similar technique could be used to target OT infrastructure directly.
  • Target HVAC Vendor Breach (2013):
    Attackers gained access to Target’s network by compromising credentials from an HVAC contractor that had remote access to the retailer’s building systems. From there, they pivoted into the payment processing network, ultimately stealing data from over 40 million credit cards.
    This attack shows how remote access given to third-party vendors, even for facility management, can become an unexpected point of entry when proper segmentation and access controls are lacking.
  • CrowdStrike Faulty Update Outage (2024):
    On 19 July 2024, CrowdStrike released a faulty configuration update for its Falcon Sensor on Windows hosts. The update contained a defective “Channel File 291” template instance that passed internal validation despite triggering a logic flaw (out-of-bounds memory read). Thousands to millions of Windows endpoints experienced crashes, boot failures, or became unusable until the update was revoked, causing disruptions across airlines, hospitals, broadcasters, banks, emergency services, and other organizations. This incident wasn’t the result of a malicious actor, but it shows how a trusted vendor’s update pipeline can create a large-scale outage.

These examples show that third-party and supply chain risks are very real and have already caused serious issues in the past. Whether it’s through a compromised software update, a vendor’s remote access, or the continued use of obsolete hardware and software, attackers often look for the path of least resistance.

In many OT environments, older systems and software remain in place because they were designed with specific versions in mind and upgrading them could risk disrupting operations. While sometimes unavoidable, this creates a common attack path that threat actors frequently exploit, especially when known vulnerabilities remain unpatched or unsupported.

This is why it’s so important to take these risks seriously and ensure proper security measures are in place before something goes wrong.

What can be done?

There are several key steps that can be taken to help protect against third-party or supply chain compromises.

Zero Trust

One of the biggest is using a Zero Trust architecture, where no user or system is trusted by default. Everything needs to be verified before access is granted, even if it’s coming from inside the network.

Network Segmentation

Another vital step is network segmentation. Keeping critical systems separate from general operations or vendor-accessible areas can help contain an incident if something goes wrong. In OT environments, this may mean isolating production systems from vendor maintenance networks or external tools.

Continuous Vendor Management

Continuous vendor management is equally important. Organizations should only work with approved and vettedvendors, avoiding sourcing equipment or software from unverified suppliers. This includes eBay, Facebook Marketplace, and gray-market hardware. Regular vendor audits help ensure that partners are following the organization’s security standards and that their practices don’t introduce unnecessary risk.

Review Updates

When it comes to software updates, skipping updates entirely can create long-term vulnerabilities, but mindlessly applying them introduces risk too. The safest approach is to review, test, and approve updates before deploying them into production. This ensures you don’t unintentionally install malicious code from a compromised vendor while also avoiding the security gaps caused by ignoring critical patches.

Remote Access Control

For remote access and third-party support, strong controls are essential. Access should be tightly scoped, time-bound, and monitored, with multifactor authentication enabled whenever possible.

Incident Response Preparedness

Third parties also need to understand their role in the organization’s incident response (IR) plan. In many cases, vendors are not directly involved in response or recovery, so operations and security teams must be prepared to take full ownership of handling incidents when they occur.

Implementing these practices can help reduce the likelihood of a third-party compromise. And if one does happen, they can also help limit the damage and make recovery a lot faster.

Conclusion

These types of attacks are serious and can often be easily overlooked. The tools, equipment, and systems maintained by third parties may not be something you interact with daily, which makes them easier to overlook when assessing risk. But that’s precisely why they need to be part of the conversation.

Organizations should prioritize defining access to third parties and ensuring strict controls over what their devices and software can connect to. These risks should be reviewed in the same manner as any internal system or employee access.

If you haven’t already, take time to review your third-party relationships, vendor access policies, and any systems connected to external support or services. Start bringing these conversations into your risk discussions and planning sessions. It’s better to address these issues before they become a problem.

At Enaxy, we help organizations identify, assess, and mitigate third-party risks in their OT environments. Our approach combines technical controls with governance processes to ensure vendors and partners meet your security standards.

Whether you need a third-party risk assessment, a vendor access review, or a continuous monitoring strategy, our team has the real-world ICS and cybersecurity expertise to help safeguard your environment against supply chain threats.

Ready to strengthen your third-party security posture? Contact us at info@enaxy.com to learn how we can help.