TroutTrout
Back to Glossary
Supply chain securitySupply chain riskVendor security

Supply Chain Security

3 min read

Supply chain security is the practice of protecting your systems from risk introduced by the outside parties you depend on: vendors, suppliers, contractors, integrators, and the software and hardware they ship you. The core idea is simple. Every vendor with a login, a component in your product, or a maintenance laptop is part of your attack surface, whether you manage them or not. In OT, the sharpest edge of that risk is the third-party remote access that keeps plants running.

What is supply chain security?

It is the set of controls that reduce the chance a trusted supplier becomes the way in. In practice that means assessing a vendor's security posture before you onboard them, writing concrete security obligations into contracts, monitoring what their connections and components actually do once they are inside, and having a plan to contain them when something goes wrong. The scope covers both digital supply chain (software libraries, firmware, updates) and the operational reality of contractors dialing into your network.

How does a supply chain attack work?

An attacker compromises a supplier that many organizations trust, then rides that trust downstream. SolarWinds is the textbook case: malicious code was planted in a routine software update and pushed to thousands of customers who had every reason to install it. The 2013 Target breach started with credentials stolen from an HVAC vendor. The pattern is always the same, the target is not breached directly, it is reached through a partner who already has legitimate access. In OT, that partner is often an equipment maker with standing remote access to a PLC or a control system.

Why does supply chain security matter for OT?

OT sites lean hard on vendors. The people who understand a specific turbine, robot, or SCADA package are usually the ones who built it, so they get remote access to maintain it. That access is frequently flat, always-on, and poorly logged, which means one compromised vendor laptop can reach a physical process. A breach here does not just leak data. It can halt production, damage equipment, or create a safety event, which is why supply chain risk sits at the top of most OT security programs.

What standards cover supply chain security?

  • NIST SP 800-171: protects controlled unclassified information in non-federal systems and sets access and monitoring expectations for the defense supply chain.
  • CMMC: the Cybersecurity Maturity Model Certification, which makes those practices auditable across the defense industrial base.
  • NIS2: the EU directive that explicitly requires essential and important entities to manage supply chain cyber risk.
  • IEC 62443: addresses supplier and integrator security for industrial automation and control systems.
  • NERC CIP: CIP-013 makes supply chain risk management a hard requirement for the bulk electric system.

How Access Gate helps

Most OT supply chain risk lives in vendor remote access, and that is exactly what Access Gate scopes down. Every third-party session is proxied through an identity-based access point, logged, and terminable, so a maintenance vendor reaches one asset for one task instead of the whole network. Microsegmentation keeps a compromised vendor connection from moving east-west into other cells, asset discovery surfaces the vendor links you forgot were open, and session traffic forwards to your SIEM for the evidence auditors ask for.

Related terms