"Ransomware No Longer Needs to Touch the Control System to Shut Down a Plant"
A tier-two equipment supplier gets hit by ransomware on a Friday night. No one touches a single PLC or HMI. By Monday, the plant it serves is idle anyway - not because its control systems were breached, but because the supplier's order-management and engineering-support systems went dark, and nobody can get a replacement part shipped, a firmware update pushed, or a technician dispatched. This has become one of the more common paths a ransomware attack takes to a factory floor: through the business systems surrounding operational technology (OT), rather than OT itself.
The trend line supports the scenario. According to Check Point Research, ransomware attacks against manufacturers rose 56% year-over-year in 2025, climbing to 1,466 incidents, as legacy OT systems, deep supplier networks and ransomware-as-a-service platforms widened the industry's exposure.
Defense Has to Move Past the Control Room
Prayukth K V, Director for the EU Region at Shieldworkz, an industrial and IoT cybersecurity firm, replied in writing to The Supply Chainer's inquiry about what changes when attackers no longer need direct access to control systems to disrupt production. His answer centered on containment rather than prevention alone: "This underscores the importance of having a multi-level security approach often referred to as Defense-in-depth. As per the IEC 62443 standard, for instance, key assets and systems can be placed behind virtual zones where they are subject to higher levels of monitoring and security and traffic management. Such zones allow containment of an attack and thereby limit the damage. What changes at a plant level is that plant and operations head should now deploy measures to monitor and contain the extended attack surfaces that exist, such as unmonitored use of pen drives or threats that travel unhindered from IT networks. Plants also need to maintain network and asset hygiene and operate with higher levels of visibility into asset and network behaviours."

The Weakest Link Is Often a Trusted Vendor
That containment logic runs into a specific problem: vendor remote access. In a written response to a separate Supply Chainer inquiry, Mike Carr, CTO at Xona Systems, described customers pulling back from software stacks that run OT protocols straight off a vendor's laptop over VPN - a setup he called "a risk that organizations can no longer afford to make." Carr said clients are increasingly deploying those tools locally within the OT environment and shifting from always-on connections to session-based access that requires approval before an outside technician gets in.
Risk Doesn't Stay Where It Starts
Prayukth was direct about how far a compromise can travel once it starts at a supplier or integrator rather than the plant. He described a chain that can reach networks tied to corporate headquarters and, for critical-infrastructure operators, national security operations centers - with the impact looking different at each stop. A delay at a national-level SOC, he noted, can slow the response to an unrelated emergency well beyond the original incident. In other scenarios, he said, a threat can move across networks and land in a more sensitive zone, such as a backup system or control room environment, where it can exfiltrate or corrupt data.
For plant and operations leaders, the practical response looks less like a single fix and more like an ongoing discipline: watching the traffic that crosses IT/OT boundaries, tightening how outside vendors connect, and treating every credential in the system - human or machine - as something that could eventually be misused. Containment, not prevention alone, is becoming the baseline plants are being asked to plan around.




