Why the unseen risks in operational technology are no longer theoretical
Operational technology (OT) environments are under growing pressure. As critical infrastructure modernises, organisations are connecting legacy systems, adopting cloud services, and integrating new platforms to improve efficiency and resilience.
While this shift is necessary, it also exposes a new class of risks that many organisations are not fully prepared to manage.
Michael Murphy, Director of Operational Technology, APAC, Fortinet, said, “Critical infrastructure organisations often focus on software vulnerabilities and network threats; however, some of the most critical risks now sit much earlier in the lifecycle before a device is even powered on. Supply chain compromise, hardware tampering, and counterfeit components are becoming more relevant as environments become more connected.”
These risks are not limited to a single deployment model. Whether infrastructure is on-premises, converged across IT and OT, or delivered through cloud services, the same questions apply: where technology comes from, how it is built, and whether it can be trusted.
Supply chain compromise: risk at the source
Modern OT environments rely on highly interconnected supply chains. Hardware, software, and services are sourced globally, often through multiple vendors and intermediaries. This creates risk. If any part of that chain becomes compromised, the impact can cascade across operations.
Michael Murphy said, “As organisations adopt cloud and platform-based services, they gain efficiency yet lose visibility. They no longer inspect what arrives on-site. They trust that the provider has done the right checks across their supply chain.”
The risk is
This aligns with broader industry concerns
Hardware tampering: trust cannot stop at the perimeter
Traditional security models assume hardware remains trustworthy once deployed. That assumption no longer holds. Tampering can occur during manufacturing, transit, or installation. In some cases, actors may modify devices to introduce hidden functionality or vulnerabilities before they ever reach the customer.
Michael Murphy said, “There are controls like tamper-evident seals for physical equipment; however, they don’t exist for cloud or service-based environments in the same way. As soon as organisations move away from physical ownership, they lose another layer of assurance.”
This results in a visibility gap. Organisations may have strong network monitoring and detection capabilities yet still lack confidence in the integrity of the underlying infrastructure. The challenge compounds in OT, where systems are often designed for longevity and cannot be easily replaced or updated. A compromised device can remain embedded in operations for years.
Counterfeit components: a growing and underestimated threat
Counterfeit or unauthorised components present another layer of risk. These may look identical to legitimate parts; however, they behave differently under certain conditions or fail to meet security and performance standards.
Michael
In OT environments, where uptime and safety are critical, this risk
At a broader level, this reflects a shift in how organisations need to think about cybersecurity. Protection no longer extends only to software and networks. It extends to the integrity of every component within the environment.
Why this matters now
The convergence of IT and OT, combined with increased reliance on cloud and third-party providers, changes the risk profile for critical infrastructure.
At the same time, threat actors are scaling their capabilities
Michael Murphy said, “These risks apply regardless of where critical infrastructure organisations are on their transformation journey. Whether they run air-gapped systems or move to full cloud integration, they still need to ask the same questions about trust, integrity, and verification.”
Addressing these risks requires a shift in mindset. Critical infrastructure organisations need to extend their security focus beyond deployment and into procurement, vendor selection, and lifecycle management.
Key areas to focus on include:
- supplier transparency: understand where components originate and how they are validated
- software bill of materials (SBOM): gain visibility into the components within hardware and software, while balancing disclosure risks
- vendor due diligence: ask providers how they manage supply chain integrity, hardware assurance, and component validation
- continuous verification: treat trust as an ongoing process, not a one-time assumption.
Industry initiatives such as the Secure by Design pledge are reinforcing the need for greater accountability and transparency across the technology lifecycle. The pledge encourages manufacturers to take ownership of security outcomes and demonstrate measurable progress in strengthening product security.
For organisations
Michael