Why the unseen risks in operational technology are no longer theoretical
Operational technology (OT) environments are under growing pressure. As critical infrastructure modernises, organisations are connecting legacy systems, adopting cloud services, and integrating new platforms to improve efficiency and resilience. While this shift is necessary, it also exposes a new class of risks that many organisations are not fully prepared to manage. Michael Murphy, Director of Operational Technology, APAC, Fortinet, said, “Critical infrastructure organisations often focus on software vulnerabilities and network threats; however, some of the most critical risks now sit much earlier in the lifecycle before a device is even powered on. Supply chain compromise, hardware tampering, and counterfeit components are becoming more relevant as environments become more connected.” These risks are not limited to a single deployment model. Whether infrastructure is on-premises, converged across IT and OT, or delivered through cloud services, the same questions apply: where technology comes from, how it is built, and whether it can be trusted. Supply chain compromise: risk at the source Modern OT environments rely on highly interconnected supply chains. Hardware, software, and services are sourced globally, often through multiple vendors and intermediaries. This creates risk. If any part of that chain becomes compromised, the impact can cascade across operations. Michael Murphy said, “As organisations adopt cloud and platform-based services, they gain efficiency yet lose visibility. They no longer inspect what arrives on-site. They trust that the provider has done the right checks across their supply chain.” The risk is now real and no longer theoretical. Increasingly, organisations see instances where components are substituted, modified, or sourced from unverified suppliers. In critical infrastructure, even a minor compromise can have operational and safety implications. This aligns with broader industry concerns about interconnected supply chains amplifying disruption, where a single compromised node can affect entire production and distribution networks. Hardware tampering: trust cannot stop at the perimeter Traditional security models assume hardware remains trustworthy once deployed. That assumption no longer holds. Tampering can occur during manufacturing, transit, or installation. In some cases, actors may modify devices to introduce hidden functionality or vulnerabilities before they ever reach the customer. Michael Murphy said, “There are controls like tamper-evident seals for physical […]