From Factory Floor to Global Door: OT Security in Supply Chain
The manufacturing and critical infrastructure sectors are now at the epicenter of cyberattacks, with manufacturing becoming the most targeted industry globally. Operational Technology (OT) environments, particularly those embedded in supply chains, face growing exposure with over 1,200 new OT-related CVEs identified in the past year alone. As cyber-physical systems (CPS) like SCADA, ICS, and PLCs increasingly converge with corporate IT for integrated supply chain management, attackers gain expanded vectors to disrupt industrial operations. This convergence transforms previously isolated OT systems into critical weak points in the global supply chain. This talk examines the evolving OT threat landscape—spanning ransomware, wireless protocol exploits, PLC firmware attacks, insider threats, and exploitation of SCADA-specific protocols (e.g., Modbus, BACnet, OPC, IEC 60870). It highlights how adversaries leverage commodity tools such as FlipperZero, HackRF, and PLC injection kits to compromise sensors, valves, and robotic systems, directly impacting manufacturing reliability and supply chain resilience. The paper underscores that attacks on OT are not isolated incidents but ripple across entire supply chains, affecting production continuity, logistics, and downstream business operations. To counter this, we discuss a defense-in-depth approach tailored for OT and supply chain ecosystems, integrating secure network segmentation, Zero Trust architectures, authenticated operations, proactive threat intelligence, and rigorous vulnerability and patch management. With insurance providers now mandating OT-specific cybersecurity controls, it is clear that safeguarding OT is no longer optional but a core requirement for operational and supply chain continuity. This session emphasizes why OT security must be treated as a foundational pillar of modern supply chain resilience.
Speaker

Jiggyasu Sharma
Information Security Evangelist
Lead Info Sec Engg Consultant at Nike with over 15 years of experience in information and application security, specializing in IOT/OT. My expertise spans web and mobile application security, API/web services, network and wireless security, Bluetooth and Zigbee, embedded device security, and 3G/4G spectrum security, where I have led large-scale security initiatives to strengthen enterprise resilience and enable secure product innovation. I hold OSCP, ECSA, and SANS-561 certifications and am an a... read more