Supply chain attack
A supply chain attack compromises a target by first exploiting a vulnerability somewhere in its supply network, such as a software vendor, hardware manufacturer, or third-party contractor, rather than attacking the target directly. In OT specifically, this can mean compromised firmware shipped from a device manufacturer, or malicious code introduced through a maintenance contractor’s remote-access tools, which is part of why vendor and contractor access is a specific focus of OT security programs.