Manufacturers are being urged to strengthen cybersecurity throughout their supply chains amid a sharp rise in attacks targeting trusted software providers, suppliers and third-party partners. The warning, from Mitsubishi Electric Automation Systems Division UK, follows a recent supply chain attack involving disk imaging software that affected thousands of systems worldwide, including those within the manufacturing sector.
(Pictured right: David Bean, Business Development Group Manager at Mitsubishi Electric Automation Systems Division9)
The attackers deployed malicious code through legitimate software downloads, using it to gather information on thousands of systems before selectively targeting organisations of interest with a second-stage backdoor.
The incident highlights a growing challenge for manufacturers. According to recent industry research, supply chain attacks have increased by 20% year-on-year, making them the fastest-growing cyber threat to the sector. As manufacturers continue to connect operational technology (OT), IT systems and external partners, every supplier relationship and software dependency has the potential to become an attack vector.
The need to strengthen cybersecurity across the wider manufacturing ecosystem is becoming increasingly important as manufacturers prepare for evolving regulatory requirements, including the Cyber Resilience Act (CRA) that mandates greater oversight of cybersecurity risks across product lifecycles and supply chains.
David Bean, Business Development Group Manager at Mitsubishi Electric Automation Systems Division, said: "Cybersecurity can no longer be viewed as something that begins and ends within a manufacturer's own network. Modern manufacturing operations depend on a complex ecosystem of software providers, equipment suppliers, systems integrators and service partners, all of which can introduce risk if they are not properly managed.
"The recent supply chain attack demonstrates how cybercriminals are increasingly targeting trusted relationships rather than attacking organisations directly. If a supplier or software provider is compromised, that risk can quickly extend across multiple businesses."
He advises manufacturers to adopt a layered approach to cybersecurity that extends beyond internal systems and considers the resilience of the wider supply chain.
"Manufacturers should have visibility of every system connected to their operations and understand who has access to critical assets and data. This includes implementing robust access controls, assessing the cybersecurity practices of suppliers and third-party partners, and ensuring security requirements are consistently applied across the wider ecosystem.
"Not only does this mean protecting internal systems but also scrutinising vendor networks and third-party partners. With cyber threats continuing to evolve, organisations that take a proactive approach to supply chain security will be better positioned to maintain business continuity, protect sensitive data and minimise operational disruption."
With supply chain attacks continuing to rise and regulatory expectations increasing, Mitsubishi Electric is encouraging manufacturers to review cybersecurity beyond their own networks. This includes understanding the security practices of software providers, suppliers and third-party partners, whilst ensuring appropriate controls are in place across connected systems. Taking a proactive approach to supply chain security can help reduce cyber risk, support business continuity and strengthen resilience against emerging threats.
Want the latest machine building news straight to your inbox? Become a MachineBuilding member for free today >>