
Shieldworkz Featured in The Supply Chainer
Shieldworkz Featured in The Supply Chainer: Ransomware No Longer Needs to Touch the Control System to Shut Down a Plant
Shieldworkz was recently featured in The Supply Chainer, addressing a shift security teams are increasingly seeing on the ground: ransomware doesn't need to touch a plant's control systems to shut it down anymore. Attackers are finding it just as effective and often easier to hit the suppliers, integrators, and vendor connections that surround OT environments. In the feature, Prayukth outlines why a defense-in-depth approach grounded in IEC 62443 is becoming essential, and what plant and operations leaders now need to monitor beyond the control room itself. Read the full coverage and Shieldworkz's perspective below.

Shieldworkz Featured in The Supply Chainer: Ransomware No Longer Needs to Touch the Control System to Shut Down a Plant
Shieldworkz was recently featured in The Supply Chainer, addressing a shift security teams are increasingly seeing on the ground: ransomware doesn't need to touch a plant's control systems to shut it down anymore. Attackers are finding it just as effective and often easier to hit the suppliers, integrators, and vendor connections that surround OT environments. In the feature, Prayukth outlines why a defense-in-depth approach grounded in IEC 62443 is becoming essential, and what plant and operations leaders now need to monitor beyond the control room itself. Read the full coverage and Shieldworkz's perspective below.


Why this coverage matters
This coverage matters because it challenges an assumption the industry has built years of defense around, that hardening the control room is enough. The scenario The Supply Chainer describes shows how a plant can be brought to a standstill without its OT ever being touched, simply because the business systems a supplier relies on go dark. Paired with Check Point Research's finding of a 56% year-over-year jump in ransomware attacks on manufacturers, the piece makes the case that the real attack surface has quietly shifted outward, into the vendors, integrators, and business systems that surround OT rather than sit inside it.
A plant can go idle without any attacker touching a PLC or HMI, the disruption comes from outside the control system entirely.
The Supply Chainer's feature opens with a scenario security teams increasingly recognize: a tier-two equipment supplier is hit with ransomware over a weekend, and by Monday, the plant it supports is at a standstill, not from a control-system breach, but because the supplier's order-management and engineering-support systems went dark.
With those systems down, no replacement parts ship, no firmware updates go out, and no technicians get dispatched, leaving the plant idle by consequence, not by direct attack.
With those systems down, no replacement parts ship, no firmware updates go out, and no technicians get dispatched, leaving the plant idle by consequence, not by direct attack.
Citing Check Point Research, the article notes that ransomware attacks against manufacturers rose 56% year-over-year in 2025, reaching 1,466 incidents.
That rise is attributed to ageing OT infrastructure, sprawling supplier networks, and the growing accessibility of ransomware-as-a-service.

Why this coverage matters
This coverage matters because it challenges an assumption the industry has built years of defense around, that hardening the control room is enough. The scenario The Supply Chainer describes shows how a plant can be brought to a standstill without its OT ever being touched, simply because the business systems a supplier relies on go dark. Paired with Check Point Research's finding of a 56% year-over-year jump in ransomware attacks on manufacturers, the piece makes the case that the real attack surface has quietly shifted outward, into the vendors, integrators, and business systems that surround OT rather than sit inside it.
A plant can go idle without any attacker touching a PLC or HMI, the disruption comes from outside the control system entirely.
The Supply Chainer's feature opens with a scenario security teams increasingly recognize: a tier-two equipment supplier is hit with ransomware over a weekend, and by Monday, the plant it supports is at a standstill, not from a control-system breach, but because the supplier's order-management and engineering-support systems went dark.
With those systems down, no replacement parts ship, no firmware updates go out, and no technicians get dispatched, leaving the plant idle by consequence, not by direct attack.
With those systems down, no replacement parts ship, no firmware updates go out, and no technicians get dispatched, leaving the plant idle by consequence, not by direct attack.
Citing Check Point Research, the article notes that ransomware attacks against manufacturers rose 56% year-over-year in 2025, reaching 1,466 incidents.
That rise is attributed to ageing OT infrastructure, sprawling supplier networks, and the growing accessibility of ransomware-as-a-service.
Shieldworkz perspective
Shieldworkz Prayukth K V, Director for the EU Region, told The Supply Chainer that when attackers stop targeting control systems directly, the real challenge becomes containment, not just prevention. He pointed to defense-in-depth under IEC 62443, where critical assets sit behind monitored zones that limit how far an intrusion can spread.
He also flagged a shift in plant-level responsibility, operations leaders now need to watch for risks like unmonitored removable media and unchecked IT-to-OT traffic, with strong asset hygiene and continuous visibility mattering as much as any single control.
The piece linked this to a related shift in vendor remote access, with Xona Systems' CTO noting a move away from VPN-based technician access toward session-based, approval-gated connections, a trend that echoes Shieldworkz zone-based approach.
Most notably, Prayukth warned that a breach starting at a supplier doesn't stay contained there, it can reach corporate networks, national-level SOCs, or sensitive plant systems like backups, where data can be altered or extracted.
Why This Recognition Matters
Being sought out for this feature isn't incidental, The Supply Chainer turned to Shieldworkz specifically because industrial and IoT cybersecurity is the firm's core focus, and Prayukth's answer reflects a perspective built from working inside OT environments, not commenting from the outside. For a publication read by supply chain and operations decision-makers, having Shieldworkz containment-first framing anchor the story's technical core signals where the firm sits in the industry conversation: not just as a vendor, but as a trusted source for grounded, standards-based guidance. It also reinforces the direction Shieldworkz has been building its own offerings around, that OT security today depends less on a single hardened perimeter and more on structured, monitored zones, tighter vendor access controls, and continuous visibility across the extended plant environment.
The Supply Chainer sought out Shieldworkz specifically for its core focus on industrial and IoT cybersecurity.
Prayukth insight reflects direct OT operating experience, not outside commentary.
Anchoring the story's technical core signals Shieldworkz standing as a trusted, standards-based source for security journalists and operators.
The coverage reinforces Shieldworkz own strategic direction: structured, monitored zones, tighter vendor access controls, and continuous visibility over a single hardened perimeter.
Key Takeaways From the Coverage
Ransomware increasingly disrupts plants indirectly by hitting a supplier's business systems, not the plant's control systems.
Check Point Research recorded a 56% year-over-year rise in ransomware attacks on manufacturers in 2025, totaling 1,466 incidents.
Shieldworkz Prayukth K V advocated a defense-in-depth approach aligned with IEC 62443, using monitored zones to contain, not just prevent, intrusions.
Plant and operations leaders now need visibility into extended risks: unmonitored removable media, unchecked IT-to-OT traffic, and vendor remote-access practices.
A breach that starts at a supplier or integrator can travel far beyond its origin, reaching corporate networks, national-level SOCs, or sensitive zones like backup systems.
The industry shift Shieldworkz described, from always-on vendor VPN access to session-based, approval-gated connections, echoes a broader move away from unmonitored third-party access.

Shieldworkz perspective
Shieldworkz Prayukth K V, Director for the EU Region, told The Supply Chainer that when attackers stop targeting control systems directly, the real challenge becomes containment, not just prevention. He pointed to defense-in-depth under IEC 62443, where critical assets sit behind monitored zones that limit how far an intrusion can spread.
He also flagged a shift in plant-level responsibility, operations leaders now need to watch for risks like unmonitored removable media and unchecked IT-to-OT traffic, with strong asset hygiene and continuous visibility mattering as much as any single control.
The piece linked this to a related shift in vendor remote access, with Xona Systems' CTO noting a move away from VPN-based technician access toward session-based, approval-gated connections, a trend that echoes Shieldworkz zone-based approach.
Most notably, Prayukth warned that a breach starting at a supplier doesn't stay contained there, it can reach corporate networks, national-level SOCs, or sensitive plant systems like backups, where data can be altered or extracted.
Why This Recognition Matters
Being sought out for this feature isn't incidental, The Supply Chainer turned to Shieldworkz specifically because industrial and IoT cybersecurity is the firm's core focus, and Prayukth's answer reflects a perspective built from working inside OT environments, not commenting from the outside. For a publication read by supply chain and operations decision-makers, having Shieldworkz containment-first framing anchor the story's technical core signals where the firm sits in the industry conversation: not just as a vendor, but as a trusted source for grounded, standards-based guidance. It also reinforces the direction Shieldworkz has been building its own offerings around, that OT security today depends less on a single hardened perimeter and more on structured, monitored zones, tighter vendor access controls, and continuous visibility across the extended plant environment.
The Supply Chainer sought out Shieldworkz specifically for its core focus on industrial and IoT cybersecurity.
Prayukth insight reflects direct OT operating experience, not outside commentary.
Anchoring the story's technical core signals Shieldworkz standing as a trusted, standards-based source for security journalists and operators.
The coverage reinforces Shieldworkz own strategic direction: structured, monitored zones, tighter vendor access controls, and continuous visibility over a single hardened perimeter.
Key Takeaways From the Coverage
Ransomware increasingly disrupts plants indirectly by hitting a supplier's business systems, not the plant's control systems.
Check Point Research recorded a 56% year-over-year rise in ransomware attacks on manufacturers in 2025, totaling 1,466 incidents.
Shieldworkz Prayukth K V advocated a defense-in-depth approach aligned with IEC 62443, using monitored zones to contain, not just prevent, intrusions.
Plant and operations leaders now need visibility into extended risks: unmonitored removable media, unchecked IT-to-OT traffic, and vendor remote-access practices.
A breach that starts at a supplier or integrator can travel far beyond its origin, reaching corporate networks, national-level SOCs, or sensitive zones like backup systems.
The industry shift Shieldworkz described, from always-on vendor VPN access to session-based, approval-gated connections, echoes a broader move away from unmonitored third-party access.


About Shieldworkz
Shieldworkz helps organisations secure Operational Technology (OT), IoT and Cyber-Physical Systems (CPS) across industrial and national infrastructure. Our threat research team blends sector-aware telemetry, hunt-driven detection, and hands-on incident response to find hidden exposure and build resilient recovery paths.

About Shieldworkz
Shieldworkz helps organisations secure Operational Technology (OT), IoT and Cyber-Physical Systems (CPS) across industrial and national infrastructure. Our threat research team blends sector-aware telemetry, hunt-driven detection, and hands-on incident response to find hidden exposure and build resilient recovery paths.
Visit our website: https://shieldworkz.com
For press inquiries and expert interviews, contact: info@shieldworkz.com
Stay ahead of tomorrow’s threats with Shieldworkz, your partner in proactive OT cybersecurity.
Learn More & Resources
Visit our website: https://shieldworkz.com
For press inquiries and expert interviews, contact: info@shieldworkz.com
Stay ahead of tomorrow’s threats with Shieldworkz, your partner in proactive OT cybersecurity.
Learn More & Resources
Read the news article

