TECH & AI
default credentials and remote diagnostic backdoors that may never be fully documented,” Sheetal says.“ Many a time these are months- or years-old published vulnerabilities which could have been easily patched if there were proper security controls and governance in place, but again these are often overlooked when building the supplier ecosystem.”
Legacy systems and air gaps These problems end up on factory floors that were not designed to defend against them. Supervisory control and data acquisition systems and programmable logic controllers installed decades ago still run unsupported software with weak or default authentication, and often cannot be routinely patched.
As IT and OT systems come together, the air gap that once kept them safe is disappearing.“ No doubt that the convergence delivers real value – realtime analytics, predictive maintenance, tighter supply-chain integration – but security has not kept pace with connectivity,” Sheetal says.“ Attackers understand this topology and now deliberately target the IT / OT boundary to maximise operational disruption pressure, because a compromise in IT can cascade directly into real consequences on the physical factory floor.”
AI can make this problem both better and worse. It gives attackers“ cheaper, more convincing tools”, from AI-enabled phishing to deepfake social engineering aimed at plant staff without regular security training.
“EVERY SINGLE VENDOR BREACH HAS A CASCADING EFFECT ON DOWNSTREAM COMPANIES THAT ARE COMPROMISED”
Sheetal Mehta, Executive Managing Director and Global Head of Cybersecurity NTT DATA
100 October 2026