Data center technology

Protecting mining’s digital backbone: OT cybersecurity in metals and minerals

Related topics

Resilience will be key to safeguarding critical mining operations from emerging cyber threats in an increasingly digitized world.


In brief

  • While operational technology (OT) is vital to mining operations, controlling physical processes and safety systems, it faces growing cybersecurity risks.
  • Threats to mining OT can disrupt production, endanger lives and cause significant financial and reputational damage.
  • Proactive cybersecurity measures, from risk management and network segmentation to workforce training, will be needed to safeguard operations for the future.

The minerals that power many of today’s modern conveniences and technologies — from smartphones to electric vehicles — depend on consistent and reliable mining operations that are increasingly relying on effective OT systems to deliver. As such, a single cyber threat in such interconnected environments can be enough to disrupt critical equipment and bring operations to a standstill - often from thousands of kilometres away.
 

OT cybersecurity is a very real and growing concern facing today’s metals and minerals sector. As cyberattacks escalate, the question is no longer about if an operation will be targeted, but when. How prepared will metals and minerals organizations be to survive the fallout?
 

The metals and minerals sector has long been a major economic driver and fortress of rugged resilience. But beneath the surface, there are very real vulnerabilities that are becoming prime targets for cybercriminals.

Dated and unsecured OT systems are increasingly integrated with IT networks, even as they control critical functions, ranging from underground ventilation to heavy machinery.

Unprotected legacy systems designed decades before cybersecurity was even a consideration can be difficult to patch by today’s standards. A commitment to worker safety adds to the pressure of meeting attackers’ demands to avoid fatalities and meet production requirements.

The harsh reality is that a single cyber breach of human machine interfaces, programmable logic controllers and engineering workstations, for example, can have devastating impacts. Besides bringing production to a halt, they can endanger lives and cost ill-equipped businesses millions of dollars — causing pillars of economic stability to collapse overnight.
 

OT cybersecurity is often dismissed, poorly articulated or buried as a line item in a cyber or IT-focused update. When attention is given, it may be treated as a compliance checkbox exercise or a cost centre to be managed.
 

In metals and minerals, where OT governs life-critical systems and multimillion-dollar processes, this mindset can present as a ticking time bomb. When threat actors successfully break into OT networks, they’re not simply stealing data — they’re manipulating physical processes, sabotaging safety systems and, ultimately, disrupting global commodity flow and supply chains from end to end.
 

The challenge for operators and managers is translating OT cyber risks into language that leadership and boards can understand. What’s the value at risk, or the likelihood of threats being exploited?
 

The metals and minerals sector has become a prime target for cyberattacks, with OT a sensitive lever and desirable access point for threat actors looking for impact. The stakes are high. The financial impact of cyber events targeting OT can be significant, from lost production and supply chain disruption to emergency response and reputational damage.
 

Ignoring OT cybersecurity is clearly no longer an option — it’s a costly gamble, with potentially catastrophic consequences.

Closing the OT security gap

Encompassing programmable systems and devices that directly control and monitor physical processes in industrial environments, OT refers to any equipment used to manage extraction and processing in mining, and support safe operation - from industrial control and safety systems, programmable logic controllers and supervisory control and data acquisition (SCADA) systems, to sensors and actuators and autonomous haulage, drilling and ventilation control systems.

Given the critical role metals and minerals plays in supplying the raw materials fueling modern life, securing OT environments is essential. A failure to control ventilation or heavy machinery, for example, could result in unanticipated and costly operational shutdowns or worse: safety incidents resulting in injury or loss of life.

In the process of digitizing their operations and increasing their use of AI, mining companies are expanding their attack surfaces. While these technologies can help strengthen supply and operational resilience, they can expose OT systems to additional threats. The industry has already experienced a rise in cyberattacks, including ransomware incidents that have disrupted operations and led to significant financial losses and recovery costs.

The situation can become more complicated as legacy OT systems, outdated software and proprietary protocols designed before such security issues arose continue to be integrated into modern IT systems. The lack of interoperability is creating troubling gaps, while antiquated protocols make patching or updating challenging. Resulting downtime or rollback plans often lead to plans being shelved or - where risk appetite is high - postponed indefinitely in favour of sustained operations.

The complex integration of multiple systems, legacy equipment, third-party and software supply chains is opening undesirable doors - to malware and insider threats that let threat actors in, and denial of service (DoS) and supply chain attacks designed to lock authorized users out.

But even frequently updated assets, like AI tools for inventory management or cloud-hosted administrative systems, are surfacing coverage gaps for unprepared cyber teams, resulting in potentially increased security risks. According to the 2026 EY Global Cybersecurity Leadership Insights Study, the metals and minerals sector topped a “vulnerability zone” list, rating 67% of surveyed organizations’ OT assets as below average on cyber visibility and coverage and making them more susceptible to cyber threats, second only to infrastructure at 71%.1

The EY study also shows that without adequate visibility and controls, continued convergence - of IT, OT networks and more recently with AI-driven systems and tools - not only exposes access but opens attackers’ ability to move laterally and compromise critical OT across an organization. A significant risk, since only 18% of respondents in the insights study reported full visibility over their OT network infrastructure and only 11% have full cyber control over them.2 Add social engineering, insider threats and human error, and metals and minerals companies are putting themselves in the crosshairs of a perfect storm.

All this complexity is complicating monitoring and incident detection, exposing vulnerabilities in a world where cyber attacks and threat actors are growing progressively sophisticated.

Making OT cybersecurity a business priority

While the outlook is not entirely bleak, metals and minerals companies should act now to prioritize and safeguard their OT environments. Cyber threats continue to evolve, and past incidents offer important lessons for strengthening resilience.

If it’s not topping the list of priorities for the industry today, it should be. While an annual EY report listing the top risks and opportunities on the minds of sector leaders featured cybersecurity as early as 2020, the topic fell off the radar completely in 2025 and is still absent in 2026.

This trend indicates cybersecurity may have been put on hold as metals and minerals organizations double down on exploration and discovery to meet growing demand. But it more than likely indicates metals and minerals organizations have relegated cybersecurity to business as usual, meaning it no longer warrants the attention devoted to broader issues of operational complexity, capital and workforce.

Either way, the decision to deprioritize OT cybersecurity depends on the business and the level of cyber risk its C-suite and shareholders are willing to accept. But the truth is that when it comes to selling cybersecurity within an organization, risk costs and returns aren’t easy to articulate or effectively communicate to the leaders responsible for making these vital investments.

Cybersecurity is almost always classified as a cost of doing business. But when comparing the costs of deploying and managing controls against remediation programs, proactive measures taken early can help prevent costly consequences down the road. 

Building the case for investment

Metals and minerals companies operate in complex regulatory and operational landscapes, with significant compliance complications and long project timelines that demand significant capital investments. Facing environmental and geographic regulations, safety and labour accountability and emerging ESG and other reporting requirements, it’s critical to get the balance right between cybersecurity for OT environments and regulatory compliance.

Looking to shore up your OT cybersecurity? Here are four steps to help you lock the door when threat actors come knocking.

  • Write it down. Proactively build out your OT cyber strategy, starting by using the Purdue Model to map out equipment and the flow of information and security standards like ISA 62443 to determine how to best protect it. Define your risk appetite and prioritize where to focus efforts and detail how you plan to respond for the greatest value.

  • Isolate access. If your network is currently flat and unmanaged, re-architect and segment IT and OT, building out zones and conduits to make managed decisions that restrict and control access across teams. Restricting access by requiring verification with each interaction helps contain cyber incidents and prevent damage.

  • Patch frequently. Challenge antiquated thinking and practices around patching and vulnerability management. Continual advancements with AI are proving how quickly attackers can chain together vulnerabilities to produce working exploits. Complacency around patching is no longer an option.

  • Be aware. For most organizations, their people continue to be one of the greatest risks. Educate teams on password use and phishing tactics, and remind them to be cautious when clicking on email links. This job never ends. Resilience and supportive communications will be needed as threats evolve and actors grow more sophisticated.

Having secure and reliable OT requires an organization’s cyber risk strategy to be closely aligned with its ERM framework. Doing so can help leaders envision where the business is going and help get them on board with the commitment and investment dollars needed to get there. Proactive investment in OT cybersecurity can no longer be considered optional or a “nice to have.”

Like the “shift left” approach of incorporating security considerations from the start of software design and development, the same move should be considered when it comes to cybersecurity considerations across the business: they should be embedded from a project’s inception and incorporated into every aspect.

EY teams help minerals and metals companies conduct risk and maturity assessments, offer compliance perspectives and build multi-year roadmaps aligned with business priorities. We help identify and prioritize the gaps that offer the greatest value, define a stronger OT security posture and embed security across the organization through tailored risk management strategies, robust controls and workforce capability building.

By improving cyber resilience and protecting critical infrastructure, we help organizations sustain long-term operational success and position cybersecurity as an enabler versus a cost centre to be borne.

Risk and maturity assessments, including reviews of third-party and vendor tools, provide a clear foundation for improvement roadmaps. Building on these findings, business impact assessments can help organizations balance operational efficiency with security, address legacy system challenges and prepare to integrate technologies like the internet of things and AI.

Managing AI’s promise — and risk

All of this is particularly relevant as AI adoption accelerates, outpacing expectations and society’s ability to manage the associated risks.

Recent cybersecurity initiatives and industry discussions have increasingly focused on the implications of advanced AI, with organizations seeking to proactively address emerging risks and vulnerabilities before they can be exploited.

AI-powered cybersecurity technologies may dramatically improve cybersecurity by automating the discovery of hidden and complex vulnerabilities that would take humans much longer to find. On the other hand, it can also be misused - against itself - to create even more sophisticated cyberattacks. This leads to a compelling reason for metals and minerals organizations to fight fire with fire, lock down OT by implementing the recommendations outlined above and working with an advisor who can help at every stage in the journey.

That’s where we can help.


Summary

OT is the backbone of modern mining operations, controlling critical processes that impact safety, production and environmental stewardship. As cyber threats evolve and digitization accelerates, metals and minerals companies face unprecedented risks that demand resilient, proactive and integrated cybersecurity strategies.

By understanding OT’s unique challenges and implementing targeted controls, the metals and minerals sector can safeguard its vital role in the global economy and protect the lives and assets it depends on.

Contributor:
Dylan D’Silva, Manager – OT Cybersecurity | Delivery Excellence Lead for Energy & Industrials | Technology Consulting, EY Canada

Related content

Mining today with EY – EP 13: Navigating responsible AI in metals and minerals

Insights from our sector advisors on current trends in responsible AI in metals and minerals. Learn more.

Epic transformation: securing the mine of the future

Explore how advanced mining technologies demand robust cybersecurity to secure operations, protect assets and ensure sustainable growth.

Cybersecurity and metals and minerals: striking a delicate balance

Explore insights from EY's roundtable on cybersecurity in metals and minerals, focusing on AI risks, incident response, and strategies to combat human error.

About this article