EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
The EY Americas Metals and Mining Center of Excellence offers companies access to cutting-edge services and innovation-led solutions.
Read more
The minerals that power many of today’s modern conveniences and technologies — from smartphones to electric vehicles — depend on consistent and reliable mining operations that are increasingly relying on effective OT systems to deliver. As such, a single cyber threat in such interconnected environments can be enough to disrupt critical equipment and bring operations to a standstill - often from thousands of kilometres away.
OT cybersecurity is a very real and growing concern facing today’s metals and minerals sector. As cyberattacks escalate, the question is no longer about if an operation will be targeted, but when. How prepared will metals and minerals organizations be to survive the fallout?
The metals and minerals sector has long been a major economic driver and fortress of rugged resilience. But beneath the surface, there are very real vulnerabilities that are becoming prime targets for cybercriminals.
Dated and unsecured OT systems are increasingly integrated with IT networks, even as they control critical functions, ranging from underground ventilation to heavy machinery.
Unprotected legacy systems designed decades before cybersecurity was even a consideration can be difficult to patch by today’s standards. A commitment to worker safety adds to the pressure of meeting attackers’ demands to avoid fatalities and meet production requirements.
The harsh reality is that a single cyber breach of human machine interfaces, programmable logic controllers and engineering workstations, for example, can have devastating impacts. Besides bringing production to a halt, they can endanger lives and cost ill-equipped businesses millions of dollars — causing pillars of economic stability to collapse overnight.
OT cybersecurity is often dismissed, poorly articulated or buried as a line item in a cyber or IT-focused update. When attention is given, it may be treated as a compliance checkbox exercise or a cost centre to be managed.
In metals and minerals, where OT governs life-critical systems and multimillion-dollar processes, this mindset can present as a ticking time bomb. When threat actors successfully break into OT networks, they’re not simply stealing data — they’re manipulating physical processes, sabotaging safety systems and, ultimately, disrupting global commodity flow and supply chains from end to end.
The challenge for operators and managers is translating OT cyber risks into language that leadership and boards can understand. What’s the value at risk, or the likelihood of threats being exploited?
The metals and minerals sector has become a prime target for cyberattacks, with OT a sensitive lever and desirable access point for threat actors looking for impact. The stakes are high. The financial impact of cyber events targeting OT can be significant, from lost production and supply chain disruption to emergency response and reputational damage.
Ignoring OT cybersecurity is clearly no longer an option — it’s a costly gamble, with potentially catastrophic consequences.