The lurking risks of Subcontracting in Operational Technology

By: Babekir Mohamed
Digital Analyst
Subcontractors are often involved when companies lack the expertise or resources to manage tasks independently, however their involvement can expose critical systems to vulnerabilities that cybercriminals are quick to exploit. Let’s take a close look at a hypothetical scenario: a power company modernizes its national grid and partners with a foreign supplier to install advanced monitoring systems. The supplier connects directly to the company’s network for diagnostics and updates. Now, consider if that supplier’s cybersecurity measures are outdated or poorly enforced. Well, It’s not just their data at risk…. it’s the entire grid.
In reality this scenario isn’t far from the truth. In Sudan, where cybersecurity infrastructure is often underfunded, the stakes are even higher. Furthermore, the Global Cybersecurity Index ranks Sudan among the least prepared countries globally, emphasizing its lack of robust cybersecurity measures to counter these threats. Many private companies and some institutions depend on cloud storage and computing services from foreign providers like Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to store data and run applications. In 2022, Interpol reported that 60% of cyberattacks in Africa targeted financial institutions, with attackers often exploiting vulnerabilities in foreign-owned systems.
Beyond security, the economic consequences are dire. During U.S. sanctions, many Sudanese businesses struggled as access to foreign-hosted payment systems like Visa and Mastercard was suspended. Even everyday services like e-commerce platforms, email, and software licenses were difficult to access. Sudan’s dependency on foreign servers may also expose the country to service disruptions. For instance, geopolitical tensions in the region or economic sanctions could prompt foreign companies to halt operations, leaving the country’s financial systems vulnerable. Such disruptions highlight the risks of depending on external infrastructure for essential services.
The solution lies in adopting international standards like IEC 62443, a globally recognized framework for securing industrial automation and control systems (IACS). This standard emphasizes collaboration between stakeholders, including subcontractors, to ensure cybersecurity is embedded at every stage, from system design and integration to maintenance and operation.
As Sudan its path to modernization, It is important to adopt stricter data localization requiring sensitive information to be stored on domestically owned servers. Building local technological capacity and establishing partnerships with trusted allies are vital steps to reducing reliance on foreign providers. For Sudan, building technological self-reliance is not just about progress, but rather about safeguarding its sovereignty in a digital age.