Quantify the cyber resilience of your supply chain by enabling early indications and warnings of compromise within your organization and critical third-party partners. Your partners’ risks are your risks. They must both be measured continuously.
Product Security & the Supply Chain: Paul Ott Of Accenture On Ensuring Integrity in the Manufacturing Sector

Supply chain security is a critical aspect of the manufacturing industry. With numerous suppliers and partners involved, the potential for security risks is high. How do product security managers ensure supply chain security? How do they identify and address potential risks associated with suppliers and partners? As a part of this series, we had the pleasure of interviewing Paul Ott.
Paul Ott is Accenture Federal Services Managing Director, Federal Supply Chain and Operations Practice Lead. Ott is a problem-solving executive with proven results in developing and leading high-impact, high-visibility business strategy, supply chain, and data analytics projects across multiple clients.
Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about how you grew up?
I was born in the Bronx, New York and moved to Pennsylvania as a child. I did fine in school but can’t say I was extraordinary. The good news was my high school was relatively small which afforded me the opportunity to be extremely involved in sports, clubs, and extracurricular activities.
Is there a particular story that inspired you to pursue a career in Supply Chain Security? We’d love to hear it.
I’m not sure if anybody dreams of becoming a supply chain professional! I evolved into this field. I have a real affinity for rolling up my sleeves and helping clients solve their hardest problems. I’ve worked mostly in the defense space, and as it turned out, there are many supply chain challenges. I also enjoy attacking things with a good balance of “street smarts and book smarts!” What I mean by that is I don’t believe you can sit in the office and just “be brilliant”. People need to be introduced to solutions at all levels, or else the best idea, the best analytics, etc. just will not work.
You are a successful leader. Which three character traits were most instrumental to your success? Can you please share a story or example for each?
I’ve been fortunate to have worked with sensational people throughout my career. Because almost everyone I work with is smarter than me, it has been essential to build great teams and give them the freedom to be curious and use their talents to contribute to the mission of our clients. I think another trait for me is being appropriately bold, which means a willingness to “break some glass” when it’s needed. I’m not a good rules person, so I don’t feel limited by traditional barriers — everything can be changed if we really want to. Lastly, this is a relationship business. So, my third trait would be an ability to build strong relationships and trust with customers, partners, and with my teammates.
Are you working on any exciting new projects now?
At Accenture Federal Services, I never could have imagined the myriad of exciting areas in which I’d be immersed. I look after various sectors in our defense business and also lead our federal supply chain practice. That has afforded me the opportunity to work on everything from digital marketing, to supply chain analytics, warehouse modernization, immersive training, and cyber security. I love the freedom I’ve had at Accenture Federal Services to essentially run a business inside of a very large company, with access to so many exceptional resources and a lot of great people. I love bringing these capabilities to our clients.
Ok super. Thank you for all that. Let’s now shift to the main focus of our interview. Can you provide an example of a real-world incident where compromised integrity in the supply chain led to product security issues? How was the situation addressed, and what lessons can other organizations learn from that experience?
I think many of us have read about vulnerabilities in sectors like energy, critical infrastructure, and defense. There’s no doubt bad actors continue to develop sophisticated techniques to exploit weaknesses in supply chain technologies. As our world grows more connected, through the proliferation of sensors, IoT and smart and connected equipment, security can no longer be an afterthought. Organizations, particularly in the manufacturing or industrial equipment sectors, must reevaluate their enterprises and look to expand their security strategies and processes to protect their supply chain infrastructure.
Are there any regulatory frameworks or industry standards that address the importance of supply chain integrity in the manufacturing or industrial equipment sector? How can organizations align their practices with these standards to enhance product security?
Regulatory requirements or standards like the NIST SP 800–161(Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations) and the NIST Cybersecurity Framework are great places to start for organizations looking to enhance product security.
At the same time, we need to recognize that supply chain risk management goes beyond compliance or traditional risk management. It requires an understanding of avenues of exposure through downstream suppliers, vendor partners, and others, so that we can holistically apply cyber threat capabilities towards early prevention and rapid response.
More mature organizations need to be more proactive and explore the MITRE ATT&CK framework techniques like Supply Chain Compromise, Trusted Relationships, and Command and Control, to rapidly recognize risks or emerging threats, as they could be lying dormant within their enterprise and even the supply chain.
How does the concept of traceability tie into ensuring integrity in the manufacturing or industrial equipment supply chain? What role does it play in identifying potential security breaches or vulnerabilities?
You can’t secure what you don’t know. Supply chain traceability is a critical capability for enterprises looking to secure supply chain networks. An end- to-end traceability can massively help enhance the organization’s ability to identify the position and origin of individual units within the supply chain. That could bring all kinds of benefits to manufacturers, ranging from better regulatory compliance, to improved anti-counterfeiting, to near real-time inventory tracking and management.
An intelligence driven approach to understanding the adversary and their intent will guide the most effective means to proactively identifying supply chain vulnerabilities. Organizations should look at themselves from the outside in and all along their supply chain.
Are there any emerging trends or technologies in the manufacturing and industrial equipment sector that can help enhance product security and supply chain integrity? How can organizations leverage these trends to stay ahead of potential threats?
The World Economic Forum found that 20% of business leaders surveyed listed artificial intelligence and machine learning (AI / ML) as having the most significant influence on their cybersecurity-risk strategies during the next two years. Organizations should seek to understand how these technologies can enable end-to-end visibility, combined with real-time situational awareness, to secure the supplier ecosystem, manufacturing, technical systems, logistics, people, and processes without interfering with business requirements.

Ok, thank you. Here is the main question of our interview. What are the “5 Things We Must Do to Ensure Product Security in the Manufacturing or Industrial Equipment Sector?” and why?
- Quantify the cyber resilience of your supply chain by enabling early indications and warnings of compromise within your organization and critical third-party partners. Your partners’ risks are your risks. They must both be measured continuously.
- Develop a SCRM plan to further enhance and adapt to supply chain changes and emergent threats within your products and services.
- Conduct self-assessments using standards like NIST Cybersecurity Framework to identify best practices, as well as ineffective or missing security controls. As part of this self-assessment, identify your assets and ask yourself, where were these assets manufactured, how many are currently in the environment, have they reached obsolescence and are running on outdated firmware or software?
- Integrate threat intelligence technologies with monitoring and detection capabilities to proactively identify threats allowing you to isolate affected assets.
- Think holistically by creating a multi-disciplinary and central team to coordinate enterprise functions such as, supply chain management, converged IT/OT security operations center, human capital, and legal to drive a resilient supply chain.
You are a person of enormous influence. If you could inspire a movement that would bring the most amount of good to the most amount of people, what would that be? You never know what your idea can trigger. :-)
No meetings before 9 am so we don’t have to trade-off between sleeping and working out!
How can our readers further follow your work online?
You can follow my work online at LinkedIN and on the Accenture Federal Services Supply Chain website.
This was very inspiring and informative. Thank you so much for the time you spent with this interview!
About The Interviewer: David Leichner is a veteran of the Israeli high-tech industry with significant experience in the areas of cyber and security, enterprise software and communications. At Cybellum, a leading provider of Product Security Lifecycle Management, David is responsible for creating and executing the marketing strategy and managing the global marketing team that forms the foundation for Cybellum’s product and market penetration. Prior to Cybellum, David was CMO at SQream and VP Sales and Marketing at endpoint protection vendor, Cynet. David is a member of the Board of Trustees of the Jerusalem Technology College. He holds a BA in Information Systems Management and an MBA in International Business from the City University of New York.
David Leichner
Editor & Journalist · Authority MagazineEditor and journalist at Authority Magazine, sharing in-depth executive interviews, leadership insights, and empowering stories from world-class founders and creators.

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.
More from Authority Magazine
See all stories →Brandon Wade & Dana Rosewall on Why ‘Yes’ People are a Liability and the “Painful” 180-Degree Redemption Story
