Five Things Mining Companies Can Do Now to Build Operational Resilience
The mine plan tells you how the mine is supposed to operate. Operational resilience asks a different question: What could stop it and how do we keep running when something does?
8/12/20264 min read
That question is becoming more important as mining operations become increasingly dependent on connected equipment, remote monitoring, vendor access, telemetry, communications infrastructure, software and automated systems. Equipment that was once primarily mechanical may now have firmware, credentials, network connectivity, data dependencies and a third-party support relationship behind it.
I saw the growing attention to this issue recently at Black Hat USA. One of my strongest impressions wasn't a new exploit. It was demand. Several of the policy and OT-oriented discussions I attempted to attend were already full, including one with roughly 50 people waiting. That interest was also visible in the agenda: roughly one-quarter of the substantive briefings touched policy, cyber-physical systems, or defense and resilience.
But for smaller and mid-cap mining companies, the answer should not necessarily be to build a larger cybersecurity program.
The more useful objective may be much more targeted: Understand the operational dependencies that determine whether the mine can continue producing.
That means looking beyond traditional IT systems. Modern operations increasingly incorporate connected or digitally managed equipment across production, maintenance, safety, environmental monitoring, communications and logistics. Even relatively ordinary industrial assets are becoming instrumented, remotely monitored or dependent on software and third-party support.
The resilience question is, therefore, what happens to the operation if this system or something it depends on is suddenly unavailable?
Here are five places mining companies can start.
1. Know What Is Actually Connected
Start with visibility and build an inventory of assets and equipment connected to the network. Ask: What equipment communicates with another system, vendor, network or cloud platform?
That inventory should extend beyond traditional servers and workstations to operational and safety equipment: control systems, sensors, telemetry, fleet systems, environmental monitoring, communications equipment and remotely supported machinery.
The age-old truth is that you cannot protect what you cannot see. So, let’s update it; you cannot evaluate the resilience of an operation if you do not know what it depends on.
2. Identify the Dependencies Behind Critical Operations
Look at almost any connected piece of equipment and you quickly realize that very little operates alone.
Map what critical systems and processes actually depend upon. A simple flow diagram showing connections and how information travels can be extremely useful. Consider:
power
communications
software
credentials
cloud platforms
replacement parts
specialized personnel
vendor support
remote access
network infrastructure
Then work backwards from the critical operational process and ask what must remain available for production to continue.
This is often where organizations uncover single points of failure that may not appear prominently in a traditional cyber-risk assessment.
A sophisticated processing operation can still depend on one communications link, one integrator, one supplier, or one employee who understands a legacy system.
Those are technology dependencies, but they are also operational risks.
3. Put Vendor Access Under the Microscope
Mining operations depend heavily on OEMs (Original Equipment Manufacturers), integrators and specialist suppliers, that makes third-party connectivity one of the most important areas for operators to understand. Remote support is often necessary, particularly at geographically dispersed or remote mine sites. The goal does not have to be to eliminate remote support. The goal is to understand exactly where that access exists and what it can reach.
Ask:
Who can remotely access operational systems?
What can their account reach?
Who controls the credentials?
Does access remain active when nobody is servicing the equipment?
What happens if the vendor itself is compromised?
How often are access rights reviewed or changed?
The objective is simple:
Know where the doors are, who has the keys, and what sits behind them and remember that vendor risk is broader than a cyberattack. A supplier could experience its own outage, lose key personnel, discontinue support, suffer a cloud-service disruption or simply become unavailable when the mine needs assistance.
Any one of those events can become an operational problem.
4. Test Whether the Mine Can Operate Without the Technology
This may be more important than it sounds. If a critical monitoring system, vendor connection, communications network or automated capability disappeared tomorrow:
Can the operation continue safely?
For an hour?
A shift?
A day?
What becomes manual?
Who makes the decision?
What information would operators lose?
What stops first?
What must be restored first?
Business-continuity documentation may say the organization can recover. Testing that assumption in an operational exercise is something entirely different.
The exercise may uncover uncomfortable answers, but that is much better than discovering them during a real high-stakes disruption.
It is also important to remember that the original incident may not be what causes the most damage. The greater operational impact can come from the downstream consequences: one unavailable system affects another process, which affects another dependency, which eventually interrupts production.
Things rarely happen in isolation. Operational resilience requires looking at the ripple effect.
5. Bring Operational Resilience Into Management Decisions
Operational resilience should not live exclusively inside IT or a conversation with a few key people. Management should understand the technology and infrastructure dependencies capable of materially affecting production. For a mining company, that conversation can sit alongside familiar operating risks:
power availability
water
equipment reliability
permitting
workforce
supply chain
weather
logistics
Technology dependency is increasingly intertwined with every one of them.
One useful management question is: “What are the five technology or infrastructure failures most capable of interrupting production, and what is our recovery plan for each?”
Getting operations, technology, finance, risk, safety, maintenance and management into the same conversation can be particularly valuable because each group sees the operation differently.
That diversity of thought matters.
What We're Thinking at Sturnella
Black Hat reinforced something I've been seeing elsewhere: the boundaries between cybersecurity, operational resilience, critical infrastructure and national security are becoming harder to draw.
The interesting signal wasn't simply that government officials were present. It was the subject matter around them: cyber resilience, operational technology, supply-chain risk and disruption. For mining companies, however, becoming more resilient does not require waiting for the next generation of AI-enabled security technology.
Start somewhere much simpler. Know what you depend on, what can stop you, how long you can operate without it, and know what you would restore first.
A mine can have an excellent orebody, a credible mine plan and compelling commodity economics. None of those things, by themselves, guarantee that the operation is resilient.
You measured the orebody. Did you measure whether the mine can operate?
Sturnella advises defense contractors, mining, energy, and critical infrastructure companies on CMMC readiness, SEC cybersecurity disclosure, and board-level cyber governance.
contact@sturnellahq.com | sturnellahq.com | news.sturnellahq.com
Disclaimer: This article appeared on the Sturnella website at sturnellahq.com and is provided for informational purposes only. It does not constitute investment advice, financial advice, legal advice, or a solicitation to buy or sell any security or financial instrument. The information contained herein is based on publicly available sources and is believed to be accurate at the time of publication but is not guaranteed. Sturnella LLC is a capital markets cybersecurity and governance advisory firm and is not a registered investment adviser, broker-dealer, or financial institution. Always consult a qualified financial, legal, or investment professional before making any investment decision.
Contact
Reach out for discreet advisory support
contact@sturnellahq.com
Sturnella LLC © 2026 All rights reserved.
Independence
Governance Precision
Discretion
Capital Markets Alignment
Accountability