Closing the Identity Gaps in Critical Infrastructure Security
In May 2021, the Colonial Pipeline ransomware attack demonstrated how quickly a compromised account can become a national issue. The attackers reportedly gained initial access through an inactive VPN account without multi-factor authentication (MFA), compromising business systems, including billing infrastructure, and triggering a shutdown that disrupted fuel supply across the U.S. East Coast.
Five years later, the lessons learned from Colonial Pipeline have more relevance than ever. Critical infrastructure is an attractive target because disruption creates pressure far beyond the breached organization. Today, that pressure is rising as state-backed actors look for persistence inside critical infrastructure networks, not just to steal data, but to hold access that could be used in a crisis.
The Identity Threat Facing Critical Infrastructure
Advancements in technology mean that systems are increasingly interconnected. Reflecting this change and new challenge, CISA recently published guidance in the paper Adapting Zero Trust Principles to Operational Technology. While the paper focuses on operational technology (OT) environments, its central warning applies across critical infrastructure: implicit trust creates unacceptable risk.
OT deserves careful, tailored treatment. Safety, uptime, legacy systems, and physical processes make it trickier to apply typical IT security models in control environments. CISA’s guidance reflects that reality, with emphasis on asset visibility, identity and access management, segmentation, monitoring, and supply chain risk.
How Attackers Break In and Stay Hidden
The tactics of threat actors like Volt Typhoon show why critical infrastructure leaders need to rethink trust. The group specifically targets critical infrastructure, using techniques designed to blend into normal network activity rather than trigger obvious alerts.
U.S. agencies have warned that PRC state-sponsored actors have compromised and maintained access to critical infrastructure networks, in some cases for years. The tactics are familiar, but effective. Attackers exploit vulnerable edge devices such as routers, firewalls, and VPN appliances. They use stolen administrator credentials and legitimate accounts and rely on “living off the land” techniques, using built-in tools instead of malware, so their activity appears routine.
Implementing Zero Trust: Why Identity Alone Isn’t Enough
Zero trust delivers a key defense against these types of attacks. However, while identity is central to zero trust, it cannot carry the full burden on its own. State-backed actors are skilled at stealing credentials, phishing users, hijacking sessions, and using legitimate tools to move quietly through networks.
Multi-factor authentication (MFA) remains essential, and every critical infrastructure organization should use it. But MFA is not a complete answer if attackers can compromise a session, enroll a rogue device, exploit a trusted remote access path, or use a legitimate account from an unmanaged endpoint.
Why Workforce Access is a Good Starting Point
Most critical infrastructure organizations cannot redesign OT overnight. They cannot quickly replace every legacy system, remove every third-party dependency, or rework decades of operational complexity without introducing new risks.
But they can strengthen how employees access critical applications, data, and systems. Workforce access controls sit at the intersection of identity, endpoint security, and policy enforcement. They help security teams move beyond asking, “Is this the right user?” to also ask, “Is this the right user, on the right device, under the right conditions, for this specific resource?”
Closing the Gaps in Zero Trust
The challenge of implementing zero trust is that workforces are no longer confined to a single site or network. Both onsite and remote workers need reliable access to sensitive systems, but the risk is that their devices vary widely in security posture.
A zero trust workforce access model should enforce that difference, with policies that require a certain level of health for all devices. Access should adapt based on device posture, user context, and the sensitivity of the resource.
This reduces dependence on network location as a trust signal. It also limits the blast radius if a device or account is compromised.
Critical infrastructure organizations need robust security controls to defend against increasingly sophisticated attacks. Solutions like Specops Device Trust can help enforce zero trust at every access point, providing phishing-resistant authentication, zero device trust, and full visibility into every device accessing the network.
- Phishing resistant authentication, preventing account takeovers by ensuring that users can only log in from approved, trusted devices.
- Zero device trust, verifying device posture at every access request and checking for active threats, disabled security controls, or outdated software throughout sessions.
- Full visibility into every device accessing the network, including managed corporate devices and unmanaged shadow IT, with controls to pin users to a specific number of authorized devices.
Verizon’s Data Breach Investigation Report found that stolen credentials are involved in 44.7% of breaches. Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles.
Critical infrastructure organizations need robust security controls to defend against increasingly sophisticated attacks. If you’re interested in seeing how Specops solutions can help you achieve stronger identity security, contact us today.
Source: BleepingComputer