The Colonial Pipeline ransomware attack in May 2021 highlighted the vast risks associated with compromised accounts, quickly escalating into a national emergency. The attackers gained initial access via an inactive VPN account that lacked multi-factor authentication (MFA), targeting critical business systems like billing infrastructure, which ultimately led to a significant fuel supply disruption across the Eastern United States.
Five years later, the implications of this incident resonate more than ever. Critical infrastructure systems are prime targets because their disruption creates extensive repercussions that reach beyond the affected organization.
The pressure is mounting as state-sponsored attackers increasingly target critical infrastructure networks. Their objective extends beyond data theft; they aim to maintain access for potential exploitation during crises.
Attackers employ common tactics like exploiting stolen credentials, using unmanaged devices, or targeting compromised laptops, remote access tools, and weak access controls. Zero Trust security models are quickly becoming indispensable for organizations that deliver essential services.
Identity Threats in Critical Infrastructure
Technological advancements have made systems more interconnected than ever. In response, CISA has released guidance on adapting Zero Trust principles to operational technology.
While this document focuses on operational technology (OT) environments, its key recommendations are applicable across all critical infrastructures. Implicit trust poses an unacceptable risk.
Operational technology demands careful and tailored handling. Factors such as safety, uptime, legacy systems, and physical processes complicate the application of standard IT security models in controlled settings. CISA emphasizes asset visibility, identity management, segmentation, monitoring, and supply chain risk management.
However, OT isn’t the sole vulnerability in critical infrastructure. Essential services also depend on IT systems, cloud platforms, and SaaS applications. As evidenced by the Colonial Pipeline attack, compromising business-critical systems can be just as detrimental as compromising OT.
How Attackers Gain Entry and Remain Undetected
Threat actors leverage various tactics, including those from Bolt Typhoon, which specifically targets critical infrastructure using techniques designed to blend with normal network activity, avoiding detection.
U.S. government agencies have identified that state-sponsored attackers, particularly from China, have compromised critical infrastructure networks, sometimes maintaining access for years.
This tactic is effective; attackers often exploit vulnerable edge devices such as routers, firewalls, and VPN appliances.
Employing “living off the land” strategies, they utilize stolen admin credentials and legitimate accounts, often opting for built-in tools instead of traditional malware.
They may also reroute traffic through compromised devices, obscuring their activities and making identification and detection more challenging.
According to Microsoft, Bolt Typhoon has been active in communications, manufacturing, utilities, construction, and transportation sectors across the U.S., creating concerns not just about espionage but also about the potential chaos in future geopolitical tensions.
Verizon’s data breach investigation report indicates that 44.7% of breaches involved stolen credentials.
Fortify your Active Directory with compliant password policies, block over 6 billion leaked passwords, enhance security, and significantly reduce support efforts.
Implementing Zero Trust: Why Identity Isn’t Enough
Zero Trust is a critical defense against these attacks. While identity plays a key role in this model, it cannot shoulder the entire burden.
State-sponsored attackers excel in stealing credentials, phishing users, hijacking sessions, and employing legitimate tools for lateral movement within networks.
While multi-factor authentication (MFA) is essential and should be adopted by all critical infrastructure organizations, it is not a foolproof solution when attackers can compromise sessions, register rogue devices, or misuse trusted remote access methods.
Organizations offering critical services must enhance access decisions by moving beyond traditional username/password methods to evaluate additional trust signals.
Enhancing Employee Access Control
Most critical infrastructure organizations can’t overhaul their operational technology overnight. It is unrealistic to replace all legacy systems or remove third-party dependencies without introducing new risks. However, enhancing employee access to critical applications, data, and systems is achievable.
Employee access control sits at the intersection of identity, endpoint security, and policy enforcement. This empowers security teams to ask not just, “Is this the right user?” but also, “Is this the right user on the right device, under the right conditions, for this specific resource?”
Binding each identity to a device is crucial. This ensures access isn’t granted merely based on possessing a password, token, or authorized session. Security teams should confirm that a device is known, trusted, healthy, encrypted, updated, and compliant before permitting access.
For critical infrastructure organizations, this is a practical step toward implementing Zero Trust and reducing implicit trust when users connect to vital systems.
Addressing the Zero Trust Gap
The challenge of implementing Zero Trust lies in the reality that employees access sensitive systems from various locations and networks. On-site and remote employees present differing device security postures, introducing additional risks.
For instance, engineers may work on-site with managed laptops, which are encrypted, updated, and equipped with endpoint protection, while finance employees may access systems remotely on personal, unmanaged devices. Both require access but come with significantly varying risk profiles.
A Zero Trust employee access model should enforce these differences through policies that mandate a certain level of device health. Access must adapt based on device status, user context, and resource sensitivity, minimizing dependency on network location as a trust signal and mitigating risks if an account or device is compromised.
Empower Access Decisions with Specops
A robust identity security framework is vital for resilient critical infrastructure. One such solution is Specops Device Trust. While attackers may steal credentials, it is significantly harder to compromise a verified physical device.
Specops Device Trust enables organizations to enforce Zero Trust across all access points by binding identities to specific devices.
This solution offers:
- Phish-resistant authentication: Protects against account takeovers by ensuring users log in only from authorized and trusted devices.
- Zero device trust: Validates the state of devices on every access request and checks for ongoing threats, disabled security controls, or outdated software.
- Complete visibility: Monitors all devices accessing your network, including both managed corporate devices and unmanaged shadow IT, with controls to limit users to a specific number of allowed devices.
- Repair toolkit: Allows users to resolve issues without contacting support, offering a grace period for device updates without hindering productivity.

Critical infrastructure organizations must implement robust security measures to protect against increasingly sophisticated cyber threats.
Interested in learning how Specops solutions can enhance your identity security? Contact us today.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


