Securing Critical Infrastructure by Closing Identity Gaps

▼ Summary
– The Colonial Pipeline ransomware attack in May 2021 exploited an inactive VPN account without multi-factor authentication, disrupting fuel supply across the U.S. East Coast.
– State-backed actors like Volt Typhoon target critical infrastructure for persistent access, using stolen credentials and “living off the land” techniques to avoid detection.
– Zero trust is essential for critical infrastructure, but identity alone is insufficient; organizations must evaluate additional trust signals beyond usernames and passwords.
– Workforce access controls should bind identity to device health, ensuring access is granted only from known, trusted, and compliant devices.
– Specops Device Trust helps enforce zero trust by requiring users to log in from approved devices, verifying device posture, and providing visibility into all network-connected devices.
The Colonial Pipeline ransomware attack of May 2021 remains a stark reminder of how a single compromised account can escalate into a national crisis. Attackers reportedly gained initial access through an inactive VPN account lacking multi-factor authentication (MFA), struck business systems including billing infrastructure, and forced a shutdown that crippled fuel supplies across the U.S. East Coast.
Half a decade later, the lessons from that incident carry even greater weight. Critical infrastructure is a prime target because disruption generates pressure that extends far beyond the breached organization. Today, that pressure intensifies as state-backed actors seek persistence inside these networks, not merely to steal data but to maintain access that could be weaponized in a geopolitical crisis.
The attack methods remain familiar: stolen credentials, unmanaged devices, compromised laptops, remote access tools, and weak access controls. The zero trust security model has evolved from a buzzword into an operational necessity for organizations delivering essential services.
The Identity Threat Hitting Critical Infrastructure
Technology advancements have made systems increasingly interconnected. Reflecting this shift, CISA recently published guidance titled Adapting Zero Trust Principles to Operational Technology. While focused on operational technology (OT) environments, the core warning applies across all critical infrastructure: implicit trust introduces unacceptable risk.
OT environments require careful, tailored treatment. Safety, uptime, legacy systems, and physical processes make it difficult to apply standard IT security models in control environments. CISA’s guidance acknowledges this, emphasizing asset visibility, identity and access management, segmentation, monitoring, and supply chain risk.
But OT is not the only exposure point. Essential services also depend on IT systems, cloud platforms, and SaaS applications. As the Colonial Pipeline attack demonstrated, compromising business-critical systems can be just as damaging as breaching OT.
How Attackers Break In and Stay Hidden
The tactics of groups like Volt Typhoon illustrate why critical infrastructure leaders must rethink trust. This group specifically targets critical infrastructure, using techniques designed to blend into normal network activity rather than trigger obvious alerts.
U. S. agencies have warned that PRC state-sponsored actors have compromised and maintained access to critical infrastructure networks, in some cases for years. Their methods are familiar but effective: exploit vulnerable edge devices such as routers, firewalls, and VPN appliances; use stolen administrator credentials and legitimate accounts; and rely on “living off the land” techniques that use built-in tools instead of malware to make activity appear routine. They also route traffic through compromised devices to hinder attribution and detection.
In Guam and other U. S. locations, Microsoft reported Volt Typhoon activity against communications, manufacturing, utilities, construction, and transportation organizations. The concern was not just espionage, but the possibility that persistent access could support disruption during a future geopolitical crisis.
Implementing Zero Trust: Why Identity Alone Isn’t Enough
Zero trust provides a key defense against these attacks. However, while identity is central to zero trust, it cannot carry the full burden alone. State-backed actors are skilled at stealing credentials, phishing users, hijacking sessions, and using legitimate tools to move quietly through networks.
Multi-factor authentication (MFA) remains essential, and every critical infrastructure organization should deploy it. But MFA is not a complete solution if attackers can compromise a session, enroll a rogue device, exploit a trusted remote access path, or use a legitimate account from an unmanaged endpoint. Organizations providing essential services need stronger access decisions that go beyond the username and password to evaluate other trust signals.
Why Workforce Access Is a Good Starting Point
Most critical infrastructure organizations cannot redesign OT overnight. They cannot quickly replace every legacy system, remove every third-party dependency, or rework decades of operational complexity without introducing new risks. But they can strengthen how employees access critical applications, data, and systems.
Workforce access controls sit at the intersection of identity, endpoint security, and policy enforcement. They help security teams move beyond asking, “Is this the right user?” to also ask, “Is this the right user, on the right device, under the right conditions, for this specific resource?” Binding each identity to a device is key. It helps ensure access is not granted solely because someone has a password, token, or approved session. Before allowing access, security teams can check whether the device is known, trusted, healthy, encrypted, updated, and compliant. For critical infrastructure, this is a practical step toward zero trust: reducing implicit trust at the point where people connect to the systems the organization depends on.
Closing the Gaps in Zero Trust
The challenge of implementing zero trust is that workforces are no longer confined to a single site or network. Both onsite and remote workers need reliable access to sensitive systems, but their devices vary widely in security posture. For example, an engineer may work onsite using a managed laptop with encryption, current patches, and endpoint protection. An employee in the finance department might work remotely using a personal, unmanaged device. They both need access but have very different risk profiles.
A zero trust workforce access model should enforce that difference, with policies requiring a certain level of health for all devices. Access should adapt based on device posture, user context, and the sensitivity of the resource. This reduces dependence on network location as a trust signal and limits the blast radius if a device or account is compromised.
Strengthen Access Decisions with Specops
The security of identity systems is crucial for resilient critical infrastructure. Specialized solutions like Specops Device Trust help address this challenge. Attackers may be able to steal credentials, but it is far harder to steal a verified physical device. By binding identities to specific devices, Specops Device Trust helps organizations enforce zero trust at every access point.
The solution provides phishing resistant authentication to prevent account takeovers by ensuring users can only log in from approved, trusted devices. It offers zero device trust by verifying device posture at every access request and checking for active threats, disabled security controls, or outdated software throughout sessions. It delivers full visibility into every device accessing the network, including managed corporate devices and unmanaged shadow IT, with controls to pin users to a specific number of authorized devices. Finally, a remediation toolkit allows users to fix issues without calling the service desk, including grace periods to let them update devices without killing productivity.
Critical infrastructure organizations need robust security controls to defend against increasingly sophisticated attacks. If you’re interested in seeing how Specops solutions can help you achieve stronger identity security, contact us today.
Sponsored and written by Specops Software.
(Source: BleepingComputer)




