Critical Infrastructure Under Siege: Closing Identity Gaps to Prevent Disruption
The 2021 Colonial Pipeline ransomware attack was a stark reminder of the devastating consequences of compromised accounts and lax security measures in critical infrastructure. The attackers, reportedly exploiting an inactive VPN account without multi-factor authentication (MFA), disrupted fuel supply across the U.S. East Coast, causing widespread disruptions and pressure on the affected organization.
Five years later, the lessons learned from Colonial Pipeline are more relevant than ever. Critical infrastructure remains a prime target for state-backed actors seeking to disrupt essential services during times of crisis. The threat landscape has evolved, with attackers now focusing on persistence within critical infrastructure networks, not just data theft, but also holding access that could be used in a high-pressure situation.
The initial attack path is familiar, involving the exploitation of stolen credentials, unmanaged devices, compromised laptops, remote access tools, and weak access controls. Zero trust has emerged as an operational necessity for organizations delivering essential services, offering a security model that can help mitigate these risks. However, the identity threat facing critical infrastructure goes beyond just implementing zero trust.
The increasing interconnectedness of systems has created new challenges for critical infrastructure leaders. CISA’s recent publication on adapting zero trust principles to operational technology (OT) environments highlights the need for tailored approaches in control environments. OT demands careful treatment due to its unique characteristics, such as safety, uptime, legacy systems, and physical processes that make traditional IT security models difficult to apply.
However, OT is not the only vulnerable area within critical infrastructure. Essential services also rely on IT systems, cloud platforms, and SaaS applications, which can be compromised with devastating consequences, as seen in the Colonial Pipeline attack. The tactics used by threat actors like Volt Typhoon demonstrate why critical infrastructure leaders must rethink trust.
Volt Typhoon specifically targets critical infrastructure, using techniques designed to blend into normal network activity rather than trigger obvious alerts. U.S. agencies have warned that PRC state-sponsored actors have compromised and maintained access to critical infrastructure networks for years. The tactics are familiar but effective: attackers exploit vulnerable edge devices, use stolen administrator credentials and legitimate accounts, rely on “living off the land” techniques, and route traffic through compromised devices to evade detection.
The concern is not only espionage but also the possibility that persistent access could support disruption during a future geopolitical crisis. Microsoft reported Volt Typhoon activity against communications, manufacturing, utilities, construction, and transportation organizations in Guam and other U.S. locations.
Implementing zero trust can help mitigate these risks, but it’s essential to recognize that identity alone is not enough. State-backed actors are skilled at stealing credentials, phishing users, hijacking sessions, and using legitimate tools to move quietly through networks. Multi-factor authentication (MFA) remains crucial, but it’s not a complete answer if attackers can compromise a session or exploit a trusted remote access path.
Critical infrastructure organizations must take a comprehensive approach to security, incorporating zero trust principles, asset visibility, identity and access management, segmentation, monitoring, and supply chain risk management. By closing the identity gaps in their systems, these organizations can prevent disruption and protect against the evolving threats facing critical infrastructure today.
As you implement or review your organization’s security measures, consider the following key takeaways:
* Multi-factor authentication (MFA) is essential but not sufficient on its own.
* Implement zero trust principles to limit access based on least privilege and enforce continuous verification.
* Regularly review and update access controls, including remote access tools and edge devices.
* Monitor for suspicious activity and invest in asset visibility solutions to detect potential threats.
* Prioritize supply chain risk management to mitigate the impact of compromised vendors or partners.
By taking a proactive approach to identity management and implementing zero trust principles, critical infrastructure organizations can reduce their vulnerability to attacks and ensure continuity of essential services.
Source: Bleeping Computer — 2026-07-21