Skip to main content
CybersecurityHacking

Zero Trust Bolsters Critical Infrastructure Against Identity Threats

Control room with industrial and technological elements, emphasizing security and access control.

"In May 2021, the Colonial Pipeline ransomware attack showed how quickly a compromised account can become a national issue." — Specops Software

Colonial Pipeline, an inactive VPN, and downstream national effects

The Colonial Pipeline incident in May 2021 is the cautionary touchstone in this account: attackers reportedly gained initial access through an inactive VPN account that lacked multi-factor authentication (MFA), moved into business systems including billing, and triggered a shutdown that disrupted fuel supply across the U.S. East Coast. The episode is cited here to show how compromise of a single account or business-system credential can cascade into broad, societal impact.

State-backed persistence and the modern attack playbook

The source warns that five years after Colonial Pipeline, critical infrastructure remains attractive to adversaries seeking more than data theft. U.S. agencies have warned that PRC state-sponsored actors have compromised and maintained access to critical infrastructure networks, in some cases for years. The report highlights Volt Typhoon as an example: Microsoft reported that group activity targeted communications, manufacturing, utilities, construction and transportation organizations in Guam and other U.S. locations, with concern not only about espionage but about persistent access that could support disruption in a future crisis.

The technical playbook described is familiar and effective: stolen administrator credentials and legitimate accounts; exploitation of vulnerable edge devices such as routers, firewalls, and VPN appliances; use of unmanaged devices and compromised laptops; session hijacking and remote access tools; and “living off the land” techniques that rely on built-in tools so activity appears routine. Attackers also route traffic through compromised devices to complicate attribution and detection. Verizon’s Data Breach Investigation Report is cited to quantify the credential problem: stolen credentials are involved in 44.7% of breaches.

CISA guidance, OT constraints, and why identity alone won’t suffice

CISA’s recent paper, Adapting Zero Trust Principles to Operational Technology, is invoked to show how zero trust thinking is being adapted to control environments. The source notes OT deserves tailored treatment because safety, uptime, legacy systems and physical processes make it trickier to apply typical IT security models. CISA’s guidance emphasizes asset visibility, identity and access management, segmentation, monitoring and supply chain risk.

At the same time, the piece argues identity—while central—cannot carry the full burden. MFA remains essential and every critical infrastructure organization should use it, the source says, but MFA can fail when attackers compromise sessions, enroll rogue devices, exploit trusted remote access paths, or use legitimate accounts from unmanaged endpoints. The result: stronger access decisions must consider signals beyond username and password.

What this means for security teams, operators, and procurement leaders

  • Security teams and technologists: Treat workforce access as a practical starting point for zero trust. Enforce policies that check device posture—known, trusted, healthy, encrypted, updated and compliant—before granting access, and make access adapt to user context and resource sensitivity.
  • OT operators and on-site engineers: Recognize the operational limits CISA notes—safety and uptime constraints and legacy systems—so changes must be staged and tailored rather than wholesale replacements. Strengthening workforce access controls offers a less disruptive lever than immediate OT redesign.
  • Procurement and enterprise leaders: Prioritize visibility and controls that include unmanaged “shadow IT” and third-party devices; demand solutions that can pin users to approved devices and offer remediation pathways that avoid interrupting critical workflows.

Device-bound identity and the vendor pitch: capabilities described

The source advances device-bound identity as a core mitigation: binding each identity to a verified physical device raises the bar beyond stolen credentials. The vendor discussed — Specops Device Trust — is described as providing phishing-resistant authentication that ensures users can only log in from approved, trusted devices; continuous device posture checks at every access request; visibility into managed and unmanaged devices; controls to limit the number of authorized devices per user; and a remediation toolkit with grace periods to let users update devices without killing productivity.

Taken together, the pieces in this account argue a focused, workforce-centered approach to zero trust—one that binds identities to devices and enforces device health at each access point—offers a practical, measurable step critical infrastructure organizations can take now, even as OT-specific challenges require tailored CISA-informed approaches. The essential question the report leaves in focus is operational: how to balance device-bound enforcement with safety, uptime and legacy constraints in real-world control environments.

Original story: https://www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/