Closing the Identity Gaps in Critical Infrastructure Security
The Colonial Pipeline ransomware attack in 2021 highlighted the vulnerability of critical infrastructure to cyber threats. Five years later, the lessons learned from this attack are more relevant than ever, as state-backed actors seek to disrupt critical infrastructure ne…
Intelligence analysis by Llama

The article discusses the importance of implementing zero trust in critical infrastructure security, particularly in the wake of the Colonial Pipeline ransomware attack. It highlights the need to rethink trust and reduce implicit trust at the point where people connect to systems. The article also emphasizes the importance of strengthening workforce access controls and using multi-fac…
Imagine you have a big house with many rooms. Each room has a lock, and the key is your password. But what if someone finds a spare key and uses it to get into the house? That's what's happening with critical infrastructure. Hackers are finding ways to get into the systems that control things like power and water. To fix this, we need to make sure that only the right people can get into the systems, and that they're using the right tools. This is called zero trust, and it's like having a super-secure lock on the front door.
Analysis
The Identity Threat Facing Critical Infrastructure
Advancements in technology mean that systems are increasingly interconnected. Reflecting this change and new challenge, CISA recently published guidance in the paper Adapting Zero Trust Principles to Operational Technology. While the paper focuses on operational technology (OT) environments, its central warning applies across critical infrastructure: implicit trust creates unacceptable risk.
OT deserves careful, tailored treatment. Safety, uptime, legacy systems, and physical processes make it trickier to apply typical IT security models in control environments. CISA's guidance reflects that reality, with emphasis on asset visibility, identity and access management, segmentation, monitoring, and supply chain risk. But OT is not the only place where critical infrastructure is exposed. Essential services also depend on IT systems, cloud platforms, and SaaS applications. As the Colonial Pipeline attack demonstrated, compromising business-critical systems can cause just as much damage as breaching OT.
How Attackers Break In and Stay Hidden
The tactics of threat actors like Volt Typhoon show why critical infrastructure leaders need to rethink trust. The group specifically targets critical infrastructure, using techniques designed to blend into normal network activity rather than trigger obvious alerts. U.S. agencies have warned that PRC state-sponsored actors have compromised and maintained access to critical infrastructure networks, in some cases for years. The tactics are familiar, but effective. Attackers exploit vulnerable edge devices such as routers, firewalls, and VPN appliances. They use stolen administrator credentials and legitimate accounts and rely on “living off the land” techniques, using built-in tools instead of malware, so their activity appears routine. They also route traffic through compromised devices to make attribution and detection harder.
Secure Your Active Directory Passwords
Verizon's Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. Effortlessly secure Active Directory with compliant password policies, blocking 6+ billion compromised passwords, boosting security, and slashing support hassles! Try it for free.
Implementing Zero Trust: Why Identity Alone Isn't Enough
Zero trust delivers a key defense against these types of attacks. However, while identity is central to zero trust, it cannot carry the full burden on its own. State-backed actors are skilled at stealing credentials, phishing users, hijacking sessions, and using legitimate tools to move quietly through networks. Multi-factor authentication (MFA) remains essential, and every critical infrastructure organization should use it. But MFA is not a complete answer if attackers can compromise a session, enroll a rogue device, exploit a trusted remote access path, or use a legitimate account from an unmanaged endpoint.
Organizations that provide essential services need stronger access decisions. That means looking beyond the username and password to evaluate other trust signals. Why Workforce Access is a Good Starting Point
Most critical infrastructure organizations cannot redesign OT overnight. They cannot quickly replace every legacy system, remove every third-party dependency, or rework decades of operational complexity without introducing new risks. But they can strengthen how employees access critical applications, data, and systems. Workforce access controls sit at the intersection of identity, endpoint security, and policy enforcement. They help security teams move beyond asking, “Is this the right user?” to also ask, “Is this the right user, on the right device, under the right conditions, for this specific resource?”
Binding each identity to a device is key. It helps ensure access is not granted solely because someone has a password, token, or approved session. Before allowing access, security teams can check whether the device is known, trusted, healthy, encrypted, updated, and compliant. For critical infrastructure, that is a practical step toward zero trust: reduce implicit trust at the point where people connect to the systems the organization depends on.
Key points
- The Colonial Pipeline ransomware attack in 2021 highlighted the vulnerability of critical infrastructure to cyber threats.
- State-backed actors are seeking to disrupt critical infrastructure networks, not just to steal data, but to hold access that could be used in a crisis.
- Zero trust offers a security model that is becoming an operational necessity for organizations that deliver essential services.
- Strengthening workforce access controls and using multi-factor authentication can help reduce the risk of cyber threats.
- Implementing zero trust requires a comprehensive approach that includes asset visibility, identity and access management, segmentation, monitoring, and supply chain risk.
If organizations implement zero trust security models and strengthen workforce access controls, they can reduce the risk of cyber threats and protect critical infrastructure. This could lead to increased confidence in the security of essential services and improved trust between organizations and their customers.
If organizations fail to implement zero trust security models and strengthen workforce access controls, they may be vulnerable to cyber threats and disruptions to critical infrastructure. This could lead to economic losses, damage to reputation, and decreased trust between organizations and their customers.



