Cybersecurity Best Practices: Why Credentials Alone Can't Protect Critical Infrastructure
The Colonial Pipeline shutdown wasn’t caused by a zero-day exploit. It wasn’t even a sophisticated piece of malware.
It was a dormant VPN account. No MFA. No monitoring. Just a forgotten credential, quietly waiting for someone to stumble on it.
That’s the brutal truth about critical infrastructure today: the most devastating breaches don’t come from the dark corners of the internet. They come from the places we stopped looking.
We’ve spent decades building firewalls, patching systems, and training users to spot phishing emails. But we’ve treated identity like a lock on a front door — something you hand out once and forget. The reality? Attackers aren’t breaking in. They’re walking through.
The Verizon 2026 DBIR says stolen credentials are involved in 44.7% of all breaches. That’s not a statistic. That’s a pattern. And in critical infrastructure — where a single compromised account can shut down fuel lines, water treatment, or power grids — that pattern is a death sentence waiting to be activated.
This isn’t about better passwords. It’s about rethinking trust.
CISA’s guidance on adapting zero trust to operational technology isn’t a suggestion. It’s a mandate. Zero trust doesn’t mean ‘trust no one.’ It means: don’t trust based on location, device ownership, or network segment. Trust must be earned — every single time.
The problem? We’ve been trying to apply IT security models to OT environments. That’s like trying to fix a steam engine with a smartphone app. The stakes are too high. The systems are too old. The consequences too visible.
So we do the only thing that works: we start at the edge. Not the network. Not the server. The person.
Because every breach starts with a human.
And if we can’t verify that human is who they say they are — and that they’re on a device we control — then we’re just giving attackers a key and hoping they don’t use it.
They will.
And they already have.
Volt Typhoon: The Ghost in the Machine
Five years.
That’s how long Volt Typhoon lived inside a U.S. critical infrastructure network before anyone noticed.
Not because they were clever. Not because they used exotic tools.
They used netsh. They used ntdsutil. They used PowerShell — the same commands your IT admin runs every Monday morning to check server health.
This is the terrifying elegance of modern cyber warfare: no malware. No signatures. Just living off the land. The attacker doesn’t need to plant a backdoor. They just need to borrow your keys and walk through the front door.
Microsoft’s analysis shows Volt Typhoon didn’t break in through a firewall. They exploited a Fortinet device — something many organizations leave exposed to the internet because it’s "just a router." Once inside, they extracted Active Directory credentials, then moved laterally like a ghost. No alerts. No noise.
They didn’t steal data to sell on the dark web. They didn’t encrypt systems for ransom.
They were building a foothold. For a crisis.
CISA, NSA, and the FBI confirmed with high confidence: Volt Typhoon’s goal isn’t espionage. It’s disruption. Pre-positioning for a moment when geopolitical tensions boil over. A blackout. A water shutoff. A transportation gridlock.
And they’ve been waiting.
The kicker? The FBI disrupted their KV-botnet — hundreds of compromised SOHO routers used to mask their traffic — in December 2023. But Volt Typhoon didn’t vanish. They just went quieter.
Because they don’t need to be loud.
They just need to be there.
And they are.
In communications. In energy. In water systems. In the very infrastructure that keeps our lights on and our fuel flowing.
The only thing stopping them from flipping the switch? The fact that we still think a password and MFA are enough.
Why MFA Isn’t the Answer — And What Actually Is
Multi-factor authentication feels like a win. It’s the security feature we all check off. We tell our teams: "Just enable MFA. You’re safe."
But MFA is a trap.
Attackers don’t need to crack your password. They don’t need to phish your token. They just need to compromise your session — or enroll a rogue device that’s already trusted.
I’ve seen it myself: a contractor logs in from a personal laptop. MFA is enabled. They’re approved. They’re "trusted." Then, six months later, that same device — now infected with a keylogger — becomes the pivot point for lateral movement.
MFA protects against one thing: password theft.
It doesn’t protect against device compromise. Session hijacking. Or a legitimate user with bad posture.
That’s why the real answer isn’t more factors. It’s context.
Can you answer this?
Is this the right user…
…on the right device…
…under the right conditions…
…for this specific resource?
If you can’t, you’re not practicing zero trust. You’re practicing wishful thinking.
CISA’s OT Zero Trust guidance lists identity and access management as a pillar — not because it’s trendy, but because it’s the only thing standing between a compromised account and a national emergency.
And that’s where device-bound identity comes in.
Not just "this user has a password." Not just "this user has a token."
But: "This user is on a device we control, patched, encrypted, and monitored."
Specops Device Trust — and others like it — don’t just verify identity. They verify posture. Every time. Every session. No exceptions.
Phishing-resistant? Yes.
Continuous monitoring? Yes.
Full visibility into shadow IT? Absolutely.
And if a user’s device is out of compliance? They get a self-remediation toolkit — not a locked-out account.
Because the goal isn’t to punish. It’s to protect.
And in critical infrastructure, that’s not optional. It’s survival.
Zero Trust Isn’t a Tool. It’s a Mindset.
NIST SP 800-207 doesn’t say "deploy MFA." It says: "Zero trust grants no implicit trust based on physical or network location."
That’s the core.
You can’t assume trust because someone is on the corporate network. You can’t assume trust because they’re using a company-issued laptop. You can’t assume trust because they’ve been here five years.
Every access request is a new threat assessment.
This isn’t just about IT. It’s about culture.
We’ve spent decades training people to think in terms of perimeters — the firewall, the VPN, the DMZ.
But those perimeters are gone.
Your engineers are working from home. Your contractors are using personal tablets. Your legacy SCADA systems are connected to the internet because someone needed remote access in 2012.
Zero trust forces us to ask harder questions.
Why does this person need access to this system?
What happens if their device is compromised?
Can we limit their access to just what they need — right now?
It’s not about control. It’s about containment.
If an account is stolen — and it will be — zero trust limits the blast radius. It doesn’t stop the breach. It stops the cascade.
And in critical infrastructure, that’s the difference between a service disruption… and a national emergency.
We’re not fighting hackers anymore.
We’re fighting complacency.
And the only thing that wins is relentless verification.
No exceptions.