Cyber threats targeting Industrial Control Systems (ICS) and Operational Technology (OT) environments are shifting rapidly away from traditional attack patterns. In the past, OT breaches relied heavily on deploying destructive malware via zero-day vulnerabilities. Today, global security authorities including CISA, MITRE, and SANS report a fundamental change in strategy. Threat actors are now bypassing complex exploit development, choosing instead to weaponise valid accounts and Living off the Land (LotL) techniques to blend in as legitimate operators.
According to the MITRE ATT&CK for ICS framework, the abuse of valid accounts (T1078) is now one of the most dominant initial access techniques. The rationale behind preferring credential theft over vulnerability exploitation is clear. Developing zero-day exploits requires immense resources and can be rapidly patched by defenders, whereas harvesting legitimate credentials requires minimal effort and effortlessly neutralises perimeter defences.
Once an attacker secures valid login details, perimeter security measures become entirely redundant. The system perceives the intrusion not as an attack, but simply as an authorised user establishing a normal session.
After breaching the network, threat actors rely heavily on LotL techniques. Rather than deploying external malware, they exploit legitimate administrative tools and scripts already native to the operating system or control environment.
Consequently, Security Operations Centre (SOC) analysts either receive no alerts at all or face severe alert fatigue as malicious actions disappear into a sea of routine operational traffic.
Most modern OT security frameworks focus heavily on identity and access control. Implementing MFA and regulating sessions through VPNs and privileged access management (PAM) solutions are essential foundational defences.
However, this session-based approach has a distinct structural flaw. Traditional access control solutions only authenticate the initial login approval at the IT/OT boundary. Once inside the network, they cannot verify the specific identity accessing individual endpoints.
When an attacker successfully initiates a session using stolen credentials, existing security appliances simply accept any subsequent actions. Whether the attacker modifies legacy PLC ladder logic or transmits critical control packets, the system processes it as a legitimate engineering task.
The current ICS threat landscape forces us to look beyond perimeter defence. The critical question is no longer just how to stop external breaches, but how to accurately identify and record the exact entity accessing individual endpoints within an authenticated session.
A one-time gateway authentication is insufficient to prevent the abuse of endpoint access disguised by valid credentials. True OT security must evolve past simple perimeter session verification. It must guarantee control privilege by flawlessly identifying the specific user and device at the endpoint access layer before a session is granted.
For global CISOs navigating the 2026 security landscape, the priority must shift from static account management. The ultimate goal is achieving access trust by securing an undeniable audit trail and absolute accountability before an endpoint session is established.
--------------------
swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.