Blog - swIDch

Stolen Credentials and OT Access Control Limits

Written by Admin | Aug 18 2026

 

Cyber threats targeting Industrial Control Systems (ICS) and Operational Technology (OT) environments are shifting rapidly away from traditional attack patterns. In the past, OT breaches relied heavily on deploying destructive malware via zero-day vulnerabilities. Today, global security authorities including CISA, MITRE, and SANS report a fundamental change in strategy. Threat actors are now bypassing complex exploit development, choosing instead to weaponise valid accounts and Living off the Land (LotL) techniques to blend in as legitimate operators.

 

The Shift Towards Stolen Valid Credentials

According to the MITRE ATT&CK for ICS framework, the abuse of valid accounts (T1078) is now one of the most dominant initial access techniques. The rationale behind preferring credential theft over vulnerability exploitation is clear. Developing zero-day exploits requires immense resources and can be rapidly patched by defenders, whereas harvesting legitimate credentials requires minimal effort and effortlessly neutralises perimeter defences.

    • IT and OT Convergence and Dark Web Leaks: Primary attack vectors include third-party VPN accounts lacking multi-factor authentication (MFA), credentials traded on the dark web, and OT domain administrator rights obtained via IT network breaches.
    • Hardcoded and Default Credentials: Default credentials left unchecked on ageing OT equipment and engineering workstations (EWS) remain highly vulnerable targets.

Once an attacker secures valid login details, perimeter security measures become entirely redundant. The system perceives the intrusion not as an attack, but simply as an authorised user establishing a normal session.

 

Concealing Threats Within Normal OT Traffic 

After breaching the network, threat actors rely heavily on LotL techniques. Rather than deploying external malware, they exploit legitimate administrative tools and scripts already native to the operating system or control environment.

    • Weaponising Legitimate Tools: Attackers hijack built-in Windows commands like PowerShell and WMI, alongside standard remote access protocols and native PLC engineering software.
    • The Blind Spot of NDR and IDS: Traditional network-based detection systems (NDR/IDS) and passive monitoring solutions look for anomalous traffic patterns or known malware signatures. Because LotL activities use standard ports and authentic protocols, they easily bypass these detection rules.

Consequently, Security Operations Centre (SOC) analysts either receive no alerts at all or face severe alert fatigue as malicious actions disappear into a sea of routine operational traffic.

 

The Gap Between Session Approval and Endpoint Access 

Most modern OT security frameworks focus heavily on identity and access control. Implementing MFA and regulating sessions through VPNs and privileged access management (PAM) solutions are essential foundational defences.

However, this session-based approach has a distinct structural flaw. Traditional access control solutions only authenticate the initial login approval at the IT/OT boundary. Once inside the network, they cannot verify the specific identity accessing individual endpoints.

When an attacker successfully initiates a session using stolen credentials, existing security appliances simply accept any subsequent actions. Whether the attacker modifies legacy PLC ladder logic or transmits critical control packets, the system processes it as a legitimate engineering task.

 

Advancing OT Security Towards Endpoint Access Authentication 

The current ICS threat landscape forces us to look beyond perimeter defence. The critical question is no longer just how to stop external breaches, but how to accurately identify and record the exact entity accessing individual endpoints within an authenticated session.

A one-time gateway authentication is insufficient to prevent the abuse of endpoint access disguised by valid credentials. True OT security must evolve past simple perimeter session verification. It must guarantee control privilege by flawlessly identifying the specific user and device at the endpoint access layer before a session is granted.

For global CISOs navigating the 2026 security landscape, the priority must shift from static account management. The ultimate goal is achieving access trust by securing an undeniable audit trail and absolute accountability before an endpoint session is established.

 

 

--------------------

 

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.