Operating an operational technology infrastructure under the assumption of complete air gapping is now an outdated myth. According to threat analysis by CISA and global cybersecurity authorities, compromised credentials now represent one of the most prevalent attack vectors in industrial cyber incidents, surpassing complex malware injection. As smart manufacturing and vendor remote access become standard operational requirements, facility managers routinely deploy virtual private networks and firewalls to secure their perimeters. However, these traditional boundary defences suffer from a fatal structural flaw in that they grant implicit trust to any traffic once inside the network.
This challenge is exacerbated by a severe shortage of dedicated on-site security personnel, which forces facilities to grant excessive remote access privileges to third-party vendors without continuous oversight. Recent field surveys across municipal water and power utilities revealed thousands of industrial programmable logic controllers directly or indirectly exposed to the internet without robust identity verification. Unmanaged credentials and loose remote pathways provide the easiest entry point for adversaries, acting as a ticking time bomb once inside the firewall.
Invasions via remote access paths are uniquely dangerous because no resistance mechanism exists between the internal network and the execution endpoints. Traditional authentication relying on static usernames and passwords completely fails once credentials are leaked, handing full control of the associated account over to the adversary. The lack of regular credential rotation or auditing caused by staffing shortages further escalates this systemic risk.
Standard industrial protocols like Modbus or DNP3 used during remote maintenance do not contain malicious payloads in their packet syntax. When an attacker uses hijacked legitimate credentials to issue standard protocol commands that close valves or halt pumps, perimeter monitoring tools fail to flag any anomaly. This explains why numerous critical infrastructure facilities equipped with multi-million pound network security solutions fall victim to a single line of malicious control commands disguised as legitimate traffic.
To overcome these structural vulnerabilities, international frameworks—ranging from NIST SP 800-82 and IEC 62443 standards to the EU NIS2 directive—strongly demand a strict separation between network access authorization and command execution rights. Even if operational realities force organizations to grant remote access to third-party vendors, passing through a virtual private network or firewall must never grant implicit permission to issue control commands to physical controllers.
The core objective is to move beyond primary authentication at the network tunnel level and enforce an independent identity re-verification mechanism right at the execution endpoint. Even if a user enters through an encrypted tunnel as a legitimate engineer, adding an identity verification layer directly before the programmable logic controller acts on a command is essential to proactively prevent infrastructure hijacking via stolen credentials.
Implementing absolute identity verification independent of network pathways requires an authentication mechanism tailored to operational technology constraints. Legacy controllers in closed offline environments cannot support heavy multi-factor authentication solutions that require real-time server connectivity or external database lookups, nor do facilities have the manpower to manage them.
The most practical resolution is deploying unidirectional dynamic authentication codes right in front of the execution endpoint, generating unique and non-reusable credentials even in completely offline environments. Eliminating static passwords in favour of a network-less dynamic authentication layer ensures that even if remote access credentials are compromised, an attacker cannot generate the valid one-time code required to move the controller. Dispelling the myth of air gapping and placing a dynamic identity lock directly before command execution provides a resilient foundation for securing critical infrastructure in the remote maintenance era.
--------------------
swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.