Your OT Network Was Never Meant to Touch the Internet — So Why Do Your Vendors Have Keys to It?
TL;DR
- OT networks were designed for physics, not packets — and remote vendor access is what dragged them onto the internet.
- The targeting is documented (Volt Typhoon pre-positioning with five-plus-year dwell; ransomware groups hitting industry jumped from 80 to 119 in a year) and the regulatory clocks are concrete.
- The fix is the connection layer: outbound-only, concealed access with closed inbound ports — not another firewall, and definitely not a rip-and-replace of the plant.
How the Plant Got Online
Every plant has a moment when its network stops being private. It’s rarely a decision — more a sequence of small, reasonable concessions: the SCADA vendor needs to dial in to troubleshoot an HMI, a field technician needs remote access to commission a new PLC, the operations center wants telemetry from every substation, the smart-grid program requires distribution data on shared networks. Each is defensible in isolation. Together they turned a system built for one purpose into a node on the public internet.
The uncomfortable fact is that OT networks were never designed for connectivity. Control systems run on protocols older than the engineers who maintain them, engineered around deterministic timing and physical safety — not authentication, segmentation, or audit trails. Most plants run flat Layer 2 with no inventory of what’s attached, because nobody ever expected a remote connection. When that expectation changed, the industry didn’t redesign anything. It bolted connectivity on top.
And the most common bolt-on is vendor access. When a PLC vendor says it needs to reach the controller to fix an alarm, the plant manager doesn’t call a security architect — in most small utilities, there isn’t one. The integrator opens a port, the vendor’s remote support tool connects, and a standing relationship is born: a third party with a credential and a path into a network never designed to distinguish friend from attacker.
That’s the pattern worth being honest about. It didn’t happen because plant operators are careless — vendor access was the path of least resistance, and nothing in the original design accounted for the internet existing at all. You can’t patch your way out of a design assumption. You have to change how connections are made.
The Evidence It’s Being Targeted
If the target’s intentions were ever in doubt, the intelligence community settled it. CISA advisory AA24-038A documents Volt Typhoon pre-positioning inside US communications, energy, transportation, and water/wastewater IT networks — specifically to enable disruptive lateral movement into OT. Not to steal data. To sit, wait, and hold the keys for a disruption, with dwell times of five-plus years per the advisory.
Why does that matter? Because the entry points for that lateral movement are the connections I just described. A vendor portal, an RDP jump box, a VPN concentrator on the perimeter — those are the doors an adversary with time and patience walks through. Volt Typhoon didn’t defeat a smart-grid mandate to reach OT. It got in through the IT edge and the vendor channel, then moved sideways into the control network.
The ransomware picture is worse than the headlines suggest. The Dragos 2026 OT Year in Review counts 119 ransomware groups targeting industrial organizations in 2025, up from 80 the year before, with roughly 3,300 organizations affected globally. That’s not the same players attacking more — it’s more players deciding the sector is worth their time.
Now put the scale next to the defender. There are roughly 170,000 US water/wastewater systems per the GAO, about 3,000 electric distribution utilities per the EIA, and more than 300 ports per MARAD. Most are small operations. A utility serving 10,000 people faces the same attacker economics as a Fortune 500 utility with a fraction of the headcount, budget, and tooling. That’s not a niche problem. That’s the bulk of critical infrastructure.
The Regulatory Clock Is Ticking
The regulators figured this out before most operators did, and they’re converting concern into deadlines — the mandates are now a calendar.
NERC CIP is the template everyone else copied: CIP-005 defines the electronic security perimeter and what crosses it, and CIP-013 forces bulk power entities to vet third parties that touch their systems — including vendors with remote access. Pipeline operators answer to TSA’s Pipeline Security Directive Pipeline-2021-01G, reissued in January 2026; the agency is not letting it age out. Ports and vessel operators are under the USCG’s Cybersecurity in the Marine Transportation System rule, in force since July 2025, with assessments due by mid-2027. And CIRCIA, delayed twice, is expected to finalize in September 2026 — so a covered operator hit by an incident won’t get time to decide whether to disclose.
There’s a telling gap in the water sector. The America’s Water Infrastructure Act requires risk assessments for systems serving more than 3,300 people, but the EPA has no statutory authority to mandate cybersecurity. Water gets the assessment requirement without the enforcement, while pipelines, the power grid, and the ports get binding rules. The result is the same spend pattern: every regime demands evidence of control around remote access, third-party connections, and the perimeter — exactly the layer bolted on a decade ago without security in mind.
Here’s the honest read. Compliance deadlines force spend, and most of it goes to paperwork, assessments, and boxes that generate audit evidence. None of it changes the fact that the plant’s doors are open. If you’re spending on the connection layer this quarter because the regulators demand it, spend on something that removes the exposure — not something that just documents it.
The Jump-Box Problem
Walk into most plants and you’ll find the same architecture: a VPN concentrator at the perimeter, a jump box in a DMZ, and a list of vendor credentials living somewhere between an email thread and a spreadsheet. The jump box was the compromise meant to give vendors access without giving them the plant. In practice, it’s the most targeted device in the building.
Exposed RDP and VPN gateways at industrial sites are a known, scanned attack surface. Adversaries don’t need internal knowledge; they just need to find the gateway, which is trivial when the plant’s external IP range has held for a decade. Once in, the jump box gives them privileged access into the control network, and the vendor accounts on it are exactly what an attacker needs for quiet lateral movement. That’s the documented anatomy of Volt Typhoon’s approach to OT.
Small plants make this worse. A plant with no SOC, no 24/7 monitoring, and one IT person — or an integrator on retainer — cannot watch a gateway open to the world. The multi-year dwell times in the advisory aren’t a detection failure at scale. They’re infrastructure nobody is watching, because nobody has the headcount.
And there’s an operational trap that guarantees the worst design persists. When a process is down and the vendor needs in now, review is skipped, credentials get shared over the phone, and the RDP port opens with the expectation it’ll close when the vendor is done. It never is. I’ve lost count of how many plants run on that promise. The jump box isn’t a security control; it’s a convenience with a casualty count.
What to Deploy Instead
The principle that fixes this fits on a whiteboard: nothing should reach the plant that the plant didn’t reach out to. That means outbound-only connections with closed inbound ports — the plant initiates, and there’s no listening service to scan, enumerate, or exploit. It also means concealing the endpoint itself. If a connection’s existence, endpoints, and attribution are hard to observe, it can’t be targeted the way an IP on your perimeter can.
That’s the argument for network-layer obfuscation, and it’s not exotic theory. SecureCo, “A Quantum Network Company,” builds its whole product line on exactly this premise — hiding the connection rather than just encrypting it, which secureco.com describes as “the security of a dedicated line in a cost-efficient software solution.” For the plant’s problem, the relevant pieces are STRATUS, the underlying platform, and CONDUIT, the tunnel product built on it.
CONDUIT is an always-on tunnel between corporate sites, data centers, clouds, or application-stack layers, with evasive routing, data anonymization, and concealed endpoints — “dedicated line-level security for VPN pricing.” For vendor access and site-to-site links, it’s a data-diode-adjacent alternative to the exposed jump box: the vendor reaches a rendezvous the attacker can’t see, not a public IP on your perimeter. Underneath, STRATUS routes evasively over a distributed mesh — random ephemeral circuits of three or more hops, layered onion-style encryption, decoy chaffing data, rotating IP ranges, and a virtual rendezvous system (US Patent 11,088,996) — with outbound-only connections, closed inbound ports, FIPS-approved ECC and AES, and zero-trust least privilege.
This isn’t fringe. Dr. Ed Amoroso’s TAG Cyber recommends stealth and obfuscation technology in enterprise cyber defense, and the approach was featured in The Hacker News 2025 Cybersecurity Report. The use cases map directly onto the plant’s problems: cloaking remote access so vendor sessions aren’t an attack surface, eliminating perimeter endpoints scanned daily, and reducing the communications signature that makes critical infrastructure stand out.
A Realistic Roadmap for Small Operators
If you’re a small utility, a co-op, or a mid-sized plant: don’t buy a platform that needs a team to run, and don’t rip-and-replace the network you’ve spent a decade stabilizing. Fix the door, not the house.
Start with vendor access. It’s your highest-risk connection, and the one you can change without touching the process network’s architecture. Put your SCADA and PLC vendors on a CONDUIT tunnel instead of their VPN or your jump box. They get what they actually want — reliable, fast remote access — and you remove the exposed gateway from your perimeter. That one change does more for your risk than a year of compliance paperwork.
Then pilot it. secureco.com runs 30-day, 60-day, and custom proof-of-concept programs, and deployment is deliberately unglamorous: CI/CD for the cloud side, app stores and MDMs for laptops, a lightweight agent for IoT endpoints, and a mobility SDK if you need remote workers. Nothing requires standing up a SOC you don’t have. If the pilot doesn’t prove itself in 60 days, you’ve lost nothing — exactly how a plant with no headcount should evaluate security purchases. There’s no published pricing to shop against, so use the PoC as your discovery process.
The product family is bigger than the plant use case. CONNECT offers cross-platform apps and SDKs positioned as a “High Security VPN Replacement” with hidden network endpoints, plus a lightweight agent for IoT — useful when you’re the one accountable for connected devices you didn’t buy. The same platform that conceals your vendor access can cloak remote access for your own team, eliminate attack surface on the corporate side, and shrink the communications signature across the utility’s network.
The roadmap fits on a page: vendor access on CONDUIT this quarter, a 30- or 60-day PoC validated against your real vendors and field technicians, expansion to site-to-site links and telemetry as it earns trust, and a rule you never break — no new inbound ports, ever. The plant was never designed for the internet, and that won’t change. But the connection layer is the one thing you control — and the one thing the attackers and the regulators are both watching.