Spend any time studying how critical infrastructure actually gets breached, and a pattern shows up: attackers typically log in using a password that leaked, a default that was never changed, or a remote account no one remembered to turn off. Then they issue commands that the equipment is perfectly happy to obey.
Artificial intelligence (AI) is now cutting both ways in this fight, and defenders should be honest about which way it cuts harder. AI compresses the time, cost and skill an attacker needs to find a target, craft an intrusion and move on it. A moderately capable actor becomes a sophisticated one, and there are more of them than there were a year ago. That is the real problem operational technology (OT) teams face: the crisis of time. You cannot patch your way out of it fast enough, so the smarter move is to take time back from the attacker by taking away the thing every one of these intrusions needs first: the ability to find and reach the target.
The Break-In That Isn't a Break-In
Look at the incidents that actually caused damage, and the entry point is almost always a legitimate one.
Colonial Pipeline shut down roughly 45% of the East Coast fuel supply in 2021. The initial access was a single leaked password on an inactive virtual private network (VPN) account with no multi-factor authentication (MFA). The attackers never touched the pipeline's control systems. Colonial halted operations because the information technology (IT) side was compromised, and it could not bill customers.
The CyberAv3ngers campaign against US water utilities in late 2023 compromised internet-facing Unitronics controllers that were still using the vendor default password “1111.” No exploit. Just a device anyone could find and a credential anyone could guess.
Volt Typhoon, the People's Republic of China state actor, has spent years inside US critical infrastructure using valid accounts and native system tools rather than malware, positioning for disruption during a future crisis. There is no signature to catch and no exploit to patch.
The common thread is trust. The attacker arrives as a legitimate user, over a remote path the plant depends on, and speaks to controllers over protocols that were never designed to authenticate anything. Our detection industry is built to find malicious code. When the intruder is a valid identity issuing valid commands, there is no malicious code to find.
Why Patching Alone Loses the Race
Patching is still critical and no one should stop doing it. But patching alone does not win this particular race, because AI keeps handing attackers the advantage. When the cost of finding and exploiting an exposed system keeps falling, the population of viable attackers keeps rising, and the window between a vulnerability becoming known and being used keeps shrinking. Defenders are left trying to close holes faster than an accelerating adversary can find them.
OT makes that math worse. Field devices live for 20 to 30 years and rely on protocols with no authentication by design. You cannot add MFA to a 1990s programmable logic controller (PLC). It will run a command from anyone who can reach it. So, the only durable question is who can reach it, and that is a question about access, not about patch cycles.
This is where the defense shifts from patching to access. If you cannot fix the underlying weakness on the timeline the attacker now operates on, you buy yourself time by hiding what is vulnerable while you remediate. An adversary cannot attack what it cannot find.
Take Away Discovery, and You Take Away the Attack
ZTNA starts one step earlier than most controls. Instead of trying to catch a bad command at the PLC or a bad login at the gateway, it removes the precondition every one of these intrusions relied on: the ability to see the target at all.
AppGate ZTNA uses Single Packet Authorization (SPA) to keep gateways and protected resources invisible to anyone who is not already cryptographically verified. An attacker scanning for exposed VPN endpoints, remote desktop ports or internet-facing controllers finds nothing to attack. The reconnaissance step that made Colonial, the water utilities and countless others possible simply returns empty. In OT specifically, that changes the picture in a few concrete ways:
A leaked or default credential is not enough to open a connection. SPA requires a cryptographically seeded device before any session is even visible, so a password pulled from another breach produces nothing.
Access is scoped to a specific resource, not the network. An engineer cleared to reach one historian cannot pivot to the controller in the next zone. The lateral movement that turns an IT foothold into an operational shutdown is closed off by design.
Vendor and third-party access runs through the same verification as everyone else, with session recording and the ability to revoke at any moment. The remote maintenance path stops being the soft way in.
Trust is evaluated continuously on identity, device posture and context, not granted once at login and forgotten.
This is not a workaround bolted onto OT. It is the control that federal cyber authorities point to directly. CISA's minimum-bar guidance for the compromised water utilities was to put a VPN or gateway in front of the controller to enforce MFA the device itself cannot support. ZTNA clears that bar and removes the exposed endpoint the VPN itself becomes. A VPN offers nothing once an attacker is past it. ZTNA still confines every session to a single resource. Controlling who can reach a device that cannot defend itself is one of the highest leverage moves available in OT, and it does not require re-architecting the plant.
Borrow the Playbook From the Hardest Environments
The organizations facing the most active and capable adversaries, in defense and national security, have already concluded that the right posture is to assume the adversary has gotten in and to design so that getting in is not the same as winning. That means self-contained architectures that do not hand your security over to a third party, controls that survive contact with a real attacker and access that is earned continuously rather than assumed. Civilian operators and commercial infrastructure face versions of the same adversaries, at similar scale, and can borrow that playbook rather than reinventing it.
You cannot make OT unhackable. No honest security leader promises that. Think of your network like a house. Every night, you lock the front door to keep intruders out. Nowadays, intruders have access to sophisticated lock-picks they can find online. Your next move is to make your front door invisible, and your room doors too, in case they climb through one of the windows. That's how you take away the attacker's easiest move. In a world where AI keeps making that easy move cheaper, removing it is the highest-value thing you can do. That is what Zero Trust Network Access delivers.
See how AppGate ZTNA secures OT remote access without re-architecting your environment. Schedule a demo.