A technical analysis of convergence risks, identity-based attack vectors, and re-establishing cryptographic boundaries in industrial and building automation environments.

1. The Death of the Air-Gap (IT/OT Convergence)

For decades, operational technology (OT) and industrial control systems (ICS) existed in a state of splendid isolation. Protected by the legendary "air-gap," these networks relied on proprietary protocols and physical security to keep malicious actors at bay. Today, that air-gap is officially dead. Driven by the operational efficiencies of Industry 4.0, smart building initiatives, and predictive cloud-hosted analytics, organizations have connected their plant floors, environmental systems, and building automation architectures directly to corporate IT environments and the public internet.

Modern commercial buildings and industrial sites are no longer passive structures; they have evolved into complex, highly connected digital environments. A typical Building Management System (BMS) controls safety-critical and operational physical loops -including heating, ventilation, air conditioning (HVAC), automated lighting, physical access control, fire detection, and energy management. While integrating these systems with IT databases and Software-as-a-Service (SaaS) platforms delivers major cost savings and remote management capabilities, it also dramatically expands the organizational attack surface.

By merging traditionally isolated OT protocols with standard IT infrastructure, organizations have turned low-profile facilities equipment into highly accessible entry points. An attacker no longer needs physical access to a mechanical room to disrupt operations. Instead, a single internet-exposed device, an unpatched vulnerability, or a compromised corporate credential can grant access to the entire physical backbone of a facility.

2. The Identity Bridge and Initial Access Vectors

As IT and OT networks merge, the boundary separating them has shifted from a rigid physical network barrier to a fluid, identity-driven control plane. This "identity bridge" has fundamentally changed the adversary's playbook. Attackers no longer have to design complex, protocol-specific exploits to breach industrial systems. Instead, they can exploit weak authentication and misconfigured identity governance to simply "log in."

According to Microsoft Threat Intelligence, identity and remote management are increasingly converging in cloud control planes, with cloud and hybrid incidents rising 26% in early 2025. Compounding this risk, more than 97% of identity-based attacks in critical infrastructure target password-based authentication through brute force or password spraying campaigns. Preventable operational exposure -such as internet-facing VPNs left enabled, contractor accounts outliving active project timelines, and dormant privileged credentials -regularly provides bad actors with low-effort entry points into sensitive OT zones.

A classic historical precedent for this vector is the 2013 Target breach. Attackers did not target the retail giant's corporate network directly. Instead, they stole active login credentials from an outsourced HVAC and refrigeration vendor. Using this trusted remote connection, the attackers bypassed the perimeter, gained access to Target's Active Directory, moved laterally across unsegmented networks, and ultimately exfiltrated credit and debit card data for over 110 million customer accounts from the point-of-sale (POS) systems.

The Edge Gateway Vulnerability Chain

To connect local on-premises field controllers (such as Direct Digital Controllers or DDCs) to cloud platforms, operators widely deploy 3G/4G/5G cellular edge routers and gateways. However, these edge devices often ship with systemic security flaws that render them highly vulnerable to remote exploitation.

In a landmark research project, Claroty's Team82 uncovered a chain of critical vulnerabilities (CVE-2023-33372 to CVE-2023-33379) in widely used ConnectedIO ER2000 4G edge routers and their cloud device management platform. The vulnerability chain highlights the severe risks of unhardened edge-to-cloud architectures:

  • Insecure hardware identifiers: The cloud platform relied on easily guessable hardware identifiers -specifically sequential IMEI and MAC addresses -to authenticate and claim ownership of devices.
  • Hardcoded clear-text credentials: The router firmware contained hardcoded, clear-text MQTT credentials shared across all deployed units globally.
  • Broker misconfiguration: Because all routers shared the same hardcoded credentials, the central MQTT broker allowed any connected device to subscribe to the global cio/device/status topic. Attackers could exploit this to sniff heartbeat messages, leaking thousands of SSIDs, private Wi-Fi passwords, and active device IMEIs.
  • Unauthenticated root command execution: The router's communication protocol supported an unauthenticated command (Opcode 1116 / CVE-2023-33374) that executed arbitrary shell commands directly under root privileges.

By chaining these flaws, an attacker could remotely execute root-level code on any connected edge gateway, fully compromise the underlying cloud infrastructure, and establish a permanent foothold inside thousands of corporate and industrial networks worldwide.

3. The Operational and Financial Toll of Mixed Networks

When IT and OT networks are mixed without strict segmentation boundaries, the blast radius of a breach expands dramatically. A security incident is no longer restricted to a single department; it can quickly trigger physical, operational, and safety-critical failures across the entire enterprise.

In converged environments, even if an attack is successfully contained strictly to the IT network, the tight operational dependencies between IT and OT systems can force a complete precautionary OT shutdown. A striking example occurred during the May 2025 Nucor Steel incident. An unauthorized intrusion into Nucor's internal IT systems forced the company to completely cease its physical production processes. Because the IT and OT domains were so tightly integrated, operators could not verify whether the control networks were safe, forcing a precautionary halt that resulted in massive operational downtime.

Furthermore, the financial impact of breaches in operational environments has skyrocketed. According to IBM X-Force threat data, 15% of surveyed businesses experienced a cyber incident that impacted their OT infrastructure. Of those affected, 23% suffered actual equipment damage. The average cost of an OT-affecting breach has reached $4.56 million, outpacing the global average data breach cost of $4.44 million. This financial risk is particularly acute in manufacturing, which has ranked as the number-one targeted sector for five consecutive years, accounting for 27.7% of all recorded X-Force incidents in 2025.

4. Evolving Cyber Threats: From Reconnaissance to Control Loop Mapping

While organizations grapple with a severe "OT visibility crisis" -with Fortinet's 2026 report indicating that OT professionals can monitor only half of their active OT environments -adversaries are moving with unprecedented speed and sophistication.

The average eCrime breakout time -the time it takes for an attacker to move laterally from an initially compromised endpoint -fell to just 29 minutes in 2025. The fastest observed breakout was a mere 27 seconds, and data exfiltration was observed starting within four minutes of initial access. Manual detection and response processes simply cannot defend against attacks operating at this velocity.

More critically, threat actors have progressed to Stage 2 of the ICS Cyber Kill Chain. Rather than focusing purely on network reconnaissance or opportunistic IT-layer ransoms, sophisticated groups are actively researching, developing, and testing capabilities inside compromised OT networks to understand physical control loops. By mapping the relationships between HMIs, PLCs, and physical sensors (such as HVAC chillers, water valves, or electrical distribution circuits), adversaries are positioning themselves to execute targeted, high-consequence physical manipulation and sabotage.

This physical capability was demonstrated during the December 2025 Polish energy sector attack. Russian state-linked threat actors (Berserk Bear/Sandworm) exploited vulnerable, internet-exposed edge devices utilizing default factory credentials. The attackers moved laterally to HMI and RTU systems, executed destructive wiper malware (including ELECTRUM variants), corrupted OT device firmware, and wiped HMI data, resulting in a total loss of view and physical control for distribution system operators.

5. Re-establishing the Boundary: A Hardened OT Architecture

To defend against automated eCrime breakouts and Sandworm-style physical sabotage, organizations must abandon the concept of "implicit trust" on the local network. In a modern defensible architecture, every connected asset must prove its identity cryptographically before communicating with any other device.

IEC 62443 functional zone model showing operations, control, and field zones with security conduits
IEC 62443 functional zone model -isolating field, control, and operations zones with conduit controls between layers.

Re-establishing a secure network boundary requires implementing the functional zoning principles of the ISA/IEC 62443 standard. This involves isolating vulnerable, unauthenticated field devices (Level 1/0) onto their own dedicated, non-routable subnets with zero direct internet exposure. Under this model, all communication across zone boundaries must pass through strictly enforced, protocol-aware conduits.

Secure data flow from unsecured DDC controllers through a dual-homed edge gateway to a cloud MQTT broker over mTLS
Secure data flow: unsecured field BACnet stays local; the dual-homed edge gateway translates, encrypts, and publishes outbound over MQTT/mTLS.

To safely bridge local networks with cloud-based monitoring and SaaS analytics, practitioners utilize a secure Edge Gateway architecture:

  • Outbound-only TLS conduits: The edge gateway initiates all connections outbound to the cloud broker (typically via MQTT over TLS on TCP Port 8883). This allows the local network to maintain zero inbound open firewall ports, completely hiding the internal controllers from external internet scans.
  • Centralized cryptographic termination: While emerging standards like BACnet/SC (Secure Connect) attempt to encrypt OT traffic, they require every single field controller to manage its own unique digital certificate. For a facility with 200 controllers, this creates a massive manual "certificate renewal burden" that often leads to configuration errors and operational downtime. A hardened edge gateway resolves this by isolating unencrypted BACnet/IP traffic on local subnets, serving as the sole secure checkpoint to terminate a single certificate and securely broker the mTLS transit to the cloud.
  • Publish-by-exception: The edge gateway only transmits data packets when a sensor value actually changes. This minimizes bandwidth consumption and prevents external network spikes from impacting local control stability.

By enforcing zone-and-conduit discipline, eliminating inbound remote access doors, and utilizing cryptographic, outbound-only gateways, industrial operators can re-establish a defensible boundary that protects physical processes from IT-layer vulnerabilities.