Sending Logs, Alerts, and Telemetry Through a Data Diode

Find Out How
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Made to Evade: The Expanding Attack Surface of Critical Infrastructure

The same innovation making infrastructure smarter and more resilient also changes what attackers can reach. That is why modernization needs security planned in from the start.
By David Mitchell, VP, Products
Share this Post

Key takeaways

  • Critical infrastructure can experience disruption from the business network, and recent public healthcare cases show how a single user action involving a malicious file can cascade into operational disruption.
  • Email remains one of the busiest gates in the attack surface: a channel that reaches both machines and the people operating them, at scale, by design.
  • Air-gapped environments still depend on content from the connected side, which makes upstream inspection important before files cross into more sensitive systems.
  • Innovation is essential to resilience, but each new vendor, integration, and update channel should be planned with the same care as the operational benefit it enables.
  • A defense built for this reality treats email security as one pillar of a layered, holistic model, inspecting and reducing risk before content reaches a reader, human or machine.

Critical infrastructure can be disrupted before the air gap

In critical infrastructure, isolation has often been treated as the finish line of security: segment the network, air gap the most sensitive systems, and the problem is contained. Yet business operations live outside the isolated core: scheduling, logistics, billing, process historians, monitoring. That territory is an attack surface too.

So, the question is not only what sits behind the air gap, but what can be disrupted before anything reaches it. For many critical infrastructure organizations, including hospitals, banks, and transport networks that could not function fully behind an air gap, the business network is a major part of the estate.

And that territory has one particularly busy front door. Email is one of the busiest gates in the attack surface, a channel every organization holds open by design, because that is how work arrives: vendor updates, contractor documents, the spreadsheet that starts a project. It carries a double threat, reaching machines with the files and links that execute, and reaching people with the persuasion that gets those files opened. Few channels deliver both at similar scale. The cases that follow are on the public record and show how email, malicious files, or trusted user actions can become the first step in broader operational disruption.

Ireland's Health Service Executive is one of the few victims that chose full transparency, commissioning and publishing an independent review, which is why the case can be walked through in detail. In March 2021, a user interacted with a phishing email that infected a workstation with malware. The attackers then operated inside the environment for eight weeks before detonating ransomware, using that time to compromise servers and privileged accounts, move laterally, and exfiltrate data before the disruption became visible at national scale. The health service switched off its IT systems to contain the spread. Hospitals reverted to pen and paper, appointments were cancelled across the country, recovery took more than four months, and the cost of remediation was estimated at €102 million as of November 2024.

An email security failure rarely stays an email problem; it can cascade into operational and business disruption, with financial consequences as well. In 2024, Ascension said an employee downloaded a malicious file in what the organization described as an honest mistake. The incident left one of the largest US hospital networks diverting ambulances, postponing care, and later reporting that 5,599,699 individuals were affected.

One scenario security leaders should consider is the one where nothing happens at first, where the attacker sits inside the business network and reads: network diagrams, engineering documents, credentials, maintenance schedules, the transfer workflows themselves. And when reading turns into action, the consequences can reach the physical world. That is how the 2015 attack on Ukraine's power grid reportedly unfolded: public reporting and technical analysis describe prior compromise of corporate networks through spear-phishing emails carrying BlackEnergy malware, followed by reconnaissance, credential theft, and coordinated disruption of substations. The incident affected roughly 225,000 customers. One trusted message, one routine action, multiple operational consequences.

Attack surface continues to expand

Critical infrastructure is innovating because it has to. The threat environment is escalating, expectations for uptime are rising, and resilience increasingly depends on smarter, more connected systems. A substation that ran the same logic for twenty years may now report into cloud analytics, a pump that was checked manually once a shift may now stream telemetry to a vendor, and maintenance that waited for failure may now be guided by AI- and machine learning-enabled prediction. These improvements are not optional distractions; they are how critical infrastructure keeps pace. The opportunity is significant, provided the security model evolves with the technology around it.

Every wave of that innovation introduces change: new code, new integrations, new vendors, update channels, and new remote access paths. With a thorough plan, that change can be managed. Security leaders can define how data moves, how vendors connect, how updates are validated, and where content is inspected before it reaches sensitive workflows. The risk is not innovation itself; it is unplanned trust. Each new vendor and contractor can create a new email relationship, with attachments, invoices, and update notices that users are expected to open. The surface expands, and so does the number of entry points where something untrusted can arrive looking legitimate.

So, what happens when modernization moves faster than the defenses designed around it? That is the compounding effect: even if attacker capability froze today, exposure could still grow, because the environment keeps gaining new connection points. AI and machine learning can improve operational resilience on the defensive side, but attacker capability shows little sign of slowing either. AI can accelerate research, targeting, and iteration on the offensive side, which makes planned, adaptive security part of responsible innovation rather than a barrier to it.

Few operators can predict exactly what their own environment will look like in five years, so today's security architecture may already be defending yesterday's topology. The goal is not to slow innovation, but to make sure security evolves alongside it. Isolation still matters, but it works as one layer in a broader resilience model rather than the whole answer.

Where this leaves us

Security leaders often size up a threat by asking three questions: does the adversary have the intent, the capability, and the opportunity? For many critical infrastructure environments, the answer to all three is increasingly yes.

  • Intent: critical infrastructure is targeted deliberately by adversaries who research their victims, and it is likely to remain attractive because the potential payoff justifies the effort.
  • Capability: attacks are increasingly industrialized, with AI lowering the cost of building, testing, and rotating campaigns.
  • Opportunity: the attack surface changes as innovation connects systems that used to stand alone and content continues to cross the boundaries that remain.

Underneath all three sits the same pair of constants: people will keep relying on email, because it is essential to keep operations running, and content will keep crossing many of the boundaries we draw, because that is how businesses run.

A defense built for that reality has a recognizable shape. It treats email security as one of the busiest gates in the perimeter and resources it accordingly, as one pillar of a holistic model. It layers controls at that gate, each doing a different job, so content is inspected and risk is reduced before a reader touches it, human or machine. It uses AI-assisted analysis inside the operating loop for faster correlation, faster triage, and faster learning from blocked attempts, moving closer to the pace attackers set. And it treats continuous improvement as part of responsible modernization, because the threat environment keeps changing.

The question worth carrying back into your own environment is simple: when content moves toward the systems you can least afford to lose, where is the last point at which it is genuinely inspected, and would that point recognize content designed to appear safe and trustworthy? For many organizations, tracing that content back to where it first arrived often ends in the same place: the inbox.

This is part 3 of the Made to Evade series

Read part 1: Critical Infrastructure Organizations Are Non-Negotiable Targets.

Read part 2: AI's Industrialization of Cyberattacks.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.