Ep 97: OT Under Siege: How to Defend Critical Infrastructure From Nation-State Cyber Threats | PrOTect IT All
HomeEpisodes › Episode 97
Episode 97
Episode 97 Solo

OT Under Siege: How to Defend Critical Infrastructure From Nation-State Cyber Threats

Mar 16, 2026 00:23:19
OT SecurityCritical InfrastructureRisk ManagementNetwork SecurityRansomware

Watch This Episode

Global conflicts are no longer confined to physical battlefields - they’re spilling into cyberspace.

In this urgent episode of Protect It All, host Aaron Crow breaks down the rising wave of cyber threats targeting critical infrastructure, from energy and water utilities to manufacturing and transportation systems.

Drawing on recent global events and real-world incidents, Aaron explores how nation-state actors, hacktivists, and advanced adversaries are increasingly targeting operational technology environments. These attacks often rely on “living off the land” techniques - leveraging existing tools and access inside networks rather than deploying obvious malware.

But this episode isn’t about panic. It’s about practical defense.

Aaron outlines the immediate steps OT security teams can take to strengthen resilience - even with limited resources and tight budgets.

In this episode, you’ll learn:

Whether you operate power systems, water facilities, industrial plants, or transportation infrastructure, this episode provides real-world guidance to help you stay ahead of evolving threats.

Tune in to learn how OT teams can strengthen defenses and protect the systems society depends on - only on Protect It All.

Key Moments:

03:41 "Rising Cyber Threats Amid Tensions"

08:24 Nation-State Cyber Threats Unveiled

11:23 "Advanced Cybersecurity and Monitoring"

14:24 Prioritizing and Addressing Security Risks

17:24 Practical Steps for Cybersecurity Improvements

19:34 "Focus on Resources and Action"

Connect With Aaron Crow:

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

03:41Rising Cyber Threats Amid Tensions
08:24Nation-State Cyber Threats Unveiled
11:23Advanced Cybersecurity and Monitoring
14:24Prioritizing and Addressing Security Risks
17:24Practical Steps for Cybersecurity Improvements
19:34Focus on Resources and Action
Read the full transcript

Aaron Crow (0:1.166): Hey, welcome back to Protect It All. I'm your host, Aaron Crowe. And look, I wasn't intending to necessarily have this podcast episode, but there's so many things going on in the world. Figured it was a great link to what was going on. Saw a couple of articles coming out from a couple of different places. My friends over at Embury OT, Industrial Cyber, a couple of places have really talked about this. So figured I'd

Aaron Crow (0:30.764): I talk about it here because here's the thing. What's going on with the US, Israel, Iran? There's definitely a lot and I'm not trying to get political at all, but it is definitely a live action threat to critical infrastructure, energy, water manufacturing, all kinds of systems that we work on every day in the O.T. spaces. So if you're an O.T. security right now,

Aaron Crow (1:0.694): You've probably been looking at this stuff, but let's make sure that we're up to speed thinking about what threat actors. So we obviously see that things are going on in wherever you are in the world. I'm here in the States. I see things that are going on in other continents and places and war zones, et cetera. But nothing because US is engaged or maybe your country or things are happening closer to home.

Aaron Crow (1:28.542): those things can be happening here. So we need to be actively looking at and protecting against things that could be coming on. So let's break down kind of what's going on and what you should be doing about it. Today, not trying to get left of bang, bad word, I'm guessing, but before something hits your network, not after. We don't wanna always be thinking about.

Aaron Crow (1:55.128): things after they happen after they bring down a network. And this is not supposed to be doom and gloom. This is not chicken little. This is not the sky's falling. this is not, you know, Fudd. this is about, you know, really what looking at what is going on, in these spaces, in real life, like on the battlefield in, these countries, in these spaces. everybody should probably know if you don't, you know,

Aaron Crow (2:21.966): Late February, now we're in March. We saw a significant escalation, US, Iran and Israel conflict and it's gotten kinetic. That kinetic has also gone into the cyberspace. We've seen everything from grid getting taken down to posts on TV and internet being taken down.

Aaron Crow (2:51.124): All sorts of things, drone strikes and oil reserves getting hit. It's definitely going after, you know, LNG production facilities, know, power plants, infrastructure, Qatar energy has confirmed attacks. There's just wide scale, large scale impacts in that region. And that's just the kinetic and firsthand pieces, right?

Aaron Crow (3:20.976): at the same time, on the cyber side, you know, we're seeing hacktivist groups mobilizing. some of them are going to be aligned with Iran. Some of them are going to be pro Russia. Some of them are going to be, Chinese focused and, and, maybe they're just going to take advantage because things are pointed or are focused in other areas. you know, they're trying to jump into the fight and, and, and do their part as well. don't want to really call out any by specific, but there's definitely well-known pro.

Aaron Crow (3:50.094): Russian, you know, DDoS actors that are getting in the space in a mix of supporting Iranian interest and converging in this fight. We've seen claims by, you know, pro-Iranian, pro-Palestinian groups against Israel. Oil and gas companies and energy companies posting on leaked sites. Massive cyber attacks are imminent, you know, making threats, making, you know, predictions that

Aaron Crow (4:20.226): devastating cyber infrastructure is currently underway, specific claims, all this to say, as these tensions are heated, because of the things that are going on, and again, not saying that I agree, disagree, that's not the point of this. The point of this is just to talk about the cyberspace of this, OTspaces, in critical infrastructure, things are going to be elevated, right? So if you look at the DEFCON level, like you know,

Aaron Crow (4:47.212): we should be thinking about this as a higher risk because there are going to be activist groups. There are going to be nation states that are going to be coming after critical infrastructure in the U S and Canada and, everybody that is potentially pro right side, left side, middle side, wherever, there's going to be a lot of, cross cross fighting come across all these things. Right. so, you know, looking at the, the, the specific threat picture,

Aaron Crow (5:16.460): what it actually looks like in an OT space, the offensive. We know these spaces are older. We know that everybody's heard the living off the land. If you've listened to this podcast before, you've heard me talking about it. You've heard many of my guests talking about it from Dean Parsons and others. Adversaries aren't having to write custom malware.

Aaron Crow (5:42.555): These are systems that many times are running off Windows XP or they're unpatched and they've got Telnet or they've got other things. So we know there's ways in. There are a lot of concerns that some of these nation states and other organizations may actually already be in. So what do you do about those things? How do you start looking at this? What we see is they're using

Aaron Crow (6:7.830): control systems, you know, that they know that DMP three and Modbus and all these protocols, they're not, they're not secure. We know those things, right? Those are, they're, they're not secure by design. It's not like a lack of, Hey, I forgot to secure this protocol. Those protocols have never been designed to be secure. So, you know, they are by design supposed to be quick. They're by design supposed to be, you know, if you, you know, send a command, it's going to respond.

Aaron Crow (6:36.455): There are thresholds, hey, you can't speed it up past the rev limiter or whatever, but that's the kind of point of those systems is to be responsive and to do their jobs the way they're supposed to. So the problem with this is that, know, antivirus isn't going to catch that. It's not something you can throw an EDR agent at. can't put antivirus. Your firewall is not even going to necessarily detect if they're already inside or if they get past or find a way in.

Aaron Crow (7:4.076): You know, none of those things, it's not phoning home necessarily. Cause once they're in, it's, it's east west, right? They're, they're on an engineering workstation and they're communicating to a PLC or a control processor or, or, you know, the, the end point field IO that's actually doing the things, right? And if you don't have net network visibility, I just talked about how important it is to have east west. This is why NERC SIP is pushing, you know, SIP 15 for things like this, right?

Aaron Crow (7:31.727): For years, we have been focused on how do we keep people out? How do we keep bad actors on the outside? And that is still a good thing to do. We absolutely need those things. But also, if you don't have the ability to monitor at all in your inside your network or know when, know, what is good to look like. And if bad things are happening, this is where situations that we're in today become really terrifying. Right. Because we have, you know,

Aaron Crow (8:1.582): known vulnerabilities. know many OT networks that have remote access and they're not necessarily monitoring those spaces. Or if they are, the systems may be monitoring, but is anybody actually looking at those logs? we are we doing anything with it? That's where the real question comes in. You know, we know that a lot of these threat actors are going to be using AI.

Aaron Crow (8:27.302): So if they know what these systems are, they know they can use AI. We all use it, right? That's what AI does is all of these systems are, we know the vulnerabilities, they're released. Microsoft Windows, Fortinet, whatever the system is, we know that we can post the vulnerabilities out there and AI can help us in theory, work around those things. Find a hole in, find a way around the way that this is architected, this is set up.

Aaron Crow (8:55.938): And you can generate, you know, very personalized, contextually accurate, you know, you're not having to build malware, like you're using things that are already there. You know, we know a lot of these, these groups, especially the nation state sides, they have labs, have PLCs, have examples of these systems running in their environments. They are waiting for the time to take actions, right? To move.

Aaron Crow (9:25.708): that that ball forward and taking action may not mean hey I'm going to shut this plant down it may mean that I'm going to further infect or I'm going to further dig my claws into this environment so that I can do you know take other actions you know if you if you look at a different country outside of of these three you look at you know obviously China is interested in Taiwan and you look at you know Russia and and and Ukraine like there is just so much going on right now

Aaron Crow (9:52.587): There's lots of focus in other places that it's very easy to overlook the things that could be going on here. know, taking a look at vendors as they come in, again, I'm not trying to point fingers and assume that a vendor is going to be maliciously trying to do anything, but I've also seen vendors, you know, the whole, you know, water well,

Aaron Crow (10:22.055): attack where I know if a vendor, you know, if I work for a, you know, vendor a call them whatever you want Acme Corporation and and this power plant uses Acme Corporation controls. I know if I get on that Acme Corporation company laptop that he takes into that place, he's going to bring in whatever I attached to it, right? There's all sorts of paths and I've seen that in very protected environments in a nuclear facility.

Aaron Crow (10:49.123): where there was a vendor that brought in a, let's call it a malware or something bad, malicious, and plugged it into a system inside of the controlled containment environment. Now, it was just not a super critical, it wasn't the control system, it didn't control the reaction, but still it was a system inside the containment area, right? It was something that happened.

Aaron Crow (11:17.835): And we checked all the boxes, we had antivirus, we had all that type of stuff on, it can still get in. And this was 15, 20 years ago. The fact that, know, thinking that might not happen now is very short-sighted. know, initial access is usually still on the IT side. It's still coming in from the connection to the IT network.

Aaron Crow (11:42.311): Whether it be from, you know, firewall through the remote access process, again, from a transient device that's literally brought in, you know, those are still coming through, right? So if I'm a threat actor, I know if I can get on the corporate network, then I'm that much further into your environment. And then I know, hey, I can go after these particular people. There's a lot of OSINT, you know, I've done an episode talking about OSINT and,

Aaron Crow (12:10.709): open source intelligence, SIGINT, know, that intelligence side of this is beyond, you know, just stuff that you find on the internet or black, you know, dark web. But, you know, we're posting on LinkedIn, like we all have who our employers are, and they know where we live. And it's public knowledge many times of what the things are, even if you try to hide it, it's really hard to, you know, really obscure yourself from that. So it's really just being intentional about that and thinking about what are the risks there.

Aaron Crow (12:40.299): And that's why you shouldn't have the same password on the IT side and OT side. You shouldn't use the same device. You should have different multi-factor authentication. There should be checkpoints and barricades that I have to walk through to be able to get into those spaces and monitor. And that's where advanced monitoring would be. Hey, if Aaron just walked into a plant in Florida and I have a signal that Aaron is logging in or working on a system in Texas,

Aaron Crow (13:9.357): You know, maybe that's okay, because he's remote access and he has access to do that. But it's at least something I should consider. I should look at what should be that process to make sure that I'm not triggering something in that space, right? You know, so with the threat picture the way that it is today, we know that nation state aligned actors are motivated. They have motivated intent, like they're going to use techniques that bypass, you know, traditional detection. And, you know, they're using AI to enhance phishing, phishing attacks.

Aaron Crow (13:39.647): I'm old enough to remember when phishing attacks were really, really bad, right? know, the whole, you know, African prince or whatever the thing was. And it was really, for those of us in the space, were really pretty obvious that it was not real. Now that's not the case. Like I got a call from a company last week that like it got, the phishing attack got all the way through for a subsidiary company that they had.

Aaron Crow (14:8.111): trying to move funds and it didn't get through until the banking, it got to the bank before the bank realized that it was fraud because the account numbers weren't right. So it got through a lot of checks and balances that they had and they were doing the right things. It's not like they had no, you know, controls, they did, but it still looked real enough that they pushed it through, right? So these things, AI has really helped push phishing that if I broadly

Aaron Crow (14:35.725): do a phishing campaign against all of your employees, the likelihood that I can at least get one of them to click on it is pretty darn high. Even with, you you do your phishing training, sure. That all it takes is one person to click the link and now they're in. And it's really, they're really, really good now, right? So, you know, they're going to hit multiple accounts. You know, we also have a place where a lot of companies, especially in the OT space, they're operating with, you know,

Aaron Crow (15:5.943): reduce staff because of budgeting issues. Maybe they've cut back on a project and they're not upgrading this system or they're not rolling out these new controls or whatever those things are. And all of those are real things. It's part of running a business at the same time. It's also additional risks as we already know these spaces are vulnerable and critical, you know, and critical infrastructure, know, there's 17 critical infrastructures, you know, I have a lot of experience in many of them. Most of

Aaron Crow (15:35.331): you know, the most experience I have is in power generation and power transmission distribution. But you know, you look at water, right? Water is, you know, very significantly less budget and staff than, than power utility. you know, you look at, you know, water is going to be less than, than a lot of the critical infrastructures. And a lot of times it's because it's a local city, you know, it's, your, your local city that it's their water department, right? And they don't necessarily have a

Aaron Crow (16:3.789): you know, a high level trained cyber security team. Some do and the ones that they do have, you know, they do the best they can, but still it's not going to be the same as the cyber security staff at Microsoft. Like it's just different. They have different budgets and different, you know, obviously less attacks. But that's, that's in the past. And, as we see with this type of stuff, that's, that's when the risks really come in. Right. So, you know,

Aaron Crow (16:31.791): My point in this again is not to really beat us over the head. It's to really for us to sit down, think about, take a breath and think, okay, all these things are going on in my environment. Where is my most risky thing? What is the thing that if I know somebody's trying to get in, where should I look? Where are the things that I know are risky? Where's my remote access? Where's my vulnerable systems? Where are the places that I haven't looked?

Aaron Crow (16:58.671): You know, and then also think about, what are some things, some tasks? And I'm not talking about spending money. I'm thinking about, hey, if I've got 10 minutes in the morning, what's a system I could go look and make sure that nothing's changed? Make sure that everything looks right. Make sure that everything is functioning right. Pick up the phone and call the operator. Hey, has everything been there? Is everything working as expected? Has anything changed? Have you noticed any difference in graphics or the way something is speed of the network or has things rebooted frequently? Is there, have you noticed any differences and changes in these systems?

Aaron Crow (17:29.968): And those are all things. Also, patching, right? Make sure that you're up to date on your patches. Make sure that you've updated your systems as well as you can within, you know, obviously outage windows and you've tested and backed up and things like that. Obviously not recommending anybody do anything dangerous or risky to potentially shut down their environment because patching a system can shut down the environment too. I realize that in OT space, patching is not always an answer, but on those systems that you can.

Aaron Crow (17:57.923): the boundary firewall, you can patch that. Like that should be updated. It shouldn't be at the, you know, 10 versions behind, right? It should be updated. Make sure that you don't have any, any rules. Make sure you're disabling remote access. Make sure you're monitoring for things that are going north, south. Do you have any monitoring going east, west? Is there anything you can do in those spaces, right? Make sure you're changing passwords. It's another thing that costs you nothing but time. Like change, especially if you have any default passwords, but hopefully you don't.

Aaron Crow (18:27.671): Change your passwords, change internet facing devices, the firewall, change the password. Like you know that there's things going on right now, maybe your normal cadence for changing your password is in December or October or hell, maybe it's in July, whatever it is. Consider bumping that up to now, right? Do it now, right? You're still doing it. The work still needs to be done, but pushing it forward can slow someone down because they got in on the old password.

Aaron Crow (18:55.053): Maybe they used a hash, whatever that may be. Well, when you change that, can stop that spread. Maybe then also you notice some things happening. Maybe you can reboot a system, because some of the things are persistent until they're rebooted. Make sure that you have MFA on remote access, on anything that supports remote access. Make sure that you're disabling accounts that are not used. Make sure that not everything has admin. Definitely don't have domain admin, right?

Aaron Crow (19:22.771): You know, just start taking a look at and considering where all of your gaps are, where all the risky environments are and the riskiest configurations and vulnerabilities in those spaces. If you know you're running a Windows XP box, what can you do to that? How can you protect it best? You're not going to update, there's no patching to it. So what can you do? Change a password, right? Disable unused services that are not needed, right? You know, maybe you can throw on some open source, you know, monitoring type stuff.

Aaron Crow (19:50.871): whatever, there's lots of things that you can do that don't cost a lot of money. And they're not super complex that you can start doing and taking a look at these spaces, right? I'm not trying to downplay the thread. I'm not trying to upplay the thread. I'm not trying to make it bigger than it has to be. But now's the time to take actions on things like this, especially if you're in critical infrastructure, especially if you're in these spaces that you haven't had the budget to do a lot of the work, or even if you have and maybe, hey, I've got a budget, rolling out this thing and...

Aaron Crow (20:17.391): you know, we've gotten 20 % of the way there, we've gotten 80 % or we've got 90%, but there's this 10 % over there that I haven't dotting to yet. Consider, hey, what can we do about those 10 so that we, you know, we don't have an issue on those spots that are potentially gonna get broke down. You know, look at the critical five, and I know we just talked about this and I'll harp on it a little bit more, but you know, the SANS ICS, you know, the five controls, right? You know, how are you doing those?

Aaron Crow (20:44.835): What are you doing? Well, what are you not doing? Well, you know, focus on what you have. You know, make sure that you have response plan. Make sure you've got backups. Make sure that you're you know, your response plan is accurate. Make sure that you're you know, your arc, your your O.T. architecture. Make sure that, you know, it is still segmented. Right. You know, make sure that you have some visibility. You can't necessarily change the visibility or not at the last minute. But, you know, really focus on the things that you have and really dive into them and then the human.

Aaron Crow (21:14.415): Like I would be, I highly recommend that you have conversation. You're sending out notices to your team, to the company. Like, hey, you know, I think back to September 11th and in New York after that, right? And the whole, you know, if you see something, say something. Start talking to people about what something may look like. Again, a system may slow down, maybe it's rebooting. Like those are things that an operator would notice that may not bubble up and seem like a cyber incident.

Aaron Crow (21:44.089): but sometimes those are the things that notice and things get picked out because something like that happens, right? You see a new application that's installed that you didn't remember it being there yesterday. There's a file on the desktop, like any little thing like that, an operator that's sitting and seeing the screen day in and day out, they're gonna notice those things even when you or I may not as a cyber practitioner because we're not staring at the screen. We don't use the screen day in and day out all day.

Aaron Crow (22:13.419): If you talk to those folks, they are your biggest ability to see changes and know changes that are going in. They're literally designed and focused on doing that type of work. The bigger picture of this is it's beyond what's going on in the Middle East. It's beyond what's going on in Russia, Ukraine. It's really just really taking focus and ownership on these things and doing what you can with what you have. How can you focus on

Aaron Crow (22:42.307): you know, finding the things, focusing on, you know, the resources that you have, the setup that you currently have, like you can't, I can't redesign your network in a day and implement that and deploy that across all of your sites. If you have one site and you have some money and some time and some outages, yeah, sure, we can do that. But it's not likely to happen in the short amount of time that is needed, right? So the threat is real. It's active.

Aaron Crow (23:11.007): we are in a, you know, there is a, a, an active, war going on, whatever word you want to use. Cause I don't know what Congress or the president or anybody else. And again, that's not what I'm talking about, but at the end of the day, there are going to be, nation state aligned attackers that are going to be looking to, you know, retaliate based upon things that, that, that's going on over there.

Aaron Crow (23:35.821): both here and with anyone that has any relations with either of the countries that they think is against them. Right. So, pay attention. you know, there's a lot of, articles that are out there. There's a lot of reports coming from, you know, everything from CrowdStrike, IBM X-Force and DHS and, and, and CISA and, and et cetera, et cetera, et cetera. You know, prioritize lockdown, you know, pick up the phone, call your engineers, go grab them lunch, walk them through things, take a look at it yourself.

Aaron Crow (24:5.899): And stay vigilant, stay practical. There's a lot that can be done to help protect this. And again, worst case scenario, be able to recover. That's the other pieces. You can't protect everything forever. So what can you do to make sure that you can recover? So love to hear you guys talk about what you're doing in your space, concerns that you have. there anything that you've seen?

Aaron Crow (24:30.943): Any additional activities that you've seen coming up on your internet facing firewalls, you're seeing new threat vectors from other IPs and countries. love to, please don't just do nothing, right? Take action, think about things, have conversations with your leadership, with your teams, Anyways, thanks again for joining me, y'all. Just wanted to have this quick one.

Aaron Crow (24:57.871): to talk about this. Please leave us a review on Apple and Spotify. Love to have some folks coming on and talking about what they're seeing, what they're focused on in these spaces. It's not all about the biggest budget, the biggest technology. It's all people, process and technology. And a lot of times it's the people that matter, both on the positive and the negative. Like they could be the one that caused the downtime, but they can also be the one to save the day.

Aaron Crow (25:26.921): What I like to tell my kids is be the hero of your own story. We can find a way or we can find an excuse. So, you know, it's easy to find, say, I don't have enough budget, I've got a small team, we can't do this, we can't do that. And all those things are accurate. What can you do with what you have? Right. Definitely reach out. Happy to talk with anyone that has questions, wants to run things by. Come see us at RSA for the ICS Village. Be at DEF CON, be at DEF CON in Singapore.

Aaron Crow (25:56.295): There's a lot of cool things going on. Definitely lots of places to plug in and a big community that is willing to help and answer questions. And really, you know, this is we're all on the same team to try to protect critical infrastructure around the world. Thanks a lot.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.