Colonial Pipeline
A single VPN password with no multi-factor authentication, on an account no longer in use but still active. The largest fuel pipeline in the US stopped. (Source: Bloomberg)
One unretired VPN account with no MFA shut down the largest fuel pipeline in the United States. The pattern in the three incidents below is the same: an access path into operations that outlived its reason to exist.
A single VPN password with no multi-factor authentication, on an account no longer in use but still active. The largest fuel pipeline in the US stopped. (Source: Bloomberg)
Control-system devices left on vendor default passwords, some reachable straight from the internet.
Networks joined for good operational reasons, without the MFA and segmentation that joining them demanded.
The IT/OT boundary is the most important line in your estate, and vendor remote access is the most common way across it. Since 1 April 2026, CIP-003-9 expects that access to be controlled at low-impact sites too — which for many utilities means systems that were never in scope before.
If any answer is "no" or "I would have to ask", that is the blind spot.
The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.
The sector page: identity security for energy and utilities. The service that closes the gap: PAM implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.
Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.