The critical infrastructure attack has stopped being the hypothetical scenario the national security advisor uses to justify the budget. It has become the operational reality the utility operator, the water utility, the hospital network has started to live with. The attack that lands in the news, the attack that the operator patches in the rush, the attack that the regulator cites in the next compliance memo. The honest framing matters here, because the critical infrastructure attack that the enterprise has not been hit with yet sits as the attack the enterprise is one phishing email away from.
What follows runs as the working version of the field guide. The shorter version is what the operator and the regulator actually have time to read.
The patterns the wave has shown
Three patterns, in roughly that order of how much each one has shown up. The first runs as the ransomware on the OT network, where the attacker breaches the IT network, the attacker moves laterally to the OT network, the attacker encrypts the OT servers, the production system the OT network controls stops, the attacker demands the ransom, the operator pays because the production system cannot run without the OT. The ransomware on the OT network has become the pattern the 2025-2026 wave has run on. The second runs as the supply chain compromise, where the attacker compromises the third party vendor (the remote management vendor, the SCADA software vendor, the industrial control vendor), the attacker uses the vendor access to reach every customer, the attacker compromises the critical infrastructure customer the vendor serves, the supply chain compromise that the SolarWinds, the Kaseya, the MOVEit patterns sit as. The third runs as the insider enabled access, where the disgruntled employee, the contractor who has been offboarded but still has the access, the partner who has the VPN credential, the insider that the security team did not know about serves as the insider the attacker uses.
Where the attack surface sits
Three places, in roughly that order of how much each one matters. The first runs as the IT/OT boundary, where the corporate network connects to the industrial control network, the boundary that the segmentation was supposed to protect, the boundary the attacker crosses through the remote management tool, the vendor portal, the engineer’s laptop. The second runs as the remote access, where the engineer, the vendor, the contractor all connect to the OT network from the remote location, the VPN that was supposed to provide the secure access, the VPN the attacker has compromised through the stolen credential, the remote access that sits as the entry point the attacker uses most often. The third runs as the legacy OT system, where the industrial control system that was installed in the 1990s, the system that cannot be patched because the vendor stopped supporting it, the system that the operator cannot replace because the production process depends on it, the legacy system that the attacker knows about because the attacker has been reading the same CVE database.
What the defender is doing about it
Three moves if you are the operator that wants to defend the critical infrastructure without shutting down the production system. Segment the IT from the OT, because the segmentation that the architecture team can implement without disrupting the production, the segmentation that puts the OT network on the isolated VLAN, the segmentation that puts the remote access behind the jump host, the segmentation that the operator should have done years ago. Inventory the OT assets, because the inventory that the operator has been postponing, the inventory that names every controller, every sensor, every HMI, the inventory that the operator needs before the operator can patch, the inventory that costs the quarter but enables every other security control. Subscribe to the OT threat intelligence, because the OT threat intelligence (the Dragos, the Claroty, the Nozomi) gives the operator the indicator the IT threat intelligence does not cover, the indicator that the OT attacker uses, the indicator that the operator needs to detect the breach before the production system stops. The operator that segments, inventories, and subscribes serves as the operator that has defended the critical infrastructure without shutting down the production.

The bottom line
Critical infrastructure attacks in 2026 sit as the operational reality the operator has to live with. The ransomware, the supply chain, the insider, those three are the patterns. The IT/OT boundary, the remote access, the legacy OT, those three are the surface. The segmentation, the inventory, the OT threat intelligence, those three are the defense. The operator that does the three holds the line. The one that pretends the critical infrastructure is not a target does not.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



