TL;DR: AI is reducing the time, cost, and skill needed to find exposed OT entry points, while real-world incidents continue to start with leaked passwords, default credentials, or forgotten remote accounts, according to Appgate. That makes access control, not patch velocity, the decisive variable when protecting systems that cannot be quickly re-architected.
NHIMG editorial — based on content published by Appgate: Zero trust network access is becoming the OT access control test
Questions worth separating out
Q: How should security teams reduce OT breach risk when attackers are using valid credentials?
A: Start by reducing reach, not by assuming every valid login is safe.
Q: Why do leaked or default credentials create such high risk in OT environments?
A: Because many OT assets will obey a valid session without additional identity challenge.
Q: What do teams get wrong about patching OT security fast enough?
A: They assume the patch cycle is the main race.
Practitioner guidance
- Map every OT remote access path Inventory VPNs, gateways, vendor tunnels, and ad hoc support channels, then identify which identities can reach which assets.
- Eliminate default and dormant access Search for shared credentials, inactive accounts, and device defaults such as factory passwords on controllers and remote admin systems.
- Scope sessions to one operational target Require each remote session to be tied to one historian, controller, or zone so a valid login cannot pivot laterally.
What's in the full article
Appgate's full analysis covers the operational detail this post intentionally leaves for the source:
- Specific ZTNA and SPA mechanics for hiding OT assets before authentication occurs
- The control changes needed to constrain vendor and maintenance access to one operational resource
- How Appgate frames the difference between VPN exposure and resource-scoped access in OT
- The implementation logic for applying continuous verification to remote maintenance sessions
👉 Read Appgate's analysis of zero trust network access for OT remote access →
Zero trust network access for OT: are your controls keeping up?
Explore further
Valid identity is now the preferred OT intrusion path: The article correctly shows that many OT incidents are not break-ins in the classic sense. They are authorised sessions using leaked, default, or forgotten credentials, which means identity governance sits directly in the breach path. In practice, that shifts the control conversation from exploit blocking to reachability and privilege scoping.
A question worth separating out:
Q: Who is accountable when OT remote access cannot be traced after the fact?
A: Accountability sits with the operating organisation, because auditors and regulators expect it to prove who accessed critical systems and under what authority. In practice, that means security, OT operations, and compliance must share one access record and one revocation process. If no one can reconstruct the session, the governance model has already failed.
👉 Read our full editorial: Zero trust network access is becoming the OT access control test