Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› How should organisations adapt Zero Trust when nation-state…
Architecture & Implementation

How should organisations adapt Zero Trust when nation-state groups target legacy network devices and critical infrastructure?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Architecture & Implementation

Organisations should treat legacy devices as part of the trust boundary, not outside it. Zero Trust works best when every access path is verified, segmented, and monitored, including remote gear and out-of-service equipment. Teams should prioritise asset inventory, device replacement, strong authentication, and microsegmentation so a single weak point cannot become a broad internal foothold.

How Zero Trust changes when legacy devices sit inside critical infrastructure

zero trust has to be applied as an operating model, not a modern-device assumption. Legacy network gear and industrial systems often cannot support strong agents, modern authentication, or frequent patch cycles, so the practical answer is to wrap them in compensating controls: strict segmentation, tightly controlled management paths, monitored access, and a clear replacement plan.

The key design shift is to stop treating older devices as trusted because they are old or “inside” the network. If a device cannot prove itself reliably, the surrounding architecture must reduce what it can reach, reduce what can reach it, and make every exception visible. That is especially important in critical infrastructure, where a single exposed device can become a bridge into operational environments.

A good Zero Trust adaptation starts with asset clarity. Teams need to know which devices exist, what protocol paths they use, who administers them, and which ones are unsupported or remotely reachable. Without that inventory, segmentation becomes guesswork and exception handling becomes permanent risk.

Where legacy network devices break standard Zero Trust assumptions

Legacy devices usually fail Zero Trust in the same few ways: weak or missing authentication, inflexible management interfaces, vendor-default trust relationships, and limited logging or telemetry. Some also require flat network reachability to function, which conflicts with least-privilege design and makes policy enforcement harder.

Those limitations do not mean Zero Trust is impossible. They mean the trust decision shifts outward. Instead of trusting the device to enforce modern controls internally, organisations enforce policy at the network, access, and management layers around it. In practice, that means separate administrative paths, explicit allow lists, strong operator authentication, and careful restriction of east-west movement.

Microsegmentation matters here because legacy assets rarely fail in isolation. A compromise of one unmanaged switch, remote terminal unit, or out-of-support controller should not imply broad lateral access. If the architecture still allows that, the organisation has only hidden the old perimeter rather than removed it.

What nation-state targeting changes for critical infrastructure defenders

Nation-state groups tend to value legacy devices because they are persistent, often exposed, and harder to monitor than standard endpoints. They also fit long-dwell operations: once an attacker gains access to a management plane, engineering workstation, or remote support path, the device can be used to maintain footholds, relay traffic, or pivot deeper into sensitive environments.

For critical infrastructure, the concern is not only compromise but control-plane compromise. A network device or embedded system may not hold the crown jewels itself, but it can govern routing, visibility, segmentation, or operator access. That makes it strategically useful even when the direct payload is limited.

Organisations should therefore treat these assets as high-value access infrastructure. That means hardening remote administration, reviewing who can reach vendor support channels, restricting credential reuse, and prioritising telemetry on devices that sit at trust boundaries. Where patching or replacement is slow, compensating controls need to be stronger, not weaker.

Nation-state tradecraft also rewards ambiguity. If defenders do not have clean inventory, ownership, and logging, it becomes difficult to tell whether a legacy device is merely fragile or already a trusted pivot point. The response posture should assume that unsupported devices may be part of the attacker’s route until proven otherwise.

Risk and Threat Considerations

Legacy network devices create concentrated risk because they often combine weak authentication, long-lived configurations, and limited visibility. In critical infrastructure, that can turn a single exposed management interface or stale support account into a durable intrusion path with outsized downstream impact.

Failure mechanism: Attackers exploit the gap between modern Zero Trust policy and old-device reality, then use the device’s management plane, trust relationships, or network position to move laterally or maintain access.

Impact: The result can be persistent access, segmentation failure, loss of operational visibility, and broader compromise of adjacent systems that were assumed to be isolated.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-4 — Information Flow EnforcementLegacy devices need segmentation and allow-listed flows to limit lateral movement.
IA-2 — Identification and Authentication (Organizational Users)Admin access to fragile network gear still depends on strong operator authentication.
Recommendation — Enforce strict information flow rules around legacy devices and management paths. Require strong authentication for all privileged access to legacy device administration.
NIST Zero Trust (SP 800-207)5.1 — Never trust, always verifyThe question is fundamentally about adapting Zero Trust assumptions for high-risk infrastructure.
Recommendation — Treat legacy devices as untrusted resources and verify access before granting connectivity.
CIS Controls v8CIS-12 — Network Infrastructure ManagementThe subject centers on controlling and monitoring network devices in critical environments.
CIS-6 — Access Control ManagementRestricted administrative access is central to reducing exposure from vulnerable legacy devices.
Recommendation — Inventory, harden, and monitor network infrastructure devices with explicit ownership. Restrict and review access to legacy device management interfaces and support paths.

Practitioner Guidance

What to prioritise: Start with the assets that can still reach sensitive systems, accept remote administration, or influence routing and segmentation. Those devices create the highest blast radius, so they deserve faster replacement, tighter access paths, and the strongest monitoring.

What to verify: Confirm that every exception for a legacy device has an explicit owner, a business justification, and a technical control compensating for the missing native capability. If you cannot show how the device is isolated and observed, it is not yet operating under a Zero Trust model.

Practitioner takeaway: Zero Trust for legacy infrastructure is less about modernising the device and more about shrinking the device’s trust footprint until its compromise cannot become an enterprise-wide event.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org