ISPs are attractive because they sit at a chokepoint for communications and can expose traffic patterns, metadata, and personnel movement across multiple organisations. If an attacker can monitor or manipulate that layer, the payoff extends beyond one victim. In geopolitical campaigns, that upstream access can support espionage, reconnaissance, and later-stage disruption against public and private targets.
Why ISP Access Is So Valuable in Critical Infrastructure Campaigns
ISPs are not just another downstream target. They sit where traffic converges, which means access there can reveal who is talking to whom, when activity changes, and which organisations are being watched or reached. That makes ISP compromise especially useful for campaigns that need broad visibility, selective interception, or a foothold that can be leveraged against many victims at once.
At the operational level, that chokepoint matters because it can turn one intrusion into a collection platform. Attackers can use upstream visibility to identify valuable internal systems, map relationships between public and private entities, and time follow-on action more effectively than if they were operating inside only one network.
For critical infrastructure campaigns, the issue is not just access to a provider. It is access to a layer where routing, metadata, and trust relationships intersect. That makes ISP environments strategically attractive for espionage, reconnaissance, and staging, especially when the end goal is broader disruption rather than a single isolated breach.
Where the subject is critical infrastructure threat activity, the most relevant control question is often whether the defender can see and constrain what an upstream compromise would expose. A useful reference point is CISA cyber threat advisories, which regularly frame adversary behaviour against critical sectors.
For broader sector context, ENISA Threat Landscape and CISA Industrial Control Systems resources help explain why upstream access matters when communications, availability, and operational visibility are part of the attack surface.
What Attackers Gain From a Provider-Level Foothold
A provider-level foothold changes the attacker’s economics. Instead of attacking many organisations one by one, they can observe traffic patterns across a shared service layer, infer high-value relationships, and pick victims or windows of opportunity with better accuracy. That is especially useful in campaigns that need stealth, persistence, or later-stage targeting after the first intrusion.
It also broadens the blast radius. If an ISP is used to support interception, manipulation, or traffic redirection, the compromise can affect multiple customers and multiple tiers of dependency at once. In practical terms, that means the defender is dealing with a shared trust boundary, not just an isolated endpoint or server.
This is why upstream compromise is often paired with downstream actions such as credential theft, reconnaissance, or selective disruption. Once attackers can observe patterns at scale, they can decide which organisations, personnel, or services are worth deeper exploitation and which can be left untouched until later.
A useful evidence point for this kind of campaign is NHIMG’s The 52 NHI breaches Report, which shows how credentialed access and lateral movement frequently turn a single foothold into wider compromise. In adjacent infrastructure cases, JumpCloud Breach illustrates how one upstream compromise can create downstream exposure for many customers.
For the control perspective, CSA Cloud Controls Matrix is useful when organisations need to map shared-service exposure, supplier trust, and identity control boundaries across interconnected environments.
Risk and Threat Considerations
ISP targeting is risky because the compromise sits above many victims at once. Even limited visibility or manipulation at that layer can create disproportionate exposure, especially when attackers are after metadata, communications mapping, or a route into higher-value networks and operational partners.
Failure mechanism: An attacker abuses the ISP’s position in the communications path to observe, redirect, or infer activity across multiple organisations, then uses that intelligence to support espionage, credential capture, or later-stage disruption.
Impact: The result can be multi-tenant exposure, broader victim enumeration, and attack amplification across critical infrastructure, with consequences that outlast the original intrusion.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC-2 — Cyber Supply Chain Risk Management | ISP targeting is a supplier and dependency risk across shared communications services. |
| DE.CM-01 — Networks and Systems Monitored | ISP compromise can hide or alter traffic patterns that defenders need to observe. | |
| RC.RP-1 — Recovery Plan Executed | Critical infrastructure campaigns can cause downstream disruption after provider compromise. | |
| Recommendation — Assess ISP dependency exposure and require upstream incident notification, monitoring, and recovery obligations. Monitor network paths and metadata for abnormal routing, interception, or provider-side changes. Test recovery procedures that assume shared-service or provider-layer compromise. | ||
| CIS Controls v8 | 15.3 — Service Provider Management | ISP compromise is a third-party and shared-service risk that needs explicit oversight. |
| Recommendation — Define security requirements, monitoring, and notification terms for critical service providers. | ||
| MITRE ATT&CK | T1040 — Network Sniffing | Attackers target ISPs to observe traffic and collect useful communications intelligence. |
| T1021 — Remote Services | Provider environments are often reached through remote administrative access that can be abused. | |
| T1090 — Proxy | Upstream infrastructure can be used to route or mask attacker operations across victims. | |
| Recommendation — Hunt for provider-path collection activity and unusual traffic inspection or capture. Restrict and monitor remote administrative access into provider-managed environments. Detect and block unauthorized proxying or traffic redirection through shared infrastructure. | ||
| NIS2 | Article 21 — Cybersecurity Risk-Management Measures | Critical infrastructure campaigns affecting providers map to governance of technical and organisational measures. |
| Recommendation — Apply risk-management measures that account for supplier and communications-layer compromise. | ||
| NIST Zero Trust (SP 800-207) | SC-7 — Continuous Diagnostics and Mitigation of Access Paths | A provider foothold is a trust-path problem that Zero Trust directly addresses. |
| Recommendation — Continuously validate access paths and remove implicit trust in upstream service layers. | ||
Practitioner Guidance
What to prioritise: Treat upstream provider compromise as a shared-visibility problem, not only a perimeter problem. The key question is whether a compromise at the ISP layer would expose metadata, relationships, or operational timing that would materially help an attacker.
What to verify: Confirm that provider access paths, monitoring coverage, and contractual incident obligations are strong enough to detect unusual routing, admin activity, or traffic-handling changes before they become a campaign enabler. If those checks are missing, assume the attacker has a better view than you do.
Practitioner takeaway: The strategic risk is not just loss of one provider account, it is loss of the layer that lets attackers see and shape activity across many organisations at once.
Related resources from NHI Mgmt Group
- How should security teams contain attacks against critical infrastructure when multiple facilities are affected at once?
- How should security teams improve resilience when cyberattacks target critical infrastructure during geopolitical conflict?
- Why do attackers target identity infrastructure soon after they get a foothold in a network?
- How should incident response teams prepare for cyberattacks against critical infrastructure before a real crisis hits?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org