Deploying Defensible Compensating Controls for Critical Infrastructure

How federal energy, power, and utility operators can reduce breach spread across fragile OT environments while managing operational risk.

table of contents

On July 30, the FBI and EPA warned that, since July 27, water and wastewater utilities in at least seven states had reported incidents involving cyberattacks against internet-facing programmable logic controllers. Some incidents degraded operations, including loss of water pressure and flooding.

For federal teams responsible for energy, power, and utility infrastructure, the warning is hard to dismiss. The systems that are most difficult to patch, replace, or take offline can also become pathways to much larger operational consequences.

A Compromised Asset Is Only the Starting Point

In the July incidents, attackers remotely accessed operational technology devices and changed passwords and IP addresses. The result was loss of monitoring and, in some cases, functionality of connected equipment. FBI and EPA guidance also advised organizations to review logs and configurations on connected devices, including modems, HMIs, and workstations, to assess potential lateral movement.

The harder question is not whether a PLC, engineering workstation, or legacy server can be compromised, but what it can reach next.

As IT and OT environments become more connected, trusted pathways can link systems that were once easier to separate. A single foothold can become more consequential when an attacker can move toward SCADA systems, operational applications, or other assets supporting essential services.

Resilience cannot depend on preventing every initial compromise. Resilience also depends on limiting how far a compromise can spread.

When Remediation Is Delayed, Exposure Persists

Containing an incident becomes harder when the exposed system cannot simply be patched, rebooted, or replaced.

Legacy OT may depend on vendor support, narrow maintenance windows, or operating systems that cannot support standard security tooling. In power, water, and industrial environments, the consequences of an unsuccessful security change can be serious enough that operations teams have good reason to proceed cautiously.

That leaves agencies managing two risks at once:

  • Cyber risk: Leaving a vulnerable or end-of-life system exposed while remediation waits
  • Operational risk: Introducing a change that interferes with an uptime-sensitive process

The July FBI and EPA guidance addresses exactly this problem. The guidance recommends replacing or isolating end-of-life assets and, when replacement is delayed, applying compensating controls with firm decommission dates.

The question, then, is not whether patching still matters. It is how to reduce exposure defensibly while patching, replacement, or modernization continues.

What Makes OT Compensating Controls Defensible?

A compensating control should do more than satisfy a documentation requirement. It should give cyber, operational, and agency leaders credible evidence that a known risk is being reduced without creating unacceptable disruption.

For critical infrastructure, that means asking whether controls can:

  • Restrict unnecessary pathways into and between sensitive operational systems
  • Reduce the ability of a compromise to spread toward critical operations
  • Work within the constraints of fragile, distributed, and uptime-sensitive environments
  • Allow teams to validate the effect of proposed controls before enforcement and introduce changes progressively to reduce operational risk
  • Provide evidence that controls are implemented and operating as intended

A network diagram showing where separation is supposed to exist is not the same as knowing which systems are actually communicating, which paths remain available, and whether containment will hold when it is needed.

Resilience Starts With Knowing Where You Can Contain

Recent federal guidance also emphasizes planning for operational isolation and containment.

On July 28, CISA and its partners released CI Fortify guidance to help critical infrastructure operators prepare to isolate vital OT and enabling systems during a serious cyber incident. Among its recommended steps are identifying vital systems, mapping connections, and establishing effective separation points before a crisis occurs.

The guidance does not prescribe a particular technology. It reinforces a practical resilience principle: operators need to understand dependencies, know what must keep running, and establish effective isolation points before an incident so they can contain a breach without creating a second operational problem.

That is especially relevant for energy, power, and utility organizations with distributed infrastructure, legacy equipment, and limited opportunities for disruptive change.

Also Read: Operational Resilience Starts with Risk-Intelligent Microsegmentation

A Lower-Operational-Lift Approach Can Accelerate Risk Reduction

Critical infrastructure resilience does not have to begin with an enterprise-wide transformation.

A more practical starting point may be one critical environment, operational workflow, asset class, or group of high-consequence connections. Map the dependencies. Identify the pathways that create the greatest potential for breach spread. Determine where additional containment would materially reduce risk.

Then expand from evidence rather than assumption.

That approach matters for teams already balancing patch backlogs, modernization programs, compliance responsibilities, and daily operational demands. A security initiative that creates another major engineering burden can reinforce the very status quo agencies need to change.

Starting with a bounded problem can make progress easier to validate and operational risk easier to manage.

Access the Forrester Wave™: Microsegmentation Solutions, Q3 2026 to see why ColorTokens was the only Leader to earn a 5/5 “Superior” score in the OT, healthcare, and IoT criterion.

Start With One Question: How Far Could a Breach Travel?

The recent water-sector attacks provide a useful reminder for every critical infrastructure operator: an incident does not have to begin in a critical system to threaten the mission.

What could a compromised asset reach in your environment today? Which operational dependencies could become part of the attack path? Where would existing controls stop lateral movement, and where are teams relying on assumed separation?

Those answers can help determine where compensating controls are needed now, where they can reduce exposure while remediation is scheduled, and where modernization should come next.

Federal energy, power, and utility operators cannot trade cybersecurity progress for operational continuity. The goal is to do both: contain a compromise before it reaches critical operations and give teams a practical way to keep essential systems running.

Start With One Priority Containment Problem

Start by identifying the critical systems and connections where containing breach spread would make the greatest difference to operational resilience.

If you are evaluating where compensating controls can reduce breach spread in your environment, connect with one of our government security advisors.