ISJ hears exclusively from Remi Ramcharan, Vice President of Senkron Digital about why critical infrastructure operators can no longer mistake normal operations for a secure environment.
Operators in critical infrastructure often fall into the trap of an old saying, “Don’t fix what’s not broken.”
If systems are running, production is stable and there are no obvious signs of disruption, then the environment must be secure, right?
Unfortunately, that’s not always the case.
This mindset exists for a fair reason as cyber-threats in the past have typically demanded immediate attention with a clear attack.
From ransomware and distributed denial-of-service attacks to major outages, their impact is instant and measurable causing systems slow down or stop, or resulting in an interruption to production and operations teams are forced to respond.
Over time, that has trained much of the industry to associate cyber-compromise with disruption.
So in other words, if operations are running normally, everything is probably fine and there’s no need to go looking for problems or trying to fix something that doesn’t appear broken.
This mindset isn’t unique to cybersecurity either.
In critical infrastructure, there can be a tendency to focus on the issues that pose an immediate operational risk, while lower-level problems that aren’t affecting performance today are deprioritised.
Take corrosion in a refinery, if it’s not threatening production, it can be easy to push it down the priority list.
But left unchecked, that same issue can grow into something far more disruptive and expensive to fix.
Cybersecurity increasingly demands the same mindset as good asset management – not just fixing what’s broken today, but identifying and addressing the issues that could become tomorrow’s biggest operational risks.
Increasingly, access comes before disruption
Over the past year or so especially, there has been a change in both the objective and behaviour of attackers as they become smarter and more patient.
They are trading quick disruptions for time spent establishing a presence within systems.
Whereas previously it was possible to identify an attacker through the objective of creating immediate operational impact, now the objective is to gain access, maintain that access, understand the environment and position themselves for future influence, if and when circumstances require it.
This is particularly the case in critical infrastructure, where operational technology (OT) environments are becoming more connected and dependent on complex interactions between systems (including IT systems), suppliers and remote operators.
This is the perfect environment for attackers to solidify unnoticed access and, as a result, the absence of disruption no longer provides the assurance it once did.
A useful analogy is leaving a spare key under a doormat.
Many will have done it; it was the age-old way to make sure someone who you trusted could get into your house if you weren’t there.
But that relies on no bad actors finding that key first. And if they do, there is no need to break a window or force open a door; it’s a quick, unnoticed access.
Maybe nothing is taken the first time, or the second time, but they will be assessing the room layout, seeing what might be valuable and waiting for the right moment.
To anyone reading that, it’s an alarming and unsettling thought and a reason many people actually no longer leave the key under the mat!
But we must hear it because that same scenario is playing out digitally. In modern cyber-breaches, attackers linger outside the core system, biding their time while compromising identities, credentials and legitimate access pathways.
Once inside, they can operate using the same tools, permissions and connections that authorised users rely on every day.
The challenge of detecting what does not disrupt
We can see evidence of this trend in the way attacks are affecting operational environments today.
According to recent Senkron Digital threat intelligence reporting, 60% of organisations experiencing cyber-incidents in 2025 reported impacts across both IT and OT environments, up from 49% the previous year.
As the traditional separation between IT systems and OT systems continues to narrow, this emphasises how new pathways through which exposure can spread are being created.
At the same time, the speed of modern attacks continues to increase.
Senkron Digital’s recent findings show that the progression from initial compromise to wider access can now occur in less than 30 minutes.
This is evidence to conclude that organisations can’t still rely on indicators such as outages, performance degradation or operational anomalies because by the time visible symptoms emerge, an attacker may already have moved well beyond the original point of entry.
On top of this, many of the indicators traditionally associated with cyber-incidents were designed to identify disruption, not threats that are deliberately avoiding attention.
As a result, an environment can remain fully operational while an attacker maps assets, studies processes, escalates privileges and establishes long-term access.
All the while, production targets are still being met, systems continue to function normally and safety systems remain unaffected.
Operationally, everything appears healthy, so how can operators know whether exposure already exists?
IT and OT convergence is changing the risk game
This question is particularly important within sectors that underpin national economies.
As energy critical infrastructure becomes increasingly digital and connected, security depends far more on how the systems supporting that infrastructure can be monitored, governed and protected under pressure.
To get the full picture, cybersecurity has to be both an OT and IT concern, especially as a breach in an IT environment can now act as a gateway into the operational systems that keep power grids running, water plants functioning and offshore platforms producing.
The more interconnected these environments become, the easier it becomes for an attacker to establish a foothold in one area and extend their presence elsewhere.
This is what makes prolonged, undetected access particularly dangerous.
An attacker does not need to create disruption if they can build an understanding of operational processes, position themselves within critical environments and maintain access without detection.
The vulnerabilities that allow this are often not the most sophisticated either.
Unmanaged remote access, incomplete asset visibility, unclear ownership between IT and OT teams, legacy operational equipment and extensive third-party connectivity continue to create opportunities for attackers to establish footholds without generating immediate concern.
Visibility is the new security imperative
Organisations cannot secure what they cannot see, especially when today’s threats are designed to avoid attracting attention.
To tackle this, it requires understanding not only whether an incident has occurred, but whether conditions exist that could allow an attacker to operate undetected.
That means understanding identities, remote connections, third-party relationships, operational assets and the pathways linking IT and OT environments together.
Continuous exposure awareness is becoming increasingly important here because normal operations no longer prove a clean environment.
Organisations need to understand where access exists, how that access is being used and whether conditions are developing that could allow an attacker to establish or maintain a presence without detection.