Skip to content

When Detection Cannot Move Fast Enough

How a prevention-based endpoint architecture can turn familiar OT guidance into enforceable, repeatable controls

A recent Newsweek article, “Water Supply Poisoning Risk Via AI Cyberattack Is Real, Expert Warns,” examined a disturbing convergence: accelerating AI-enabled attack methods, geopolitical targeting of critical infrastructure and the persistent exposure of resource-constrained water and wastewater systems. The article was intentionally vendor-agnostic. Its central warning, however, leads to a practical architectural question: how can operators make established guidance enforceable across the endpoints and access paths surrounding critical operations?

The guidance is familiar. The urgency is not.

The fundamentals of the threat—and much of the guidance on what to do—remain familiar: know the assets; remove direct internet exposure; control remote access; segment operational networks; enforce least privilege; maintain trusted backups and tested methods for rapid recovery; and monitor for unauthorized activity.

What has changed is the urgency. AI is accelerating vulnerability discovery, lowering the expertise needed to adapt available tools and compressing the path from discovery to exploitation from months to days—and, in some cases, hours. At the same time, geopolitical tension is making U.S. critical infrastructure a more likely target for retaliation, disruption and pre-positioning.

Operationally targeted malware is also moving closer to a living-off-the-land model for OT. Legitimate administrative tools, open-source libraries, valid credentials and existing remote-access paths can be repurposed against the operation. The malicious action may initially resemble normal maintenance or administration, making intent harder to distinguish and giving defenders less time to react.

Why detect, patch and respond cannot carry the full burden

Detection, network monitoring, EDR, vulnerability management, patching and incident response remain essential. But a model that depends primarily on recognizing the threat, producing an update and remediating every exposed system is increasingly mismatched to the speed of the problem—especially in OT environments where uptime, safety validation, long equipment lifecycles and limited maintenance windows constrain change.

The architectural objective must therefore move farther upstream: reduce what can execute, what can persist, what an identity can reach and how far a compromise can move before it reaches the physical process. This is the shift from cybersecurity alone to cyber resilience. The decisive question is no longer only whether an adversary can gain a foothold. It is whether that foothold can gain control over the operation.

 

Established objective Architectural enforcement at the endpoint edge
Know the assets Require managed endpoint enrollment and maintain centrally governed identity, configuration and policy state.
Remove direct exposure Broker application and administrative access through controlled paths rather than exposing operational endpoints directly.
Segment IT and OT Integrate endpoint identity and posture with network-access and segmentation controls using a comply-to-connect model.
Enforce least privilege Deliver only the applications, protocols, peripherals and destinations required for a user, device and operational role.
Limit persistence Use an immutable, read-only endpoint foundation and centrally approved software to reduce arbitrary execution and durable local change.
Recover rapidly Return an endpoint to a centrally defined, known-good operating state without rebuilding a conventional PC image.

The IGEL Preventative Security Model™

The IGEL Adaptive Secure Endpoint Platform™ is designed to operationalize this prevention-based model at the endpoint edge. It combines a hardware-backed chain of trust, a modular and read-only operating system, centralized management through the IGEL Universal Management Suite™ (UMS), curated application delivery and policy-driven configuration. The result is a substantially smaller mutable attack surface than a conventional general-purpose endpoint.

This matters in water and other critical environments because the attack does not have to begin at the PLC. A compromised engineering workstation, HMI access endpoint, administrator credential, remote-support path or general-purpose device can provide the bridge toward the process. IGEL creates a managed trust and policy boundary around those access points. It does not claim to replace PLC hardening, ICS-aware monitoring, network controls or secure engineering practices; it helps prevent weaknesses at the endpoint and access layers from becoming control of the physical operation.

A unified edge control plane for heterogeneous IT and OT

Utilities rarely have the option to replace their operating environment wholesale. They must support multiple hardware generations, specialized OEM applications, browsers, remote-display protocols and partner tools while maintaining availability. The IGEL platform is intended to sit across that heterogeneous edge, supporting qualified x86 endpoints and integrating with the existing identity, network, security and application ecosystem, so policy does not have to be recreated device by device.

UMS provides centralized enrollment, configuration, application assignment and policy enforcement. When connected to identity and network-access controls, enrollment and device posture can contribute to a comply-to-connect decision: an unknown, unmanaged or noncompliant endpoint should not receive the same access as a known device in a trusted state. Contextual policy can further restrict what is available according to the user, endpoint, location, network, risk state and operational role.

The platform also supports a curated application model with our over 130 IGEL Ready partners who are the leaders in the industry. Rather than allowing arbitrary software to be installed and persist locally, approved applications and configurations are delivered centrally with certificate-based attestation. This helps utilities standardize secure browser access, remote connectivity and OEM workflows while limiting application sprawl and configuration drift.

Ransomware containment and known-good recovery

On a conventional mutable endpoint, malware may alter the operating system, establish persistence, encrypt local applications or data and complicate restoration. With IGEL, the core operating system is read-only during normal operation, applications and configuration are centrally governed, and business data can remain in protected upstream systems rather than on the endpoint. If an endpoint or session is suspected of compromise, the device can be isolated, restarted and returned to its defined operating state far more quickly than a traditional PC rebuild.

This is not a claim that an immutable endpoint eliminates ransomware across identity, network, server, SaaS or application layers. It changes the endpoint’s role in the incident: from a durable platform for persistence and local encryption to a controlled access device designed for containment and rapid restoration. Combined with segmentation, strong identity, protected backups and tested continuity procedures, this can materially reduce the probability that an endpoint event becomes an extended operational outage.

Making strong security practical for smaller utilities

The resource problem is central to the water-sector challenge. Many utilities cannot staff a large OT security team, operate a separate tool for every device class or replace functioning industrial systems simply to obtain a modern security posture. Centralized policy, reusable endpoint profiles and curated application delivery allow a small team to apply consistent controls across many locations. Existing qualified hardware can often be repurposed, reducing capital cost and avoiding unnecessary disruption.

That operational simplicity is not merely an efficiency benefit; it is a security control. The fewer one-off configurations, unmanaged endpoints and manually maintained software stacks an organization must support, the easier it becomes to establish a known state, demonstrate governance and recover under pressure.

Protect the architecture around the process

The Newsweek warning should not be interpreted as a problem limited to one PLC manufacturer, one utility class or one attack technique. Products and vulnerabilities will change. The more durable risk is the architecture around the process: exposed access paths, unmanaged endpoints, excessive privilege, mutable operating environments and inconsistent controls across legacy infrastructure.

IGEL’s answer is an Enterprise Edge Platform built on a Preventative Security Model: establish a trusted endpoint foundation; enroll before granting access; centralize policy; permit only approved applications and paths; integrate with identity, network and security controls; minimize persistent local state; and restore rapidly to a known-good condition.

We already understand much of what critical infrastructure must do. The next step is to make those principles executable at scale. Assume the threat may already be present. Reduce what it can exploit. Control what it can reach. And ensure that compromise somewhere in the enterprise does not become control of the critical operation.

Sources and further reading

  • Hollie Silverman, “Water Supply Poisoning Risk Via AI Cyberattack Is Real, Expert Warns,” Newsweek, August 24, 2026.
  • NIST SP 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access), June 2026.
  • CISA, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” July 30, 2026.
  • Joint Cybersecurity Advisory AA26-231A, Defending Against an Active Threat to Siemens S7 Series PLCs, August 2026.
  • IGEL Adaptive Secure Endpoint Platform™ and Preventative Security Model™ product architecture.

John Walsh

Field CTO – Critical Sectors at IGEL
Tagged Tags:
Back To Top