Securing Critical Water Infrastructure and Halting OT Cellular Lateral Movement

The vulnerability of critical infrastructure to remote access exploits has moved from theoretical risk to active operational disruption. Recent cyberattacks targeting water utility companies across several states have exposed a critical security gap in how municipalities manage remote operational technology (OT) systems. Adversaries are actively exploiting cellular modems—the primary link used to monitor remote water treatment facilities, pumping stations, and distribution nodes. Once inside, these attackers leverage the implicit trust of legacy network architectures to move laterally, targeting programmable logic controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) systems.
The Anatomy of Cellular Modems as Entry Points
Cellular modems are deployed extensively in critical infrastructure because physical cabling to remote sites is often cost-prohibitive. These modems operate over cellular networks, acting as gateways for telemetry data. However, this deployment model introduces a massive attack surface. Remote modems are frequently exposed to the public internet or placed behind poorly configured private Access Point Names (APNs). Attackers utilize automated scanners to locate these entry points, exploit unpatched software vulnerabilities, or leverage compromised credentials to gain a foothold.
Once an adversary compromises a remote cellular modem, the primary structural failure of traditional OT networks becomes apparent: lateral movement. Standard networking models rely on IP-based routing, which assumes that any device within a designated network segment is trustworthy. Once past the modem’s perimeter, the attacker is effectively inside the local network. They can scan the environment, locate sensitive systems, and send unauthorized control commands directly to critical processes.
The Inadequacy of Traditional Network Perimeters
Standard industry remediations have proven insufficient. Implementing private APNs, deploying cellular Software-Defined Wide Area Networks (SD-WANs), or wrapping traffic in legacy Virtual Private Networks (VPNs) merely shift the perimeter. They do not eliminate it. These traditional architectures still expose listening ports to the network and rely on legacy IP routing. If an attacker compromises a single endpoint or steals a cryptographic key, they gain access to the routing table. They can then sweep the entire subnet. What is required is a complete departure from IP-based routing in operational environments—a shift to an architecture where connectivity is authenticated by cryptographic identity rather than network location.
Concealing Remote Telemetry with Conflux Identity Mesh
To address this architectural vulnerability, organizations must decouple critical telemetry from the underlying transport medium. This is where VeilNet Conflux redefines remote OT networking. Conflux provides identity-authenticated mesh networking, establishing a secure overlay that operates independently of public or private IP routing. Under the Conflux architecture, network interfaces do not expose public IP addresses, and they do not listen on open inbound ports. This makes the remote telemetry nodes entirely invisible to external network scanners.
The foundation of Conflux lies in its ability to enforce a meta air gap. In a traditional air-gapped network, physical isolation prevents data flow. Conflux delivers the security benefits of an air gap while allowing secure, bidirectional data transfer across logically separated networks. Because Conflux endpoints require explicit cryptographic authentication to establish peer-to-peer tunnels, an attacker who compromises a cellular modem finds themselves in a network vacuum. There are no IP addresses to ping, no ports to scan, and no routes to exploit. The compromised modem is isolated from the rest of the operational network, halting lateral movement before it can begin.
Neutralizing Eavesdropping with Quantum-Resistant Routing
Furthermore, remote telemetry often transits public cellular networks, making it vulnerable to interception. Adversaries are increasingly harvesting encrypted traffic with the intention of decrypting it once quantum computing becomes viable. Conflux addresses this risk directly through quantum-resistant packet routing. By integrating post-quantum cryptography (PQC) standards directly into its routing protocols, Conflux ensures that telemetry data remains secure against both current threats and future quantum-decryption techniques. Even if an adversary intercepts the encrypted packet stream from a cellular tower, the data remains permanently unreadable.
Securing the Industrial Data Plane with Aether Protocol Validation
Securing the network transport layer is only the first step. Critical infrastructure protection also requires deep validation of the data itself. Below the application layer and above the Conflux network layer, VeilNet Aether manages the industrial data plane. Remote water utility sites rely on industrial protocols like OPC UA to transmit sensor readings and control commands. Legacy systems often run these protocols without authentication or encryption, assuming the underlying network is secure.
Aether provides dedicated OPC UA integration to solve this vulnerability. Aether acts as a protocol-aware proxy that translates legacy OPC UA traffic into secure, authenticated streams that flow exclusively over the Conflux mesh. It validates every message at the protocol level, preventing attackers from injecting arbitrary or malicious commands. If an unauthorized device attempts to send commands to a PLC, Aether detects the lack of cryptographic identity and drops the traffic immediately.
Restricting Lateral Action with Decoupled Protocol Proxies
By decoupling the data plane from the network plane, Aether ensures that even a highly sophisticated attacker who gains physical access to a remote site cannot pivot. They cannot execute arbitrary RESTful API queries or manipulate machine learning workflows. Aether’s integration engine ensures that only pre-approved, cryptographically verified application streams can communicate. This structural separation prevents the generic protocol exploitation that often follows a perimeter breach.
Moreover, as modern OT environments integrate more intelligent agents and remote diagnostics, the data plane must evolve. Aether supports Model Context Protocol (MCP) and RESTful API integrations, allowing secure machine-to-machine communication without introducing the risks of traditional web-facing APIs. This means utilities can implement predictive maintenance and automated analysis at remote pumping stations without exposing their OT systems to web-based attack vectors.
Hardening Critical Infrastructure Against Remote Exploitation
The recent targeting of critical municipal systems demonstrates that the era of relying on physical isolation or legacy perimeters is over. Relying on cellular modems secured only by standard VPNs or private APNs is an open invitation to lateral exploitation. By deploying VeilNet Conflux, water utilities can render their remote assets invisible to the public internet, sealing off the network with a meta air gap and protecting it with quantum-resistant packet routing. Simultaneously, VeilNet Aether secures the industrial data plane, ensuring that OPC UA telemetry and control streams are cryptographically validated and immune to lateral injection. Security in critical infrastructure must be absolute, beginning at the identity layer and extending through every byte of operational data.
Securing Critical Water Infrastructure Against State Sponsored OT Exploits
Securing municipal water systems and critical OT networks against state-sponsored exploits requires post-quantum cryptography and zero-trust mesh networking.
Securing Water Utility Critical Infrastructure Against Cellular Gateway Exploits
How municipal water utilities can secure remote cellular modems and PLCs using VeilNet's quantum-resistant network mesh and secure industrial data plane.