Summary
Overview
The client, a gas distribution business, had recently completed a large-scale cloud migration program, and sought to ensure that its new environment was secure from both an OT security and cloud security perspective.
Reversec was approached to perform an Attack Path Mapping (APM) assessment to identify key security vulnerabilities across the client’s core gas control networks and cloud environment.
Company
Gas distribution company
Industry
Energy
Solution
We conducted a risk-led technical assessment using our Attack Path Mapping methodology. The findings from this engagement demonstrated what could be leveraged by an attacker with no access or with an arbitrary workstation within the on-premises environment, in pursuit of the following objectives:
- Obtain a level of access to the SCADA and ICS sites that would allow for disruption of service.
- Gain administrative access to the client’s AWS cloud environment from the residual on-premises estate.
- Disrupt the client’s business operations by impacting either the availability or integrity of critical services in the AWS cloud environment.
The client had taken steps to elevate its security posture, remediating several notable findings from a previous APM exercise. Still, we observed that basic IT security issues continued to diminish this overall improvement, and ultimately left the client exposed to risk.
Given the unsophisticated nature of the attack paths, it is reasonable to assume that a more advanced state actor, pursuant to financial or disruptive objectives, would achieve a similar result.
We identified three root causes that allowed us to traverse these attack paths:
- Shared IT infrastructure: Assets in AWS and the gas control environment were being administered from corporate endpoints. The compromise of these users often led to the subsequent compromise of cloud or gas control assets, weakening both cloud security and OT security.
- Weak passwords: Weak passwords were systemic across the business and materially weakened the client’s security posture. For example, 67% of all enabled Active Directory account passwords were successfully obtained in plaintext.
- Active Directory architecture: The sharing of the Active Directory forest root resulted in the integrity of one domain being dependent on the other. Compromise of the corporate environment immediately provided Reversec with the necessary privileges to target ICS assets.
Outcome
Following the Attack Path Mapping exercise, we provided a series of recommendations that would allow the client to increase its security posture and reduce its risk exposure.
At a high level, these included hardening the CNI boundary, strengthening passwords for both corporate users and Active Directory, and developing a detection and response capability.
Our accreditations and certificates








Don’t be a stranger, let’s get in touch.
Whether you’re facing a cybersecurity challenge or simply looking for advice, we’re here to help. Fill out the form and one of our experts will get back to you as soon as possible.
This site is protected by reCAPTCHA and the Google
Privacy Policy and Terms of Service apply.