Articles & Research

Retrospective

Colonial Pipeline: what ransomware taught operational technology

The May 2021 shutdown of a major US fuel pipeline exposed how brittle the line between IT and OT security had become.

Marcus Whitfield

Senior Editor, American Computer Society

May 2021 · 6 min read

Analysts monitoring threat dashboards in a security operations centre
Analysts monitoring threat dashboards in a security operations centre

On 7 May 2021 a ransomware attack forced Colonial Pipeline to halt fuel deliveries across the southeastern United States, triggering panic buying and a $4.4 million ransom payment. The incident remains one of the clearest illustrations of why critical infrastructure security demands specific professional discipline.

A single credential, a national shortage

On 7 May 2021 Colonial Pipeline Company discovered that ransomware operated by the DarkSide group had infiltrated its billing systems. Out of caution the company halted the entire 5,500-mile pipeline that carries roughly 45 percent of the fuel consumed on the US East Coast. The shutdown lasted several days and produced fuel shortages, long queues at filling stations and states of emergency in several states.

The intrusion reportedly began with a single compromised password for a virtual private network account that lacked multi-factor authentication, tied to a legacy system that was not actively in use but had not been decommissioned. Colonial's chief executive, Joseph Blount, later told Congress the company authorised payment of a $4.4 million ransom, of which the Department of Justice subsequently recovered roughly $2.3 million in bitcoin.

“A corporate IT incident produced a physical, national-scale disruption — and the pipeline itself was never actually compromised.”

IT breach, OT consequence

Colonial's operational technology, the systems that physically control pumps and valves, was not itself compromised. The pipeline was shut down as a precaution because the company could not be confident the ransomware would not spread from its corporate IT network into the systems used for billing customers by volume, which are themselves intertwined with operational metering. That distinction mattered less to the public than the outcome: a corporate IT incident produced a physical, national-scale disruption.

The episode accelerated federal action. The Transportation Security Administration issued its first cybersecurity directives for pipeline operators within weeks, mandating incident reporting to CISA and, later, more prescriptive requirements for network segmentation and contingency planning — obligations that a decade of voluntary guidance had failed to produce.

The persistent IT/OT divide

Colonial Pipeline was not an outlier. Surveys of utilities and industrial operators conducted in the aftermath consistently found that many organisations still lacked network segmentation between corporate IT and industrial control systems, still permitted single-factor remote access, and still had incomplete asset inventories of their OT environments.

  • Segment IT and OT networks and treat any bridging system as high-risk.
  • Enforce multi-factor authentication on all remote access, with no legacy exceptions.
  • Maintain a current inventory of OT assets and their exposure.
  • Rehearse manual fallback operating procedures, not only IT recovery.

What the Society advises

The Society urges practitioners working across critical infrastructure to treat OT security as a distinct discipline requiring its own competence, not an extension of enterprise IT practice. Engineers should decommission unused access paths as rigorously as they patch known vulnerabilities, and organisations should ensure that professionals with authority over industrial systems hold current, verifiable credentials.

The Society continues to recommend mandatory incident disclosure for critical infrastructure operators, continuing professional development in industrial control system security, and clear lines of accountability between corporate leadership and the engineers responsible for physical safety systems.

CybersecurityPublic policy

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member