Key takeaways
- Most utility incidents compromise IT systems, not the industrial controls themselves, and IT-side attacks still shut down operations.
- The file shares hold the most operationally sensitive documents a utility owns, and their reconnaissance value makes them a standing nation-state collection target.
- Pre-positioning campaigns like Volt Typhoon use valid credentials and living-off-the-land techniques that perimeter and endpoint tools were never built to catch.
- Small operators are targets too; attackers scale across the sector’s long tail.
- For lean utility teams, the answer is consolidation: storage that defends itself, keeps immutable recovery points, and produces the audit evidence regulators ask for.
Critical-infrastructure security conversations gravitate to operational technology: the controllers, the relays, the air gaps. That focus is deserved, but it can obscure where incidents actually begin. Utility compromises overwhelmingly start and often end on the IT side: business systems, email, and above all the ordinary file servers holding the organization’s institutional knowledge.
Consider what accumulates on a utility’s shares: one-line diagrams, substation drawings, SCADA and relay documentation, emergency procedures, vendor credentials in spreadsheets, decades of customer records. An attacker does not need to touch a controller to create leverage; encrypting or publishing that archive is disruption enough, and the reconnaissance value of the engineering documentation alone makes utilities a standing collection target.
The incidents keep proving the point
The most consequential infrastructure attack in recent American memory never touched a control system. The May 2021 Colonial Pipeline incident was ransomware on the IT side, and the pipeline stopped anyway: the company shut down operations because it could no longer trust or operate the business systems around them. The lesson generalizes. When the IT estate that schedules crews, bills customers, and holds the operating documentation goes dark, operations follow, whether or not a PLC was ever at risk.
The quieter campaigns are more alarming. CISA and its partners have documented Volt Typhoon, a state-sponsored actor pre-positioning inside U.S. critical infrastructure IT networks, not for immediate extortion but for future disruption. The tradecraft is exactly what the perimeter cannot see: valid accounts, living-off-the-land techniques using built-in tools, and patient collection of the documentation that would matter in a conflict. No malware to signature, no anomaly at the firewall, just legitimate-looking sessions reading engineering files. The only vantage point that sees that behavior for what it is sits at the data layer, where the reads themselves are visible and can be judged against what is normal for that account.
What the file share knows about the grid
It is worth being concrete about why these shares are worth pre-positioning for. The documentation on a utility’s IT file servers describes how the physical system works and how it fails: protection settings, interconnection agreements, black-start procedures, network diagrams that map the OT environment an attacker has not yet reached. IT/OT convergence has made this worse, not better; the engineering workstations that touch both worlds read their documentation from the same ordinary shares as everyone else. Defending the controllers while leaving their documentation unwatched secures the vault and publishes the floor plan.
Regulators have reached the same conclusion. NERC CIP-011 exists precisely because BES Cyber System Information, the documentation about critical systems, requires protection and accountable handling wherever it lives, and audits increasingly ask for evidence of who accessed that information, not just a policy stating who may. A per-operation audit record on the shares holding CIP-scoped information turns that request from a scramble into a query.
The long tail is the target surface
The sector is not a handful of giants; it is thousands of cooperatives, municipals, and districts running lean IT teams. Extortion crews understand this and scale horizontally. The ransom demand adjusts to the victim, but the playbook is identical. Florida Keys Electric Cooperative lived this arc: hit by ransomware in 2015, watching peers and neighbors targeted since, and ultimately deciding the file layer itself had to be able to detect and stop an attack rather than hope the perimeter held.
For a five-person IT shop, the arithmetic matters. A SOC-grade stack of detection tools demands staff a cooperative does not have; every additional console is a cost that competes with keeping the lights on. Security that requires around-the-clock human attention is security the long tail cannot operate, which is why the sector’s practical answer has to be automation at the point of attack, not more alerts about it.
What resilient looks like at a utility
The pattern that works for lean teams is consolidation rather than accumulation: storage that detects and stops malicious file activity on its own, holds immutable recovery points, keeps the audit trail regulators ask for, and does not require a 24/7 security staff to operate. Behavioral detection on every read and write covers both halves of the threat: the encryption run of an extortion crew and the patient document collection of a pre-positioned adversary. Inline response means the session is terminated in seconds, without waiting for a human who may be the same person restoring the billing system.
For the operators keeping power and water moving, the file share should be the most defended system they own, not the least. The organizations that internalize this stop treating storage as plumbing and start treating it as what the incidents show it to be: the terrain the adversary is actually walking.
Sources
Go deeper
