By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Why Living Off the Land (LotL) Attacks Can Have Catastrophic Impact on Operational Technology (OT) 

LOTL attacks don’t break into your infrastructure — they blend into it. Sam Alva (Novacoast) on why water and OT environments are uniquely exposed, and the isolation and recovery steps CISA says critical infrastructure operators need to start now.

According to FEMA, “Community Lifelines are categorized critical infrastructure made up of seven sectors, Energy, Communications, Water & Wastewater, Transportation, Health & Medical, Safety & Security and Hazardous materials.” As Geopolitical tensions continue to unfold around the world, we must face the reality that our community lifelines will be a target of opportunity. 

Living off the land (LOTL) techniques are primarily utilized against high-value targets, where stealth and long-term persistence are critical. State sponsored groups like China and Russia utilize techniques like Volt Typhoon and Sandworm against U.S. critical infrastructure (Primarily energy, water and communications) to disrupt civilian life, delay military responses and sabotage national infrastructure during conflicts. 

How Disruptions Pose Risk to Utilities and Critical Infrastructure 

Water, unlike energy and communication, is a single point of failure. The loss of drinking water and wastewater services immediately disrupts public health, economic stability and environmental safety. It halts essential daily activities, creates severe sanitation risk and paralyzes local and global industrial functions. 

Key disruptions to public health and safety are critical to consider. Without clean drinking water, severe dehydration and disease outbreaks like cholera, dysentery and typhoid rise sharply. Medical facilities, which require clean water for sterilization and patient care, can be paralyzed with serious consequences. Industry and the economy are also affected as utility services, manufacturing, and electricity generation rely heavily on uninterrupted water and wastewater operations. Disruption cause supply chain bottlenecks, agriculture losses, and severe economic setbacks. 

Current National Security Threats

As the U.S. remains in conflict with Iran, we are seeing significant escalated attacks on Operational Technology and Industrial Controls Systems (ICS). These campaigns primarily focus on pre-positioning (LOTL techniques) stealthy accessing networks and executing disruptive operations against critical infrastructure. 

Whether ransomware, worm, USB-carried, Trojan virus, or a sentiment-charged attack, the risk are prevalent and require action. Because they weaponize the victim’s own infrastructure, these attacks are difficult to detect, leaving minimal digital footprints and often making security professionals struggle to differentiate malicious activity from normal operations. LOTL attacks allow threat actors, including nation-states (China, Russia, Iran) and sophisticated criminal groups, to execute their campaigns in a way that blends in with normal network activity. 

Operational Technology vs. Information Technology

Protecting Operational Technology (OT) is unique due to its differences from normal information technology (IT). Timeliness and performance are huge factors when discussing Operational Technology (OT). OT systems are generally time critical, meaning every second counts when an OT system is offline. OT is operationally driven, whereas IT is data driven, meaning the primary goals in an incident response are vastly different between IT and OT. There are two distinct types of objectives when it comes system recovery, Recovery Time Objective (RTO) and Recovery Point Objective (RPO). 

System recovery in an OT environment may include communication links, critical manufacturing, and processing capabilities and is usually specified in terms of a Recovery Time Objective (RTO). Data recovery involves the recovery of data that describes production or product condition in the past and is usually specified in terms of a Recovery Point Objective (RPO). This is defined as the time for which an absence of data be tolerated.

Once you understand the differences between IT and OT, you then can then apply specific Defense-in-Depth OT disciplines. People, Processes and Technology are the three pillars in effectively protecting the OT environment. This includes convergence, which is the act merging of distinct disciplines and technologies into a unified whole. Establish OT Governance, which includes the policies, procedures and processes for managing the organizations regulatory, legal, risk and environmental and operational requirements. Lastly Technology, which can include secure by design/default and cyber-informed engineering which allows the secure on-boarding practices of devices and components utilizing the OT framework. 

Threats to Operational Technology will continue to grow, especially as this environment continues to be completely interconnected. Energy and water are lifelines that inherently dependent on one another and can have devasting cascading impacts if either one are loss. 

Cybersecurity Infrastructure Security Agency Guidance

On May 5th, the Cybersecurity Infrastructure Security Agency (CISA) unveiled a new initiative to fortify Americas Critical Infrastructure. The guidance is to help critical infrastructure entities across all sectors prepare to operate through a crises or conflict, continuing vital service delivery even as their systems are under attack. Key points in this guidance urge critical infrastructure entities to start now, if they have not already, to invest and develop isolation and recovery capabilities. 

Isolation: Proactively disconnecting from third party dependencies and operating with reliable telecommunications, internet vendors, service providers and upstream dependences

Recovery: Rapidly disconnecting vital compromised systems while isolated. A key part is testing recovery plans and practicing local and manual operations. 

Are we prepared? Are our customer and stakeholders prepared to disconnect and isolate from resources that are vital to business operations? Are your business continuity plans and engineering processes allowing you to operate safely for weeks to months while isolated?  These can only be addressed and answered by a comprehensive risk assessment. 


Sam Alva

Director of Operational Technology | Novacoast

About the Author

Sam Alva is a retired Kansas Air National Guard member with 21 years of service who now leads critical infrastructure and operational technology security initiatives. He previously served as Kansas’ Director of Critical Infrastructure and OT, and as a Protective Security Advisor and Cybersecurity Advisor for CISA. He is currently the Director of OT Security Sevices at Novacoast.

Previous Post

Top 10 Cybersecurity News (July 27, 2026): Ernst & Young Discloses Breach Of Third-Party Platform, Federal Agencies Update Warning On Iranian Targeting Of PLCs, and More

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.