SANS Spotlight: Why VPN and MFA Is Not Enough for OT: Evidence from the SANS State of ICS/OT Security Report
Created: Thursday, June 4, 2026 - 17:22
Categories:
(TLP:CLEAR) VPNs and MFA remain essential for securing remote access into OT environments — but recent research suggests they may not be enough on their own. In the blog “Why VPN + MFA Is Not Enough for OT,” Michael Hoffman of Dragos highlights findings from the 2025 State of ICS/OT Security Survey, including that half of reported OT incidents involved unauthorized external access. The article explores ongoing visibility, monitoring, and resilience gaps, along with security capabilities gaining attention across critical infrastructure sectors. Read the blog to explore the findings and access the full survey report.
