Why Firewalls Cannot Isolate OT Networks

In July 2026, a coordinated cyberattack targeted operational technology at more than 30 community water systems in Minnesota, prompting the FBI and EPA to issue a broader warning that water and wastewater utilities in at least seven states had reported incidents involving internet-facing PLCs. Attackers changed IP addresses and passwords, and the FBI reported operational effects including loss of pressure and flooding. In a new article, Benny Czarny, CEO, Founder and Chairman of the Board of OPSWAT, uses these attacks and previous incidents to make the case that firewalls, while necessary, do not equal isolation, and that critical infrastructure should default to one-way data flows combined with content inspection.

What the Minnesota and Volt Typhoon Attacks Reveal

The Minnesota attacks on July 26 and 27 prompted a statewide cybersecurity response, with the FBI later finding similar third-party network configurations across several victims that may have allowed attackers to repeat the same success.

These incidents follow a pattern. In the Volt Typhoon campaign, Chinese state-sponsored actors likely gained initial access by exploiting CVE-2022-42475 in an unpatched FortiGate 300D perimeter firewall. The device installed to protect the perimeter became the path through the perimeter. In December 2015, attackers compromised three electricity distribution companies, moved from IT into operational systems, accessed the ICS environment through VPN infrastructure, operated electrical breakers, and caused outages affecting approximately 225,000 customers.

Each case involved a bidirectional network path that attackers used to reach operational technology.

Why a Firewall Is a Guard, Not a Wall

OPSWAT draws a distinction between filtering and isolation. A firewall examines traffic, applies thousands of rules, checks credentials, and decides what enters and leaves. That function is valuable, but the connection remains bidirectional.

“I think of a firewall as a very smart security guard standing in front of a door. The guard knows thousands of rules. It looks at credentials. It examines traffic. It decides what is allowed to enter and leave. That is extremely valuable. But there is still a door,” Benny Czarny writes.

Water utilities send alarms, power stations send telemetry, factories export historian information, pipeline operators need centralized monitoring, and defense environments export logs. All of that information flows outbound. If there is no operational reason for communication to come back through that same boundary, the return path creates unnecessary risk.

What “One-Way and Clean” Means for OT Security

A data diode enforces one-way communication at the hardware level, eliminating the return path. But direction alone does not solve the content problem. A malicious file moving in the permitted direction is still malicious.

OPSWAT’s position combines data diodes with content inspection: Multiscanning, data sanitization and Deep CDR Technology, sandboxing, DLP, AI-based content inspection, file validation, and policy enforcement. The principle is “one-way and clean,” where both direction and content are controlled.

OPSWAT has invested in this area through its acquisition of the assets of Bayshore Networks in 2021 (industrial security, OT, ICS, and secure data transfer), its acquisition of Fend in 2024 (data diode capabilities), the opening of a hardware production facility in Tampa, Florida, in November 2025, and a tripling of R&D resources.

Five Concepts for a US Executive Order on Critical Infrastructure

The article calls for a US Executive Order built around five concepts:

  1. No critical controller should be directly exposed to the internet.
  2. If data only needs to go out, make the connection one-way, and make the data clean.
  3. Remote control should be an exception.
  4. Help smaller utilities modernize.
  5. Set the security requirement, not the vendor.

A new 2026 critical infrastructure isolation guide recognizes data diodes and cross-domain solutions as providing higher assurance than standard network gateway architectures when properly implemented. Isolation, the article contends, should be part of how critical infrastructure is designed from the beginning, not something operators prepare to do only during a crisis.

Separately, Executive Order 14412, issued June 22, 2026, accelerates the federal transition toward NIST-approved post-quantum cryptography. The article positions hardware-enforced isolation as complementary: post-quantum cryptography protects the mathematics, while hardware-enforced isolation can protect the path to machines.

Europe’s NIS2 framework establishes a common cybersecurity framework across 18 critical sectors, including energy, transportation, health, drinking water, wastewater, digital infrastructure, manufacturing, government, and space. The article contends that regulators should ask whether each connection to critical infrastructure needs to exist at all.

Read the full article on OPSWAT.com.

Related from IIoT World:

Sponsored by OPSWAT.Help Build the Industry Benchmark: Take the 2027 Industrial Data & AI Readiness Survey and Get Early Access to the Report


Frequently Asked Questions

1. Why are firewalls not enough to protect critical infrastructure OT networks?

Firewalls filter traffic based on rules but maintain a bidirectional connection. Attackers who compromise a firewall, as in the Volt Typhoon campaign where a FortiGate 300D was the likely entry point, gain a two-way path into operational technology. Data diodes enforce one-way communication at the hardware level, removing the return path entirely.

2. What happened in the 2026 Minnesota water cyberattack?

On July 26-27, 2026, attackers targeted operational technology at more than 30 community water systems in Minnesota. They remotely accessed internet-facing PLCs, changed IP addresses and passwords, and caused operators to lose monitoring and control. The FBI reported operational effects including loss of pressure and flooding, and at least seven states reported similar incidents.

3. What does “one-way and clean” mean in OT cybersecurity?

“One-way and clean” combines data diodes (which enforce one-directional data flow at the hardware level) with content inspection technologies such as Multiscanning, Deep CDR, sandboxing, and DLP. The data diode removes the return path, while content inspection ensures that files moving in the permitted direction are free of malware.

4. What are the five concepts proposed for a US critical infrastructure executive order?

The article proposes five concepts: no critical controller should be directly exposed to the internet; if data only needs to go out, make the connection one-way and clean; remote control should be an exception; help smaller utilities modernize; and set the security requirement rather than specifying the vendor.