6-minute read • Critical Infrastructure Security
TL;DR: Executive Brief
The Crisis: You’re not being targeted you’re already discovered. Censys found 148,000 industrial systems exposed online right now. 85% of organizations have RDP exposed. Automated scanners catalog these exposures in hours, not days.
Recent Breaches Prove the Pattern:
- Major healthcare processor: Missing MFA on one system = $2.87B loss
- Automotive software provider: One exposed service = $1B disruption, 15,000 dealerships offline
- File transfer platform: Single vulnerability = 2,620 organizations breached
The Attack Timeline: Mass scanning (0-1hr) → Enumeration (1-3hr) → Credential harvesting (3-6hr) → Access validation (6-12hr) → Mass exploitation (12+hr)
Three Metrics That Predict Breach: External exposure <5% • Detection <6 hours • Third-party zero standing access
ROI: $700K prevention vs $4.88M average breach = 7:1 minimum return
The Discovery Crisis
A major healthcare technology company processing 15 billion transactions annually had enterprise security teams and million-dollar budgets. Yet in February 2024, automated attackers found their single portal missing MFA during routine scanning. According to SEC filings, this one overlooked system triggered catastrophic consequences: $2.87 billion in losses, 100 million patient records exposed, six months of recovery, and Congressional hearings.
The attackers weren’t specifically hunting this company. They were running automated scans that discovered an exposed system that happened to belong to them. This pattern repeats across every major breach today. Censys reports 148,000 industrial control systems exposed online, while Unit 42 found 85% of organizations have RDP exposed to the internet.
A major automotive software provider learned this lesson brutally when their June 2024 breach caused $1 billion in disruption and shut down 15,000 car dealerships for weeks. Recent telecom breaches didn’t need sophisticated zero-days; CISA confirmed attackers exploited known vulnerabilities to compromise nine major providers. A file transfer vulnerability demonstrated the scale when one flaw led to 2,620 organizations being breached, affecting media companies, airlines, and state governments.
The Five Stages of Getting Discovered
Stage 1: Mass Scanning (0-1 hours)
Every second, automated scanners probe millions of IP addresses searching for exposed services. The tool of choice, Masscan, can scan the entire IPv4 internet in just 6 minutes and sits freely available on GitHub. Rapid7’s National Exposure Index found the average organization gets scanned 14 times per hour by different threat actors.
These scanners systematically hunt for specific ports: 3389 for RDP (85% of organizations have it exposed), 445 for SMB file sharing, 22 for SSH (2.3 million exposed globally), 502 for Modbus industrial controls (148,000 systems online), and 8080 for web applications. When found, these discoveries get logged into criminal databases that are bought, sold, and shared worldwide.
Stage 2: Enumeration (1-3 hours)
Once open ports are identified, automated enumeration begins immediately. Scripts probe these services to identify exact versions, test for default credentials, and check against databases of known vulnerabilities. With MITRE logging 28,000 new vulnerabilities in 2024 alone, attackers have an endless arsenal of exploits to test.
Recent VPN zero-day attacks demonstrate the terrifying speed of this process. CISA’s emergency directive reported 1,700 systems compromised within 48 hours of disclosure. Similarly, a major remote access vulnerability saw 20,000 systems hit according to GreyNoise intelligence. These weren’t sophisticated nation-state operations initially; they were automated tools systematically testing every previously cataloged system against new vulnerabilities.
Stage 3: Credential Harvesting (3-6 hours)
Modern attackers don’t crack passwords; they find them. GitGuardian’s 2024 State of Secret Sprawl discovered 12.8 million secrets exposed in public GitHub repositories, with 90% still valid when found. That’s one valid credential exposed every 10 seconds. CyberArk’s research reveals organizations have 20 machine identities for every human, and most don’t track them.
The sources of credentials are disturbingly common: 67% of organizations have “Passwords.xlsx” on network shares, 37.8% of building systems still use admin/admin, and service accounts average 45,000 per enterprise with 68% orphaned. A major data warehouse breach proved how dangerous old credentials are when Mandiant’s investigation confirmed passwords from 2020 still worked in 2024, leading to breaches at ticketing companies, banks, and 160+ other organizations.
Stage 4: Access Validation (6-12 hours)
With harvested credentials in hand, validation begins systematically. This stage reveals why Microsoft’s research showing 99.9% of compromised accounts lack MFA is so critical. Without multi-factor authentication, stolen credentials provide instant access. Attackers test each credential set methodically, and Sophos reports 26% of ransomware now enters through exposed RDP.
CISA’s advisory AA24-290A details how state actors demonstrated industrial-scale validation, attempting brute force against thousands of critical infrastructure targets simultaneously. With just a 3% success rate, they compromised 30 organizations per 1,000 attempts. During this stage, validated access gets priced according to Kela’s cybercrime research: small business access sells for $500-1,500, healthcare organizations fetch $5,000-20,000, and critical infrastructure commands $100,000+.
Stage 5: Mass Exploitation (12+ hours)
This final stage transforms individual discoveries into industry-wide catastrophes. Intel 471’s Underground Economy Report documents how initial access brokers operate like wholesale distributors, selling validated access to specialized criminal groups. The original discoverer rarely conducts the actual attack; they’re simply suppliers in a vast criminal supply chain.
A recent file transfer vulnerability perfectly demonstrates this industrialization. Emsisoft tracked how one vulnerability led to 2,620 organizations compromised, affecting 77.2 million people. Coveware’s analysis found each initial compromise spawns an average of 4.2 secondary attacks as access gets resold to different groups. Chainalysis estimates this criminal ecosystem generates $8.5 trillion annually.
Three Metrics That Predict Your Breach
External Exposure Percentage
BitSight’s research proves organizations keeping external exposure below 5% experience 73% fewer breaches. The industry average sits at 12-15%, but ESG found 68% of organizations don’t know their actual percentage. Coalfire’s penetration testing reveals organizations typically underestimate exposure by 300%.
Detection Speed
CISA mandates 15-day patching for federal systems, but Palo Alto’s research shows attackers exploit vulnerabilities within 6 hours. SANS found organizations take 21 days average to detect new exposures, creating a 17-day window of certain compromise.
Third-Party Access Control
Verizon’s DBIR shows 29% of breaches involve vendor access, while SecurityScorecard discovered 98% of organizations connect to at least one breached vendor. A major retailer’s 2013 breach through an HVAC vendor stealing 40 million cards still defines this risk.
Your Monday Action Plan
8 AM: See what attackers see. Run Shodan on your organization, scan your perimeter with nmap, check haveibeenpwned.com. Bishop Fox found 82% of organizations discover unknown assets during their first external scan.
9 AM: Fix three critical gaps. Deploy MFA everywhere (blocks 99.9% of attacks per Microsoft). Eliminate default passwords (37.8% still use admin/admin). Kill unnecessary services (each increases breach probability 7%).
10 AM: Implement real protection. Deploy exposure monitoring to see what attackers can reach. Proper segmentation reduces impact 87% but 74% of “segmented” networks aren’t really protected.
11 AM: Present the ROI. Average breach costs $4.88M, healthcare $10.93M. Prevention costs ~$700K. Return: 7-40x.
While you’ve read this, 50 organizations were scanned, 10 had exploitable exposures, and 2-3 will be breached today. You’re not a future target. You’re already cataloged.
The Choice Is Yours
Right now, you’re at a crossroads. You can close this article, go back to your day, and hope your organization isn’t one of tomorrow’s breach headlines. Or you can take action.
The technology to prevent these breaches exists. The ROI is proven. The only missing piece is recognition that you’re already exposed, already cataloged, already on someone’s list. Every hour you wait, your exposure probability increases 4%. Every day without MFA is a day closer to becoming a statistic.
Take Action Today
Start with one simple step: Run Shodan on your organization right now. It takes 30 seconds. What you discover might save your company millions.
Then ask yourself three questions:
- When did we last scan our external exposure?
- How many systems have MFA disabled?
- Who owns our third-party access?
If you can’t answer these immediately, you need help.
Join Our Community of Defenders
Every week, I share actionable intelligence that helps security leaders protect critical infrastructure. No vendor pitches, no fluff, just hard truths and practical solutions based on real-world data.
Subscribe to this newsletter for weekly insights on:
- Latest attack patterns and how to stop them
- Metrics that actually predict breaches
- Tools and techniques that work in production
- Real breach analysis and lessons learned
Share your experience: What did Shodan reveal about your organization? Which stage is your weakest link? Comment below and let’s discuss.
Forward this to someone who needs to see it. Maybe your CTO, your security team, or that colleague who thinks “we’re too small to be targeted.”
Connect with me on LinkedIn for daily security insights and join our private Security Leaders group where we share confidential lessons learned.
Remember: The difference between the breached and the secure isn’t sophistication. It’s action.
What will you do in the next hour?
Every statistic cited and verified through primary sources. No fear-mongering, just facts.
Subscribe for weekly actionable intelligence that helps you stay ahead of attackers.
#Cybersecurity #CriticalInfrastructure #OTSecurity #RiskManagement #CISO #SecurityLeadership #InfoSec #CloudSecurity #ZeroTrust #ThreatIntelligence