When discussing Operational Technology (OT) security, the threat of lateral movement through cellular networks has often been treated as a theoretical whiteboard exercise. Yesterday, that theory became a documented reality.
The Cellular Blind Spot
Cellular networks are increasingly used to connect Operational Technology (OT) devices, but they create a critical security blind spot. Traditional enterprise firewalls cannot inspect device-to-device traffic within a private cellular Access Point Name (APN), allowing attackers to move laterally unseen. 5G Secure Access Service Edge (5G SASE) solves this by extending Zero Trust Network Access (ZTNA) and deep packet inspection directly into the cellular network layer, securing unagentable OT devices and preventing cellular cyberattacks.
The CERT Polska Report: A Real-World Cellular OT Attack
Industrial Cyber highlighted a stark report from Poland’s national CERT detailing a destructive cyberattack on an energy plant serving roughly 50,000 residents. The attackers successfully compromised the facility, but they didn’t do it through a direct, frontal assault on the plant's primary firewall.
They used a blind spot that exists in thousands of deployments worldwide: the private cellular APN.
Why Traditional IT Security Fails at the Cellular APN
To understand the severity of this attack, you first have to understand the technology being exploited. An Access Point Name (APN) is a gateway that connects cellular devices to a corporate network. Carriers use private APNs to provide dedicated routing and isolation from the public internet. However, this isolation often creates a massive visibility gap.
According to CERT Polska, this attack is the first observed real-world use of the private-APN-to-OT attack vector. The kill chain highlights a massive gap between traditional IT security and carrier-managed cellular networks:
The kill chain exposed the two biggest gaps in modern infrastructure:
- Legacy Access: Exposed VPNs without MFA remain the "front door" for attackers.
- The Cellular Blind Spot: Traditional SASE and firewalls cannot see or control device-to-device movement inside the cellular network. Once an attacker is "on-net" via an APN, they are often invisible to the security stack.
Layered controls and better basic hygiene could have prevented this, but that requires flawless coordination across multiple siloed teams, vendors, and environments. When device-to-device traffic routes entirely through a carrier's infrastructure, your standard enterprise firewalls simply cannot see it.
How 5G SASE Closes the Cellular Blind Spot
This incident is exactly why we partnered with Aeris. The kill chain in this attack splits cleanly along the line of our joint 5G SASE integration.
Critical infrastructure, energy grids, and utilities - especially those facing stringent compliance mandates like NIS2 and NERC CIP—need a way to bridge the gap between their enterprise edge and their cellular OT edge. Here is how the joint solution addresses this exact kill chain:
- Securing the Enterprise Edge: Palo Alto Networks Prisma Access eliminates the vulnerability of exposed, legacy VPNs by implementing Zero Trust Network Access (ZTNA).
- Agentless Enforcement: We apply Zero Trust policies to "unagentable" OT devices and industrial sensors directly at the SIM/Network layer.
- Illuminating the Cellular Network: Traditional SASE cannot inspect traffic inside a carrier’s private APN. Our integration with Aeris feeds cellular signaling and traffic context directly into Prisma Access.
- Enforcing Client Isolation: Through Aeris, we extend Zero Trust principles into the private APN. Even if a remote cellular router is compromised, strict client isolation ensures it cannot scan, see, or communicate with a critical PLC at another facility.
A Unified Zero Trust Approach with Palo Alto Networks and Aeris
The ultimate lesson from the CERT Polska report is that fragmented security policies between IT and OT networks will inevitably be exploited.
By bringing Aeris’s deep cellular visibility into Prisma Access, we are giving CISOs a single pane of glass. Security teams can now implement, manage, and update their policies with absolute consistency-whether securing an employee’s laptop at a coffee shop or a cellular-connected sensor at a remote wind farm.
The threat is no longer theoretical. It is time to close the cellular blind spot.
Ready to secure your remote operations?
If you are managing a large footprint of cellular-connected devices in a critical infrastructure environment, you cannot afford to leave your private APN unmonitored. Contact us today to discuss how 5G SASE can secure your remote operations.