Pen Test Partners Found Wi-Fi Bridging OT Segmentation
Pen Test Partners found a control-room Wi-Fi setup that let corporate laptops and phones reach the OT LAN during an OT engagement, breaking IT/OT segmentation without any exploit or firewall bypass. The access point was serving both the office side and the control room, so devices that wandered in could roam onto the wrong network.
The failure came from a convenience request: engineers had asked for corporate and internet access in the control room, and the provider reused an existing path instead of keeping the boundary separate. That meant the Wi-Fi itself became the bridge, so business devices could carry phishing or malware exposure into the control network.
For critical-infrastructure sites, the lesson is that segmentation can fail in the room, not just at the perimeter. If legitimate connectivity is handled ad hoc in shared spaces, the OT estate can inherit IT risk through normal movement, and the cleanup problem is as much about the operating model as the network design.