Ransomware Lateral Spread! All-Optical IT/OT Isolation Blocks Virus Propagation Across the Entire Factory

Ransomware gangs no longer rely solely on brute-force attacks to breach external firewalls. Their primary expansion tactic is to compromise a single endpoint and then move laterally within the internal network. The security incident at Tata Electronics in India serves as a typical example: attackers sent phishing emails disguised as supplier reconciliation notices to compromise an office terminal used by a procurement employee. After gaining a foothold on the internal network, they stole credentials and scanned the LAN for lateral movement. The attackers lurked on the corporate network for weeks, traversing server storage, and ultimately leaked 630GB of core supply chain drawings and quotation agreements. Throughout the whole attack, they barely launched high-intensity assaults on the external network perimeter, achieving their objectives purely through internal lateral infiltration.
Similar attack cases have also occurred in China. Attackers used office terminals as entry points, captured account credentials to spread across the internal network, breached the IT and OT boundary, and endangered the safety of production control systems.
A review of numerous manufacturing ransomware incidents reveals a consistent attack chain:
Phishing email / vulnerability exploit compromises office endpoints → Internal network scanning and account credential theft → Lateral movement to infiltrate servers → Breach of IT/OT boundaries → Intrusion into production control systems such as MES and PLC.
The root cause enabling these successful attacks is the lack of rigid isolation between office networks and production networks. Internal networks are trusted by default. Once attackers gain access to one internal node, they obtain a pathway to spread into production zones.
So how can enterprise campuses establish clearer cybersecurity boundaries against the risk of ransomware lateral spread? Many enterprises first consider deploying firewalls and creating VLANs. However, this traditional approach struggles to effectively block lateral propagation.
I. Why Traditional "Firewall + VLAN" Fails to Stop Lateral Spread
Many factories deploy firewalls for perimeter defense and VLANs for network segmentation, believing this isolates office and production networks. In real-world combat scenarios, this setup has four inherent weaknesses against internal lateral movement:
- VLAN isolation is logical isolation, not rigid physical-layer isolation.
VLANs are software-based logical segmentation. Their isolation effect depends entirely on switch configurations. Misconfigurations, incorrectly patched ports, or compromised devices can bypass VLAN restrictions to achieve cross-segment access. Factories often face complex O&M, and VLAN policies become messy amid continuous business iteration. Segmentation merely separates network segments without truly cutting underlying communication paths. After attackers obtain internal network privileges, they can easily bypass logical isolation to access other business domains. - Firewalls only allow "conditional traffic" and cannot achieve absolute blocking.
Traditional firewalls primarily protect north-south traffic between external and internal networks. Ransomware lateral movement generates east-west internal traffic; data packets from endpoint-to-endpoint attacks are forwarded directly by internal switches without passing through firewalls, rendering firewall rules ineffective against such internal attacks. Even if industrial firewalls are deployed between IT and OT environments, they can only govern traffic passing through gateways and cannot restrict lateral scanning from already compromised endpoints inside the LAN. - Insufficient capabilities to monitor and block east-west internal traffic.
Legacy security architectures prioritize external perimeters and neglect internal networks, which are trusted by default. Once an office PC is infected, its scanning, brute-force cracking and credential theft activities targeting other internal devices flow freely across the LAN without regular monitoring or interception. By the time business systems raise abnormal alerts, the virus has already spread widely. - Multiple parallel networks lack encryption and access constraints for cross-network communication.
Digital factories run parallel networks for office work, production, video surveillance and IoT terminals, with frequent business interactions across different services. Cross-network traffic under traditional architectures is mostly transmitted in plaintext with no native encryption. Meanwhile, refined cross-network access policies are hard to implement. To guarantee connectivity, permissions are often over-granted, inadvertently opening channels for ransomware lateral movement.
II. AINOPOL Integrated Encryption & Connectivity Solution: From "Conditional Access" to Physical-Layer Blocking
AINOPOL’s Integrated Encryption & Connectivity solution embeds native security capabilities into the all-optical bearer network. Following the 5-tier in-depth defense framework of Level Protection 2.0, it abandons the traditional model of add-on security appliances. It builds a complete protection system covering five dimensions: physical environment, communication network, regional boundary, computing environment and management center. This upgrades security philosophy from perimeter-based "conditional access" to underlying "physical-layer blocking".
- Physical / Environmental Layer: Leveraging inherent optical network features, paired with machine room access control, video surveillance and fiber tap detection, the solution delivers full protection for equipment rooms, cabling and physical hardware. Alerts trigger automatically if fiber links suffer physical tapping, bending or damage, safeguarding the physical security of network infrastructure and forming the foundation of the full defense system.
- Communication Network Layer: To mitigate link and data transmission risks, it adopts native PON encryption and hard slicing technology to realize link encryption, slice isolation and data integrity verification. Each business domain occupies an independent optical channel, with isolated underlying bearer paths instead of the logical segmentation of conventional VLANs. Transmitted data is encrypted by default, eliminating plaintext transmission risks in multi-service parallel networks. This blocks cross-domain data leakage and lateral infiltration at the transmission layer.
- Regional Boundary Layer: Integrated security gateways are deployed at campus network boundaries, incorporating NGFW, application identification, intrusion prevention and access control. Traffic crossing boundaries is finely managed. Industrial control protocol whitelists can be configured to block high-risk protocols commonly abused by ransomware such as RDP and SMB. The system identifies and intercepts unauthorized access and attacks at network boundaries, securing gateways between campus business domains.
- Computing Environment Layer: A unified endpoint security system is deployed for terminals and business systems. Security controls including identity admission, antivirus protection, patch management and operation auditing are enforced to strengthen endpoint access validation and reduce the likelihood of endpoints being compromised via phishing or vulnerability exploits. All endpoint operations are logged for auditing. Abnormal endpoint behaviors are detected promptly, minimizing opportunities for attackers to establish internal footholds.
- Management Center Layer: A cloud-based unified management platform delivers centralized network-wide control. It handles log retention, security situational awareness and unified policy orchestration, aggregating security data from physical, network, boundary and endpoint layers. If abnormal access or virus spread signs emerge within the internal network, administrators can quickly locate high-risk assets, push isolation policies with one click, shorten incident response cycles and enable unified orchestration of network-wide security.
The complete Integrated Encryption & Connectivity solution does not replace endpoint antivirus, data backup, vulnerability management or other security measures. Instead, it builds a rigid isolation baseline built upon underlying all-optical network capabilities. Even if a single endpoint becomes compromised, the five-tier in-depth defense restricts ransomware lateral spread. It achieves the effect: attackers may get in, but they cannot go far. While maintaining business interoperability, the system meets compliance requirements for Level Protection construction on the campus.
It must be clarified that the all-optical network itself cannot replace firewalls, endpoint security, vulnerability management, identity authentication or data backup, nor can it guarantee that enterprises will never suffer ransomware attacks.
From a cybersecurity architecture perspective, however, proper IT/OT isolation addresses a critical question:
Once an endpoint is compromised, how to contain further lateral risk spread.
AINOPOL all-optical IT/OT network isolation helps enterprises define clearer business boundaries at the architectural level:
- IT office networks and OT production networks are isolated by business requirements;
- All-optical hard slicing defines network bearer scopes for different services;
- Access control reduces unnecessary cross-zone communications;
- Unified management improves the efficiency of anomaly detection and location across the network.
Cybersecurity priorities are shifting from merely perimeter defense toward internal network protection, evolving from "keeping threats out" to "containing spread after breach".
FAQ
Q: What is the typical ransomware path from office networks to production networks?
A: The typical chain: phishing email → office endpoint infection → virus scans other LAN devices → lateral movement via AD domain privileges or weak passwords → breach IT/OT boundary → compromise PLC and MES systems. The attack path targeting Foxconn and Fairlife followed exactly this pattern.
Q: Why can traditional VLAN isolation not block lateral movement?
A: Traditional VLAN is software-level logical isolation. Configurations are complex and prone to errors. Many factories only use simple routing for connectivity without creating independent security domains. The all-optical network uses VLAN hard isolation, industrial protocol whitelists and cross-network access control to block lateral movement at the architecture level.
Q: What is the function of industrial protocol whitelists?
A: Devices such as PLCs and SCADA systems on the shop floor communicate using industrial protocols including Modbus. These protocols inherently lack encryption and authentication mechanisms. Whitelists only permit legitimate industrial control protocol traffic and block all unauthorized flows, preventing attackers from manipulating equipment through malicious protocols.