Stopping Lateral Movement Across Private Cellular Operational Technology Networks

Industrial infrastructure is undergoing a rapid transition toward cellular connectivity. Operational technology (OT) environments—ranging from remote utility substations and water treatment facilities to manufacturing floors and wind farms—now rely on private 4G and 5G networks to transmit critical telemetry. To isolate this sensitive traffic from the public internet, organizations routinely deploy private Access Point Names (APNs) provided by telecommunications carriers. This approach creates an illusion of security, leading infrastructure architects to assume that an isolated cellular network is inherently safe from external intrusion.
In reality, private cellular APNs harbor a massive architectural blind spot that exposes physical operations to severe risk. Traditional enterprise firewalls and network security appliances are deployed at the egress point where the cellular carrier's network meets the corporate data center or cloud. They are designed to inspect northbound and southbound traffic leaving the APN or entering it from the outside world. However, these perimeter-based firewalls have zero visibility into device-to-device (east-west) traffic within the cellular network itself.
If an attacker gains access to a single cellular-connected endpoint, the perimeter firewall remains completely oblivious to their presence. A compromised field device, such as a cellular gateway or an edge controller, becomes a launchpad for lateral movement. The attacker can scan, target, and exploit other vulnerable devices sharing the same private APN. Because the carrier routes traffic directly between endpoints within the subnet, this peer-to-peer malicious activity bypasses central inspection mechanisms entirely.
Once inside the APN, adversaries can execute arbitrary commands, rewrite programmable logic controller (PLC) registers, or deploy ransomware across the entire industrial fleet. Traditional security tools fail to mitigate this risk because they cannot segment or monitor cellular radio access network (RAN) traffic at the device level. The lack of granular, identity-verified network access control within the cellular subnet transforms a localized breach into a systemic operational failure. Security architects require a paradigm shift that embeds zero-trust enforcement directly onto the devices themselves, bypassing the carrier's routing blind spot.
Cryptographic Micro Segmentation for Cellular Infrastructure
Securing cellular-connected OT assets requires discarding the assumption that the network carrier can provide a trustworthy boundary. Instead, organizations must establish cryptographically enforced trust directly at the device level, independent of the underlying network transport. VeilNet solves this challenge by deploying Conflux, an identity-authenticated mesh networking engine that transforms how cellular OT devices communicate. Conflux operates as a decentralized overlay, establishing secure, authenticated connections directly between endpoints.
Conflux completely eliminates the cellular APN blind spot by enforcing identity-authenticated mesh networking across all connected nodes. Every gateway, PLC, and industrial workstation must cryptographically prove its identity using post-quantum credentials before any network packet is transmitted. If a field gateway within a private APN is physically compromised or infected with malware, it cannot communicate with any other device on the mesh without mutual cryptographic authentication. Unauthenticated lateral movement becomes mathematically impossible, stopping attackers dead at the initial point of entry.
Furthermore, Conflux introduces a meta air gap that completely conceals industrial assets from unauthorized discovery and scanning. Devices running Conflux do not expose open listening ports or visible IP addresses to the carrier's cellular subnet. To an attacker scanning the private APN, the entire network appears completely dark and uninhabited. This meta air gap ensures that even if an adversary gains access to the cellular subnet, they cannot map the network topology or discover adjacent target systems.
Defending Industrial Control Systems Against Quantum Exploitation
The vulnerability of cellular OT networks is further compounded by the threat of long-term cryptographic degradation. Attackers are actively intercepting and archiving encrypted industrial traffic today with the intention of decrypting it once quantum computers reach sufficient scale. For critical infrastructure operators with assets designed to remain in the field for decades, this "harvest now, decrypt later" strategy presents an immediate risk to national security.
Conflux addresses this future-proof security requirement by incorporating quantum-resistant packet routing directly into the transport layer. The network uses NIST-approved post-quantum cryptographic algorithms to secure every packet transition, preventing future decryption of captured telemetry. By securing peer-to-peer cellular communication with quantum-resistant keys, Conflux guarantees that industrial control signals remain confidential indefinitely. This ensures that long-lived utility assets remain immune to both current lateral threats and future quantum-enabled adversaries.
Restricting Industrial Protocol Interaction at the Data Plane
While securing the network layer is critical, defending operational technology also requires granular control over the data flowing between machines. Malicious actors who compromise an edge device often attempt to send unauthorized commands using standard industrial protocols like OPC UA. To prevent these application-layer attacks, organizations must pair secure network transport with strict protocol sanitization.
VeilNet's Aether handles this operational requirement by serving as the industrial data plane directly above the Conflux network layer. Aether integrates natively with OPC UA, RESTful APIs, and Model Context Protocol (MCP) systems to inspect and validate every industrial transaction. Rather than allowing unrestricted protocol communication, Aether enforces strict policy-based control over telemetry reads and register writes.
For example, when an OPC UA client attempts to modify a PLC register over a Conflux-secured cellular link, Aether intercepts and validates the command. It ensures that the requesting device is explicitly authorized to perform that specific operational action, rather than just possessing network connectivity. By sanitizing and filtering industrial telemetry at the application plane, Aether prevents compromised devices from executing destructive physical actions. This combined architecture of Conflux securing the transport and Aether validating the data plane ensures comprehensive, end-to-end operational resilience.
Deploying Decentralized Zero Trust in Legacy Environments
One of the primary obstacles to securing OT networks is the sheer volume of legacy equipment that cannot support modern security agents. Many water, power, and manufacturing systems rely on older PLCs and RTUs that communicate using unencrypted, legacy protocols. Upgrading this physical infrastructure is cost-prohibitive and introduces significant operational downtime.
The combination of Conflux and Aether solves this deployment bottleneck by acting as a transparent, high-performance security gateway. Industrial operators can deploy lightweight edge appliances running Conflux and Aether immediately adjacent to legacy field devices. These gateways ingest legacy serial or ethernet traffic, encapsulate it within a post-quantum Conflux mesh tunnel, and apply Aether's protocol validation policies.
This deployment model allows organizations to modernize their security posture without replacing a single piece of legacy physical infrastructure. The private cellular APN is transformed from a vulnerable blind spot into a highly secured, quantum-resistant communication fabric. Operators gain complete visibility, granular protocol control, and absolute protection against lateral movement, securing critical operations for the next generation.
Securing Operational Technology When the Zero Trust Gateway Itself Is the Vulnerability
Learn how VeilNet Conflux and Aether secure operational technology by eliminating public gateway listening ports and enforcing protocol-level isolation.
Securing Smart Building Operational Technology Against Lateral Movement
Protect operational technology and smart building networks from lateral movement with VeilNet's post-quantum zero-trust Conflux and Aether engines.