* [Blog](https://www.paloaltonetworks.com/blog) * [SASE](https://www.paloaltonetworks.com/blog/sase/) * [5G](https://www.paloaltonetworks.com/blog/sase/category/5g/) * 5G SASE for OT Security: ... # 5G SASE for OT Security: Stopping the Cellular APN Blind Spot [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsase%2F5g-sase-for-ot-security-stopping-the-cellular-apn-blind-spot%2F) [](https://twitter.com/share?text=5G+SASE+for+OT+Security%3A+Stopping+the+Cellular+APN+Blind+Spot&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsase%2F5g-sase-for-ot-security-stopping-the-cellular-apn-blind-spot%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fsase%2F5g-sase-for-ot-security-stopping-the-cellular-apn-blind-spot%2F&title=5G+SASE+for+OT+Security%3A+Stopping+the+Cellular+APN+Blind+Spot&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/sase/5g-sase-for-ot-security-stopping-the-cellular-apn-blind-spot/&ts=markdown) \[\](mailto:?subject=5G SASE for OT Security: Stopping the Cellular APN Blind Spot) Link copied By [Srudi Dineshan](https://www.paloaltonetworks.com/blog/author/srudi-dineshan/?ts=markdown "Posts by Srudi Dineshan") Sep 04, 2026 4 minutes [5G](https://www.paloaltonetworks.com/blog/sase/category/5g/?ts=markdown) [Partner Integrations](https://www.paloaltonetworks.com/blog/sase/category/partner-integrations/?ts=markdown) [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) When discussing Operational Technology (OT) security, the threat of lateral movement through cellular networks has often been treated as a theoretical whiteboard exercise. Yesterday, that theory became a documented reality. ## **The Cellular Blind Spot** Cellular networks are increasingly used to connect Operational Technology (OT) devices, but they create a critical security blind spot. Traditional enterprise firewalls cannot inspect device-to-device traffic within a private cellular Access Point Name (APN), allowing attackers to move laterally unseen. [5G Secure Access Service Edge (5G SASE)](https://www.paloaltonetworks.com/sase/5G-for-service-providers?ts=markdown) solves this by extending Zero Trust Network Access (ZTNA) and deep packet inspection directly into the cellular network layer, securing unagentable OT devices and preventing cellular cyberattacks. ## **The CERT Polska Report: A Real-World Cellular OT Attack** Industrial Cyber highlighted a stark report from Poland's national CERT detailing a destructive cyberattack on an energy plant serving roughly 50,000 residents. The attackers successfully compromised the facility, but they didn't do it through a direct, frontal assault on the plant's primary firewall. They used a blind spot that exists in thousands of deployments worldwide: **the private cellular APN.** ## **Why Traditional IT Security Fails at the Cellular APN** To understand the severity of this attack, you first have to understand the technology being exploited. An **Access Point Name (APN)** is a gateway that connects cellular devices to a corporate network. Carriers use private APNs to provide dedicated routing and isolation from the public internet. However, this isolation often creates a massive visibility gap. According to CERT Polska, this attack is the first observed real-world use of the private-APN-to-OT attack vector. The kill chain highlights a massive gap between traditional IT security and carrier-managed cellular networks: The kill chain exposed the two biggest gaps in modern infrastructure: 1. **Legacy Access:** Exposed VPNs without MFA remain the "front door" for attackers. 2. **The Cellular Blind Spot:** Traditional SASE and firewalls cannot see or control device-to-device movement *inside* the cellular network. Once an attacker is "on-net" via an APN, they are often invisible to the security stack. Layered controls and better basic hygiene could have prevented this, but that requires flawless coordination across multiple siloed teams, vendors, and environments. When device-to-device traffic routes entirely through a carrier's infrastructure, your standard enterprise firewalls simply cannot see it. ## **How 5G SASE Closes the Cellular Blind Spot** This incident is exactly why we partnered with [Aeris](https://www.aeris.com/). The kill chain in this attack splits cleanly along the line of our joint 5G SASE integration. Critical infrastructure, energy grids, and utilities - especially those facing stringent compliance mandates like NIS2 and NERC CIP---need a way to bridge the gap between their enterprise edge and their cellular OT edge. Here is how the joint solution addresses this exact kill chain: * **Securing the Enterprise Edge:** Palo Alto Networks Prisma Access eliminates the vulnerability of exposed, legacy VPNs by implementing Zero Trust Network Access (ZTNA). * **Agentless Enforcement:** We apply Zero Trust policies to "unagentable" OT devices and industrial sensors directly at the SIM/Network layer. * **Illuminating the Cellular Network:** Traditional SASE cannot inspect traffic inside a carrier's private APN. Our integration with Aeris feeds cellular signaling and traffic context directly into Prisma Access. * **Enforcing Client Isolation:** Through Aeris, we extend Zero Trust principles *into* the private APN. Even if a remote cellular router is compromised, strict client isolation ensures it cannot scan, see, or communicate with a critical PLC at another facility. ## **A Unified Zero Trust Approach with Palo Alto Networks and Aeris** The ultimate lesson from the CERT Polska report is that fragmented security policies between IT and OT networks will inevitably be exploited. By bringing Aeris's deep cellular visibility into Prisma Access, we are giving CISOs a single pane of glass. Security teams can now implement, manage, and update their policies with absolute consistency-whether securing an employee's laptop at a coffee shop or a cellular-connected sensor at a remote wind farm. The threat is no longer theoretical. It is time to close the cellular blind spot. ## **Ready to secure your remote operations?** If you are managing a large footprint of cellular-connected devices in a critical infrastructure environment, you cannot afford to leave your private APN unmonitored. [Contact us](https://www.paloaltonetworks.com/sase/sase-contact-us?ts=markdown) today to discuss how 5G SASE can secure your remote operations. *** ** * ** *** ## Related Blogs ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown), [Zero Trust Security](https://www.paloaltonetworks.com/blog/network-security/category/zero-trust-security/?ts=markdown) [#### Introducing Secure Agentless Access (SAA): A New Zero Trust Access Method for Any User on Any Device](https://www.paloaltonetworks.com/blog/sase/introducing-secure-agentless-access-saa-a-new-zero-trust-access-method-for-any-user-on-any-device/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### The Unified SASE Advantage: Top 3 Reasons to Converge SD-WAN \& SSE](https://www.paloaltonetworks.com/blog/sase/the-unified-sase-advantage-top-3-reasons-to-converge-sd-wan-sse/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### The End of Data Leaks: Modern Data Security Begins in the Browser](https://www.paloaltonetworks.com/blog/sase/the-end-of-data-leaks-modern-data-security-begins-in-the-browser/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [SD-WAN](https://www.paloaltonetworks.com/blog/sase/category/sd-wan/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Examining the Coffee Shop Model and SASE](https://www.paloaltonetworks.com/blog/sase/examining-the-coffee-shop-model-and-sase/) ### [Partner Integrations](https://www.paloaltonetworks.com/blog/sase/category/partner-integrations/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Platformization Maximizes Security Efficacy \& IT Operations Efficiency](https://www.paloaltonetworks.com/blog/2025/04/platformization-maximizes-security-efficacy-it-operations-efficiency/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Why Weak MFA Is as Dangerous as Having No MFA](https://www.paloaltonetworks.com/blog/sase/why-weak-mfa-as-dangerous-as-no-mfa/) ### Subscribe to Sase Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language