Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old remote access account that only needed a password. Multi-factor authentication on that account would very likely have stopped them.

Why "MFA on everything" is a business decision

Multi-factor authentication is well understood and inexpensive. The gaps are usually exceptions: old accounts, vendor accounts, systems that "don't support it," executives who find it inconvenient. Attackers look specifically for those exceptions.

The business impact

  • Operational shutdown — Colonial stopped operations even though the attack hit IT systems.
  • Ransom and recovery costs.
  • Regulatory consequences, including new security directives for the sector.

Questions to ask your team

  • Does every way into our network — VPN, remote desktop, cloud apps, vendor tools — require MFA?
  • How many accounts haven't been used in 90 days but are still active?
  • Could our operations continue if our IT systems were down for a week?

What good looks like

MFA on every remote access path without exceptions (or with documented, monitored ones), dormant accounts removed automatically, and a continuity plan that separates operations from IT where possible.

The decision

Ask for a written list of every exception to MFA in your organization. Each one should have an owner and a date to close it.

colonial pipeline hack impactColonial Pipeline2021

More on this story