CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything
Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old remote access account that only needed a password. Multi-factor authentication on that account would very likely have stopped them.
Why "MFA on everything" is a business decision
Multi-factor authentication is well understood and inexpensive. The gaps are usually exceptions: old accounts, vendor accounts, systems that "don't support it," executives who find it inconvenient. Attackers look specifically for those exceptions.
The business impact
- Operational shutdown — Colonial stopped operations even though the attack hit IT systems.
- Ransom and recovery costs.
- Regulatory consequences, including new security directives for the sector.
Questions to ask your team
- Does every way into our network — VPN, remote desktop, cloud apps, vendor tools — require MFA?
- How many accounts haven't been used in 90 days but are still active?
- Could our operations continue if our IT systems were down for a week?
What good looks like
MFA on every remote access path without exceptions (or with documented, monitored ones), dormant accounts removed automatically, and a continuity plan that separates operations from IT where possible.
The decision
Ask for a written list of every exception to MFA in your organization. Each one should have an owner and a date to close it.
- Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA Incident Teardowns
- How to Find Remote Access Accounts That Bypass MFA How-To & Hardening
- Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections Detection & Response