Colonial Pipeline Paper

Course: CS 462 – Cybersecurity Fundamentals

Artifact Type: Research Paper

Semester: Fall 2025

Overview

This paper examined the 2021 Colonial Pipeline cyberattack as a case study in cybersecurity and critical infrastructure. I researched how the attack occurred, the impact of the ransomware incident on the Colonial Pipeline’s operations, and the broader consequences cause by this shutdown. I also researched security weaknesses associated with the incident and considered lessons that organizations can apply to reduce the risk and impact of similar attacks.

My Work

In this paper, I analyzed both the technical and organizational aspects of the Colonial Pipeline attack. My research considered how compromised credentials , remote access, and weaknesses in authentication contributed to the incident, as well as the role of ransomware and other attacker activity. I also looked into the effects of the attack beyond the compromised systems, including fuel shortages, operational disruption, financial loss, and changes to cybersecurity requirements.

I concluded the paper by identifying lessons organizations can take form the incident, including the importance of stronger identity and access management, multi-factor authentication, updated remote access practices, and incident response planning. This helped me consider how cybersecurity failure can develop into a much larger business and infrastructure problem.

Artifact

Figure 1. Opening analysis from my case study
Figure 2. Analysis of cybersecurity lessons and recommendations identified form the attack

Skills Demonstrated

The Colonial Pipeline attack showed me how closely cybersecurity and business operations can be connected. A security failure that began with access to an organization’s systems eventually contributed to disruptions that reached far beyond the network itself.

Analyzing the incident required me to determine what contributed to the attack and identify security practices that could reduce similar attacks. This allowed me to practice evaluating a real cybersecurity incident and developing conclusions based on what went wrong and what could have been handled differently.