Article
News
3
min read
Brad Bonavida

How a USB Stick Plugged In During a Penetration Test Discovery Meeting Owned the Central Energy Plant in Minutes

May 19, 2026

Mike MacMahon of Newcomb & Boyd has conducted numerous security penetration tests, and at NexusCon 2025, he shared how easy some of them have been. At a central energy plant, MacMahon walked into an office for a meeting, leaned over the desk to make small talk, and quietly unplugged the network cable from the tower beside him. He swapped in a Land Turtle — a USB-powered Linux device that introduces itself to Windows as a network adapter. Windows held the connection. The device sat on the desk with a small label saying "don't touch - IT," giving it enough credibility that no one would touch it.

Once plugged in, the Land Turtle reached out to the internet and opened a remote tunnel. From his car in the parking lot, he opened his laptop, tunneled into the device, and ran network discovery in the background. The central energy plant's control equipment was on the same flat network as the office machines. Every control device was at its default password. A small USB stick had given him virtually full control of the central plant.

MacMahon's larger point was that commercial buildings are full of simple, unaddressed vulnerabilities like these: default passwords, flat networks, and a willingness to leave an unknown USB in a server. Securing our buildings starts with a cultural shift toward constant security consideration. His framing for the room was that cybersecurity in buildings is the thing everyone assumes someone else owns, so nobody owns it. It moves forward when someone is willing to bring it up, ask the awkward question, and hesitate before saying yes, regardless of where they sit on the org chart.

Watch the full recording.

Register for the next Nexus Labs event.

Sign up for the newsletter to get 5 stories like this per week:

Sign Up for Access or Log In to Continue Viewing

Sign Up for Access or Log In to Continue Viewing

Mike MacMahon of Newcomb & Boyd has conducted numerous security penetration tests, and at NexusCon 2025, he shared how easy some of them have been. At a central energy plant, MacMahon walked into an office for a meeting, leaned over the desk to make small talk, and quietly unplugged the network cable from the tower beside him. He swapped in a Land Turtle — a USB-powered Linux device that introduces itself to Windows as a network adapter. Windows held the connection. The device sat on the desk with a small label saying "don't touch - IT," giving it enough credibility that no one would touch it.

Once plugged in, the Land Turtle reached out to the internet and opened a remote tunnel. From his car in the parking lot, he opened his laptop, tunneled into the device, and ran network discovery in the background. The central energy plant's control equipment was on the same flat network as the office machines. Every control device was at its default password. A small USB stick had given him virtually full control of the central plant.

MacMahon's larger point was that commercial buildings are full of simple, unaddressed vulnerabilities like these: default passwords, flat networks, and a willingness to leave an unknown USB in a server. Securing our buildings starts with a cultural shift toward constant security consideration. His framing for the room was that cybersecurity in buildings is the thing everyone assumes someone else owns, so nobody owns it. It moves forward when someone is willing to bring it up, ask the awkward question, and hesitate before saying yes, regardless of where they sit on the org chart.

Watch the full recording.

Register for the next Nexus Labs event.

Sign up for the newsletter to get 5 stories like this per week:

⭐️ Pro Article

Sign Up for Access or Log In to View

⭐️ Pro Article

Sign Up for Access or Log In to View

Are you interested in joining us at NexusCon 2026? Register now so you don’t miss out!

Join Today

Are you a Nexus Pro member yet? Join now to get access to our community of 600+ members.

Join Today

Have you taken our Smart Building Strategist Course yet? Sign up to get access to our courses platform.

Enroll Now
Conversation
Comments (-)
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Guest
6 hours ago
Delete

This is a great piece!

REPLYCANCEL
or register to comment as a member
POST REPLY
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Guest
6 hours ago
Delete

I agree.

REPLYCANCEL
or register to comment as a member
POST REPLY
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get the renowned Nexus Newsletter

Access the Nexus Community

Head over to Nexus Connect and see what’s new in the community. Don’t forget to check out the latest member-only events.

Go to Nexus Connect

Upgrade to Nexus Pro

Join Nexus Pro and get full access including invite-only member gatherings, access to the community chatroom Nexus Connect, networking opportunities, and deep dive essays.

Sign Up