US Cyber Strategy Misses the PLC-Driven Backbone of Military Logistics

US Cyber Strategy Misses the PLC-Driven Backbone of Military Logistics

When policymakers talk about defending the homeland from cyberattacks, the conversation usually gravitates toward fighter jets, satellites, or the Pentagon's networks. Yet the machinery that actually keeps a military in motion—container cranes at seaports, rail signaling and switching systems, and the electrical distribution networks feeding forward bases—runs on the same programmable logic controllers (PLCs) and industrial control systems (ICS) now being probed by Iranian-linked threat actors. That is the uncomfortable thesis of a new CyberScoop commentary by Darron Makrokanis, who argues the United States' national cyber strategy is defending the wrong targets. The warning lands at a moment of peak urgency: CISA has confirmed that malicious activity hit more than 100 internet-exposed water and wastewater systems in a single month, often through PLCs connected directly to cellular modems. If the same playbook is portable to logistics infrastructure, then PLC and ICS cybersecurity is no longer a utility-sector problem—it is a national readiness problem.

Why the Real Cyber Battlefield Runs Through Ports, Rail and Power

The op-ed's core insight is structural. Military power projection depends on a chain of civilian infrastructure: ports that offload equipment, railroads that move it inland, and utilities that power both. Each of those links has been progressively automated over two decades, embedding PLCs and SCADA systems into cranes, track switches, substations and pump stations.

That automation delivered efficiency and labor savings. It also created single points of failure that are often poorly segmented from IT networks—and, in the worst cases, reachable straight from the public internet.

Analyst Insight: The threat is not a hypothetical breach of a combat system—it is the systematic erosion of the logistics layer that supports combat. Adversaries do not need to defeat a military if they can slow its resupply, disrupt a port's throughput, or darken a rail corridor. Critical infrastructure cybersecurity is now a force-multiplier question, not just a compliance checkbox.

Inside the Iranian PLC Playbook

Federal advisories from CISA, the FBI, the NSA, the Department of Energy and the EPA have mapped a consistent Iranian-affiliated campaign targeting operational technology. The tactics are simple, repeatable, and—critically—manufacturer-agnostic.

Attackers scan the internet for exposed controllers, authenticate with weak or default credentials, and then alter or lock out operators. In several documented cases, they modified project files, changed passwords, and reassigned IP addresses to sever operator visibility entirely.

Technical Specs: How the Attacks Are Executed

Primary vector: Internet-exposed PLCs, frequently connected via cellular modems or routers that bypass network segmentation.

Discovery tooling: Public scanning services such as Censys and ZoomEye identify live controllers across TCP ports commonly used by industrial protocols (for example, port 102 for Siemens S7 devices).

Targeted families: Rockwell Automation / Allen-Bradley units (including MicroLogix 1100 and 1400 series), Siemens S7 series (S7-200 through S7-1500, including F-series), and Schneider Electric controllers have all been cited in advisories.

Impact: Password modification, IP address changes, HMI and SCADA display manipulation, disabled shutdown processes and alarms, and modified PLC project files.

Escalation signal: Recent advisories note the use of AI-assisted, publicly derived Python scripts—leveraging open-source libraries such as python-snap7—to accelerate exploitation of exposed controllers.

The Scale of the Threat: PLCs as Single Points of Failure

What began as sector-specific harassment has become a broad, multi-sector campaign. Government advisories now list water and wastewater, energy, critical manufacturing, chemical, food and agriculture, and commercial facilities among the targeted environments.

For logistics operators, the concern cuts both ways. Ports, rail networks and power distribution are themselves critical infrastructure—and they are also the connective tissue that military operations rely upon during a crisis.

Market Statistics: The Numbers Behind the Warning

100+ systems: Federal agencies confirmed more than 100 internet-exposed water and wastewater systems were targeted in a single recent month of activity.

7 to 12+ states: Reported incidents spanned at least seven states, with indications of roughly a dozen affected, including Michigan, Minnesota, South Dakota, Georgia, New Jersey and Alabama.

~0.5%: Industry analysts estimate those 100 systems represent only a fraction of the total US water utility base—reinforcing that the campaign is a probe rather than a one-off.

Multi-agency response: Five federal agencies have jointly issued advisories on the activity, signaling the elevated national priority assigned to OT/ICS defense.

Market Trend: The attack campaign is evolving from commodity exploitation toward AI-assisted, scalable tooling. That shift compresses the time defenders have to patch and harden environments—and it raises the value of network segmentation, asset inventory and rapid firmware discipline across the entire automation supply chain.

The Strategy Gap: Why OT Hardening Lags in Logistics

Makrokanis's central critique is that national strategy concentrates on headline-grabbing targets while treating the logistics and utility backbone as a secondary concern. The funding, attention and hardening mandates flow toward high-profile systems, leaving transportation and energy operators to retrofit decades-old control environments on constrained budgets.

The result is a familiar paradox: the infrastructure most essential to sustained military operations is often the least resourced to defend itself.

What Operators and Integrators Should Do Now

The remedies are neither exotic nor expensive—but they demand discipline. Federal guidance consistently returns to a handful of foundational controls that eliminate the easiest attack paths.

FAQ: Practical Hardening Steps for PLC and ICS Environments

What is the single most urgent action? Remove publicly exposed PLCs and other OT assets from the internet. Direct exposure is the common denominator in documented attacks.

How should remote access be handled? Replace direct modem or public-internet connections with intermediate, hardened systems that enforce authentication and monitoring.

What about credentials? Change default passwords, enforce unique credentials, and eliminate shared accounts across controllers and engineering workstations.

Is network segmentation mandatory? It is the highest-value structural control—isolating OT networks from IT and the public internet dramatically reduces accessible attack surface.

How often should exposure be reassessed? Continuously. Networks, third-party connections and remote maintenance links evolve, and each change can reopen a previously closed path.

Do end-of-life controllers need replacing? Legacy units without modern security features should be inventoried, isolated, and prioritized for upgrade or compensating controls.

The Bottom Line for the Automation Sector

The strategic blind spot highlighted in the op-ed is a signal to every stakeholder in industrial automation—manufacturers, integrators, and plant operators alike. The components that run ports, rail and power are the same components that run water systems, and the adversaries have already demonstrated their willingness to exploit them.

Defending the logistics backbone is not a niche cybersecurity task. It is the difference between a military that moves and one that stalls—and it starts with treating every exposed PLC as a potential front line.

Related Articles

Back to blog