CISA Sounds Alarm on Internet-Exposed PLCs Amid Escalating OT Threats

CISA Sounds Alarm on Internet-Exposed PLCs Amid Escalating OT Threats

Why it matters now: For the second time in as many years, the United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark and unambiguous warning: internet-connected programmable logic controllers (PLCs) are being actively targeted, remotely accessed, and reprogrammed by threat actors — and the majority of exposed devices still lack even the most rudimentary authentication controls. The advisory, co-signed by the FBI, NSA, EPA, and Department of Energy, is not a theoretical exercise. It reflects confirmed, ongoing intrusions across the water, energy, and manufacturing sectors — with physical safety consequences already on the table.

Analyst Insight: This is not a patchable vulnerability. The threat actors are connecting to exposed PLCs using the same legitimate engineering software — such as Rockwell Automation's Studio 5000 — that authorized technicians use. What CISA is describing is an architectural weakness, not a software bug. The internet was never meant to touch these devices directly.

The Attack Vector: No Exploit Required

The modus operandi detailed in the joint advisory is disturbingly simple. Threat actors — linked by intelligence agencies to Iranian-affiliated advanced persistent threat (APT) groups — scan the open internet for industrial control system (ICS) devices. When they locate a PLC with no authentication gate, they connect exactly as a legitimate engineer would.

Once inside, the attacker can modify the controller's underlying logic — the instructions that tell physical equipment what to do. In documented cases, operators saw no anomalies on their HMI or SCADA displays because the attackers also manipulated the data being presented on those screens. A valve could be commanded to malfunction while the control room display shows normal operation.

The Scale of Exposure: 74,000+ ICS Devices Visible Online

Public scan data from Shodan, the internet-connected device search engine, reveals that more than 74,000 industrial control system devices are directly reachable from the open internet today. These span PLCs from Rockwell Automation/Allen-Bradley, Siemens, Schneider Electric, and other major manufacturers. While this figure represents a decline from previous highs, security researchers note that the devices which remain are often the most critical — and the most persistently misconfigured.

The targeted devices include Rockwell CompactLogix and Micro850 PLCs, with evidence that attackers are also scanning ports associated with Siemens S7 protocol, suggesting a broadening campaign across multiple OT vendor ecosystems.

Manufacturing: The Number One Target

The manufacturing sector has emerged as the most frequent victim of OT-focused cyber campaigns. According to Check Point's Manufacturing Threat Landscape 2025 report, cyberattacks against manufacturers surged 56% in 2025, climbing from 937 recorded incidents to 1,466. The Dragos 2026 OT/ICS Cybersecurity Report tracked 26 active OT threat groups globally, with manufacturing accounting for more than two-thirds of all victims.

The logic is straightforward: production downtime translates directly to financial loss. A compromised PLC on a packaging line, a bottling plant, or an assembly station can halt operations for hours or days. And unlike IT ransomware, where data can sometimes be restored from backups, a corrupted PLC logic file may require physical on-site reconfiguration — a process that demands specialized engineering expertise.

Market Trend: ICS vulnerability disclosures nearly doubled year-over-year, with 2,451 vulnerabilities identified across 152 vendors according to Cyble's Annual Threat Landscape Report 2025. This widening attack surface, combined with legacy devices never designed for network connectivity, creates a structural risk environment that regulatory pressure alone cannot solve.

CISA's Urgent Mitigation Guidance

The advisory outlines specific, actionable steps that critical infrastructure operators should implement immediately. The primary recommendation is unambiguous: remove PLCs and other OT devices from direct internet exposure. If a PLC is reachable from the public internet without a controlled intermediary — a firewall, secure gateway, or VPN — that exposure must be closed now.

Beyond disconnection, CISA urges operators to activate physical mode switches or software key switches on PLCs that prevent remote modifications, implement proper network segmentation between OT and IT environments, create offline backups of PLC configurations, and verify that all configurations match known-good baselines to detect unauthorized changes.

Key Questions About PLC Exposure & Risk

Why are so many PLCs still internet-connected?

Many industrial organizations connected PLCs for remote monitoring and diagnostics during the pandemic-era push for remote operations. Others inherited configurations from system integrators who enabled internet access for convenience during commissioning and never removed it. In both cases, the result is the same: devices designed for air-gapped networks are sitting on the public internet.

Which industries are most at risk?

The joint advisory specifically flags water and wastewater systems, energy infrastructure, and manufacturing. Water utilities are of particular concern because many operate with limited cybersecurity staff and rely on remotely accessible SCADA systems for geographically dispersed pump stations and treatment facilities.

What makes PLCs so vulnerable?

PLCs were designed in an era when physical isolation was the primary security control. Most lack native authentication, encryption, or access logging. They listen for commands on well-known industrial protocols (EtherNet/IP, Modbus, S7) and execute whatever instructions arrive — without verifying the source.

Can a firewall solve the problem?

A properly configured firewall with strict access control lists and deep packet inspection can significantly reduce risk. However, CISA's guidance emphasizes that the only fully effective mitigation is complete removal from public internet access. Firewalls can be misconfigured, and VPN credentials can be compromised.

The Persistent Reality: Legacy Architecture Meets Modern Threats

The core challenge articulated in CISA's advisory is not new, but it is intensifying. The industrial automation market has long prioritized availability and reliability over security. PLCs that were installed a decade or more ago remain in service because they still control critical processes — and replacing them means costly downtime. Yet these same devices now sit at the intersection of nation-state cyber campaigns and an increasingly interconnected operational landscape.

ESET research found that 78% of UK manufacturers had experienced a cyber incident. The convergence of IT and OT networks, accelerated by Industry 4.0 initiatives, has dissolved whatever air gap once existed. For critical infrastructure operators, the CISA advisory serves as a final reminder: the window for voluntary remediation is closing, and the consequences of inaction are no longer confined to data loss — they now include the physical world.

Industry Takeaway: The CISA advisory signals a regulatory trajectory. Operators who fail to secure exposed PLCs today may face mandatory compliance requirements tomorrow. Proactive hardening — network segmentation, authentication enforcement, and continuous configuration monitoring — is no longer optional. It is the baseline expectation for operating critical infrastructure in 2025 and beyond.

Related Articles

Powrót do blogu