Elif Özaksu
Corporate
- Thread Author
- #1
Recent attacks on internet-connected PLCs in critical infrastructure in the US have garnered significant media attention. Headlines focused on Iranian-linked threat actors and national security concerns. While these concerns are valid, they risk overshadowing the crucial point: for OT professionals, the details of these incidents are not new.
🤔 An Industry in Transition
These incidents highlight that OT cybersecurity is in a period of transition. Awareness is much higher than it was 10 years ago; most operators understand the importance of cybersecurity. However, the real challenge lies in implementation.
- Many organizations have policies, guidance documents, and technology investments.
- Yet, they struggle to maintain asset visibility, manage remote access, validate recovery processes, and build OT-specific expertise.
The problem is no longer awareness, but a lack of operational implementation.
🌐 Why Are There Still Internet-Connected PLCs?
One of the most common reactions to incidents like the recent attacks on water systems is the astonishment, "How can there still be a PLC directly connected to the internet?" However, for those who have spent time in water treatment plants, manufacturing facilities, or municipal infrastructures, the situation is different.
- Most exposed systems were not intentionally set up to create a cybersecurity risk.
- They were the result of decades of operational decisions made to ensure reliability, accessibility, and maintainability.
- Remote access was enabled for troubleshooting, reducing travel costs, and providing support to third parties.
Every decision made sense at the time it was made. However, over time, they can lead to an unintended exposure that is not fully understood by the system's operator. In small-scale facilities, the same individuals might be operating the water treatment plant and also handling network administration, SCADA management, compliance reporting, and cybersecurity tasks. This often stems not from negligence, but from a lack of resources and OT cybersecurity specialists.
🧠 The Expertise Gap: The Real Vulnerability
The cybersecurity industry often frames its conversations around technology acquisition: endpoint protection, network monitoring, firewalls, etc. While these technologies are valuable, many critical infrastructure organizations face a much larger problem: a lack of OT cybersecurity expertise among their personnel.
The difference between IT security and OT security is vast. A great IT security professional might know how to manage authentication, cloud, and enterprise networks, but understand nothing about:
- Protecting control logic
- Operational safety
- Industrial communications
- Engineering workflows
- Maintenance
- Availability
Without this knowledge, implementing cybersecurity advice can be very difficult. This expertise gap is particularly problematic for small municipalities and public utilities.
🤝 Third-Party Access: The Forgotten Attack Surface
When it comes to internet-accessible PLCs and other industrial systems, the emphasis is often on the assets themselves. However, many OT incidents occur due to authorized remote access points that were initially established for legitimate reasons.
- System integrators, OEMs, contractors, and service providers often require access to perform commissioning, troubleshooting, updates, and other maintenance tasks.
- This access can be quite beneficial, but it can also pose risks if not properly managed.
Common issues include remote support solutions that were set up several years ago and have not been regularly reviewed since. Some of these reviews might involve validating shared service accounts accessed by several external personnel, and can also lead to overly privileged access that exceeds current organizational requirements.
The easiest question organizations can start with is: "Which third parties currently have access to our OT environment, and when was the last time we reviewed it?" Often, the answer turns out to be not as simple as it seems. Effective management of the environment requires regular review of all third-party access points, documented ownership for each, and appropriate access approval processes, as well as the ability to monitor and audit external activities within the OT environment.


















