Our takeCISA is seeing a significant increase in actors targeting PLCs in water and wastewater systems. If you run these controls, pull any internet-exposed PLCs and OT offline now and review remote access.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:If you operate water or wastewater OT, inventory PLCs and other controllers for internet exposure and remove any public access immediately. Review remote-access paths and OT/IT segmentation against the CISA alert.
What this means for you — Lean IT orgs:Unless you run water or wastewater systems, this likely does not apply directly. If you do operate any industrial or building controllers, take them off the public internet and lock down remote access now.
What this means for you — MSP:Survey client estates—especially water, wastewater, and industrial accounts—for internet-facing PLCs or OT and pull them offline. Treat exposed controllers as an urgent finding across your book.
What this means for you — Researcher:CISA reports a significant rise in threat activity against PLCs in the water and wastewater sector; primary guidance is removing public internet exposure of OT. Track the alert for any added TTPs or affected product detail.