HN Debrief

CISA Alert: Water Sector PLC Targeting

  • Security
  • Infrastructure
  • Public Policy
  • Hardware

The linked post is a vendor writeup on a CISA alert covering attempts to access PLCs used in water infrastructure, with Censys adding internet scan data showing more than four thousand hosts answering on EtherNet/IP and identifying as Rockwell Automation or Allen-Bradley. That gave people a concrete number to react to, but the bigger point was familiar: critical control systems are still exposed to the public internet in 2026, and nobody in the space sounds surprised anymore.

If you operate industrial systems, stop treating this as a niche OT problem and assume exposed control equipment will be found and probed. For leaders, the practical issue is governance and funding: inventory internet exposure, remove direct access, and make someone accountable for legacy system risk instead of waiting for federal warnings to do the work.

Discussion mood

Frustrated and alarmed. Most comments treated the exposure as long-running, obvious negligence shaped by legacy OT constraints, weak procurement, and absent accountability rather than a surprising new cyber campaign.

Key insights

  1. 01

    Security gets lost in project procurement

    Security falls out of the system long before a device is exposed online. Water and wastewater upgrades are often awarded as narrowly scoped projects to the lowest bidder, with vague security requirements, weak inherited documentation, and no budget for the slow process work that OT security actually needs. That explains why "just disconnect it" and "just patch it" keep failing as prescriptions. The organization that delivered the install is paid to finish the project, not to own secure operations for the next decade.

    If you buy industrial upgrades, write concrete security controls into the contract and fund post-install operations, not just commissioning. Ask who owns documentation, password rotation, remote access, and logging after the integrator leaves.

      Attribution:
    • doobiedowner #1
    • fathermarz #1 #2
  2. 02

    Legacy remote access is the real trap

    Old connectivity is not automatically insecure, but in practice it becomes dangerous because it is glued directly onto fragile control systems with almost no compensating controls. Comments described dial-up lines that auto-answer into PLC or HMI environments, shared passwords, little monitoring, and Windows XP SCADA machines still sitting behind them. The problem is not nostalgia for old tech. It is that obsolete access paths are still carrying production risk while the systems behind them can no longer be patched or meaningfully instrumented.

    Treat every legacy remote access method as a live attack surface, even if it feels obscure. Inventory modems and cellular links, then put modern authentication, logging, and network isolation in front of them or retire them on a deadline.

      Attribution:
    • fathermarz #1
    • tamimio #1
  3. 03

    OT is not just badly managed IT

    Control engineers in the comments drew a hard line between enterprise IT and operational technology. PLCs and related gear are often weakly secured by design, and the systems they run cannot be rebooted, patched, or swapped on normal IT schedules because doing so can interrupt physical processes. That does not excuse internet exposure, but it changes the shape of the fix. The right response is engineered isolation, tightly controlled remote access, and process discipline, not copying a corporate laptop policy onto plant equipment.

    Put OT under a security program that starts from uptime and safety constraints instead of forcing it into standard IT playbooks. Leaders should ask whether their security team actually has ICS and OT expertise, not just general network or endpoint experience.

      Attribution:
    • fathermarz #1 #2
    • andyjohnson0 #1
  4. 04

    Scale breaks purely federal enforcement

    The sector's structure matters. With more than 150,000 water utilities in the US by one commenter’s count, a model that assumes the federal government will directly secure every small operator is not credible. Regulation may still be necessary, but the operating burden lands locally through asset owners, integrators, and state-level oversight. The number explains why repeated national alerts do so little on their own. The system is too fragmented for warning memos to turn into uniform practice.

    If your strategy depends on a central authority finding and fixing every weak site, it is not a strategy. Build controls that can be checked through procurement, insurance, audits, and state or regional governance closer to the operators.

      Attribution:
    • fathermarz #1 #2
    • throwaway894345 #1

Against the grain

  1. 01

    Incentives matter more than compensation

    Higher pay alone will not fix a bureaucracy that does not reward initiative or punish inaction. This view argues that people in politically diffused organizations learn to avoid personal risk, which makes security drift toward the minimum acceptable effort even when talent is present. That framing cuts against the idea that the main problem is simply underpaying skilled staff.

    When you fund cyber hiring in public infrastructure, pair it with clear ownership and decision rights. Otherwise you may buy expertise that still cannot force upgrades, shut off unsafe access, or change procurement behavior.

      Attribution:
    • moscoe #1 #2
  2. 02

    Obsolete links are not automatically unsafe

    One technical pushback said the age of a transport like dial-up or 3G is not the decisive issue. A slow point-to-point link can be wrapped in secure tunnels and may present a smaller attack surface than a device listening on the open internet. That does not defend the examples described elsewhere, but it is a useful correction to the idea that every old technology is inherently worse than every new one.

    Do not use age as your risk model. Judge remote access by exposure, authentication, encryption, and monitoring, then prioritize the links that are reachable and unaudited over the ones that are merely old.

      Attribution:
    • fc417fc802 #1

In plain english

3G
Third-generation cellular network technology, now being retired in many places and often still embedded in older field equipment.
Allen-Bradley
A product brand of industrial control hardware, especially PLCs, owned by Rockwell Automation.
CISA
Cybersecurity and Infrastructure Security Agency, the main US federal agency that warns about and coordinates response to cyber threats affecting critical infrastructure.
EtherNet/IP
An industrial network protocol used to let factory and utility control devices communicate over Ethernet networks.
HMI
Human-Machine Interface, the screen or software operators use to monitor and control industrial equipment.
OT
Operational Technology, the hardware and software that monitors or controls physical industrial processes such as water treatment or manufacturing.
PLC
Programmable Logic Controller, a rugged industrial computer that directly controls machines, pumps, valves, and other physical equipment.
Rockwell Automation
A major industrial automation vendor whose Allen-Bradley brand makes widely used PLCs and control equipment.
SCADA
Supervisory Control and Data Acquisition, a class of systems used to supervise and control industrial processes across facilities and networks.

Reference links

Industry commentary