Factories, water utilities, energy providers and government facilities run on operational technology: the controllers, human-machine interfaces (HMIs) and industrial networks that move valves, run production lines and keep services flowing. Much of that equipment was installed decades ago, was never designed to face the internet, and is now being actively probed by nation-state groups, ransomware crews and opportunistic hacktivists alike.
Throughout 2025, US agencies repeatedly warned operators to find and protect exposed legacy systems, from HMIs reachable over the internet to the firewall and remote-access consoles that sit between business networks and plant floors. These are not just IT problems. A single compromise can halt production, disrupt supply chains, or interrupt services that whole communities depend on. This article explains why industrial environments are so exposed and what operators can do about it.
What the warnings say
In May 2025 CISA, the FBI, the EPA and the Department of Energy issued a joint fact sheet, “Primary Mitigations to Reduce Cyber Threats to Operational Technology,” after observing unsophisticated actors targeting industrial control systems in US critical infrastructure. The message was blunt: attackers were succeeding not through advanced exploits but by finding internet-exposed HMIs and controllers with default or weak passwords.
That pattern has a track record. In late 2023, an Iran-linked group calling itself CyberAv3ngers defaced Unitronics programmable logic controllers at US water facilities, including the Municipal Water Authority of Aliquippa in Pennsylvania, largely by exploiting internet exposure and default credentials. At the other end of the sophistication scale, US and allied agencies warned in February 2024 that the China-linked group Volt Typhoon had pre-positioned inside IT networks of critical infrastructure organizations in ways that could enable disruption of OT systems in a future crisis.
Between those extremes sit ransomware groups. They rarely target controllers directly, but when they encrypt the business network that schedules production or bills customers, operators often shut down the plant as a precaution. The 2021 Colonial Pipeline shutdown, triggered by a ransomware attack on IT systems, remains the best-known example.
Why industrial systems are so exposed
- Long lifespans. Industrial equipment is expected to run for 15 to 30 years. Operating systems on HMIs and engineering workstations are frequently long out of support, and patching can require vendor approval and a production shutdown.
- Protocols built for trust. Many industrial protocols, such as Modbus, have no authentication. Anyone who can reach the device on the network can send it commands.
- Convenience-driven connectivity. Remote access for vendors and engineers, often added quickly and never revisited, is a common path in. So are HMIs placed directly on the internet for monitoring from a phone.
- IT and OT convergence. Production data now flows to ERP systems, cloud analytics and SaaS platforms. Each connection is useful, and each is a potential bridge from a compromised office laptop to the plant floor.
- Cascade effects. A manufacturer that stops producing affects every customer downstream. A single weakness in a shared supplier, integrator or remote-access vendor can reach many sites at once.
A practical defense plan for operators
The agencies’ guidance and established frameworks such as ISA/IEC 62443 and NIST SP 800-82 converge on a short list of actions. In rough priority order:
- Remove OT assets from the public internet. Search for your own exposed HMIs, controllers and management consoles, using your external attack surface tools or services that index internet-connected devices. Anything reachable from the internet should be taken off it or placed behind a secured gateway.
- Change default passwords and enforce strong credentials. This alone would have stopped many of the 2023 and 2025 incidents.
- Secure remote access. Route all vendor and engineer access through a single controlled path, such as a VPN or privileged access gateway with phishing-resistant MFA, session recording and time-limited accounts. Patch that gateway quickly; firewalls and VPN appliances are among the most exploited devices in any network.
- Segment IT from OT. Put a demilitarized zone between business and industrial networks, allow only the specific data flows that are needed, and deny everything else by default.
- Build an asset inventory. List every controller, HMI and engineering workstation with firmware versions and network paths. Passive OT monitoring tools can build this without disrupting operations.
- Monitor for anomalies. OT-aware detection, including machine learning models that learn normal process traffic, can flag unexpected commands or new devices. Treat it as a complement to segmentation, not a substitute.
- Practice manual operations. Make sure staff can run critical processes safely without the HMI, and that you have tested backups of controller logic and configurations.
Supply chain, people and the business case
Supply chain. System integrators, equipment vendors and maintenance contractors often hold persistent access to many customers. Include OT security requirements in contracts: notification of vulnerabilities, secure remote-access methods, and the right to review their practices. When patches are impractical, ask vendors for compensating controls in writing. Our article on critical zero-days in legacy software covers why unsupported systems demand this approach.
People. Social engineering remains a leading way into the IT networks that connect to OT. Plant engineers and operators need training tailored to their environment: recognizing suspicious remote-access requests, handling USB media, and reporting unusual HMI behavior.
The business case. The trade-off in OT security is uptime. Every change carries a risk of disrupting production, which is why OT teams are cautious. The answer is to plan changes in maintenance windows, test them in a lab or on redundant equipment first, and start with the actions that carry little operational risk, such as removing internet exposure and changing passwords. The cost of an unplanned multi-day shutdown usually dwarfs the cost of a planned one.
Update (September 2026): In December 2025 CISA and partner agencies issued a further advisory on pro-Russia hacktivist groups conducting opportunistic attacks against internet-exposed OT in US and global critical infrastructure, reinforcing the same core mitigations: remove exposure, change default credentials and segment networks.
Frequently asked questions
We are a mid-sized manufacturer, not critical infrastructure. Are we a target?
Yes. Most attacks on industrial systems are opportunistic: attackers scan for exposed devices and weak passwords regardless of who owns them. Manufacturers are also among the most frequent ransomware victims because downtime creates pressure to pay.
Can we run standard IT security tools on OT networks?
Carefully. Active scanning can crash older controllers. Use passive monitoring built for industrial protocols, and test any agent on OT workstations with the vendor’s approval first.
What if the vendor no longer supports our HMI?
Isolate it. Remove network paths it does not need, restrict who can reach it, monitor it closely, and put its replacement on the capital plan with a date.
Modernize, monitor and mobilize
Delana Technologies helps manufacturers, utilities and public organizations reduce OT and legacy-system risk, from exposure assessments and segmentation design to vendor access controls and compliance with sector frameworks. To review your industrial environment, call 239.414.5126 or contact us.
Sources: CISA, FBI, EPA and DOE, “Primary Mitigations to Reduce Cyber Threats to Operational Technology” (May 2025); CISA advisory on IRGC-affiliated actors exploiting Unitronics PLCs (December 2023); CISA advisory AA24-038A on Volt Typhoon (February 2024); CISA advisory AA25-343A on pro-Russia hacktivists (December 2025); NIST SP 800-82 Rev. 3; ISA/IEC 62443.
