As part of our ongoing monitoring of the threat landscape, ISI Cyber wanted to share a recent development involving Operational Technology (OT). This is especially relevant to organizations operating industrial, manufacturing, building management, or other connected physical systems.
The FBI and EPA recently warned that malicious actors are actively targeting internet facing Programmable Logic Controllers (PLCs) used in water and wastewater facilities. Since July 27, incidents have been reported across at least seven states.
Key threat insights:
An OT compromise can look very different from a traditional IT incident.
An IT incident may affect data or system availability. An OT incident can affect production, equipment, safety, infrastructure, and potentially mission readiness.
That distinction is getting more attention from Department of War (DoW) Chief Information Officer (CIO), Kirsten Davies, who has publicly stated that OT will receive more focus from her office. The recent Brilliant at the Basics guidance reinforces fundamental OT controls including asset visibility, segmentation, secure remote access, continuous monitoring, and documented incident response plans.
This communication is advisory only.
If your organization doesn’t operate OT, industrial control systems, or connected physical equipment, no immediate action is required.
If you do operate OT, consider reviewing:
Organizations should also understand who owns and supports each OT system, including any third-party integrators or specialized OT providers.
We’re sharing this because the FBI activity provides a real-world example of the same OT risks the DoW CIO is now putting additional focus on across the Department and Defense Industrial Base.
Stay safe, stay secure.
-ISI Cybersecurity Team