Back to Blog
Critical Infrastructure Advisory

Defending Critical Infrastructure: What Recent PLC Attacks Mean for Water & Industrial Systems

Threat actors are actively targeting internet-exposed industrial control systems and PLCs across US facilities. Here is what infrastructure leaders need to know, and how to harden your operational environment today.

Published 2025 9 min read OT Security

Update — August 2026

CISA has issued a joint Cybersecurity Advisory confirming an active threat to Siemens S7 series PLCs. Attackers are leveraging publicly documented weaknesses in the legacy S7comm protocol to compromise internet-exposed controllers, overwrite control logic, and disrupt industrial processes. All operators running Siemens S7-300/400/1200/1500 equipment should treat this as an active exploitation event and apply the hardening steps below immediately.

Download the CISA Guidance (PDF)
Critical Risk

Direct Internet-Facing PLCs & HMIs

Physical Impact

Valve overrides, pressure loss & emergency boil orders

Zero-Trust

Mandatory IT/OT DMZ network segmentation

Watch Episode 2 by 5D Cyber: How Hackers Hijacked US Water Plants

From Data Theft to Physical Kinetic Disruption

For decades, industrial control systems (ICS) were assumed safe behind the "air gap," the physical separation between operational technology (OT) and corporate networks. That air gap has effectively dissolved. Modern water, wastewater, and manufacturing facilities now connect PLCs, HMIs, and SCADA systems to business networks for remote monitoring, efficiency, and vendor support. The result is severe exposure across the sector, and attackers have shifted from stealing data to causing real-world, physical disruption.

The Latest Development: Active Threat to Siemens S7 Series PLCs

A joint CISA advisory published August 18, 2026 confirms malicious actors are actively exploiting internet-exposed Siemens S7 series programmable logic controllers. The legacy S7comm (S7 Communication) protocol, used widely across water, energy, and manufacturing environments, lacks native authentication and encryption — allowing attackers who can reach a controller to read and overwrite its logic, issue unauthorized set-point commands, and disrupt physical processes.

The advisory is a sharp reminder that the threat is not theoretical. It moves from opportunistic scanning to confirmed, targeted exploitation of a specific, widely deployed vendor platform — and underscores why every utility and industrial operator should audit for exposed S7 ports today.

Read the Full CISA Advisory (PDF)

Internet-Facing PLCs/HMIs

Devices reachable via open ports on public IP addresses, directly discoverable by internet-wide scanners.

Default Vendor Credentials

Factory passwords left unchanged on field controllers, granting immediate access to anyone who can reach the device.

Flat, Unsegmented Networks

Direct routing paths between corporate IT and industrial OT, allowing an IT compromise to pivot into control systems.

Legacy Remote Access

Management portals lacking phishing-resistant Multi-Factor Authentication, exposed to credential theft and session hijacking.

5-Step Hardening Roadmap for Utility & Industrial Operators

A prioritized, practical sequence to close the exposure gap across your operational environment.

1

Eliminate Public Exposure

Disallow direct web access to control devices; audit exposed industrial ports (Modbus, EtherNet/IP, BACnet) using continuous attack surface scanning.

2

Enforce Phishing-Resistant MFA

Mandate Multi-Factor Authentication on all remote management gateways and change every factory-default credential across field devices.

3

Implement IT/OT Network Segmentation

Deploy industrial firewalls to establish a strict DMZ between enterprise business networks and control subnets.

4

Maintain Golden-Image Backups & Manual Overrides

Keep offline, air-gapped backups of all PLC logic and test physical manual valve controls on a regular schedule.

5

Monitor OT Traffic at Switch Level

Deploy behavioral network sensors to flag unauthorized firmware changes or abnormal set-point commands in real time.

Infrastructure Hardening Checklist

Use this readiness matrix to benchmark your facility against the controls that matter most.

Priority
Control Requirement
Status
Critical
Zero PLCs/HMIs directly exposed to the public internet
Audit Required
Critical
Factory default passwords updated across all field devices
Audit Required
Critical
Siemens S7-300/400/1200/1500 controllers removed from public internet access; S7comm (TCP 102) not reachable externally
Audit Required
High
Phishing-resistant MFA enforced on all remote access portals
Audit Required
High
Strict firewall DMZ separating IT systems from OT networks
Audit Required
Medium
Tested, offline backups of PLC logic & SCADA software
Audit Required
Medium
Switch-level OT network traffic monitoring enabled
Audit Required

End-to-End Operational Defense with 5D Cyber

5D Cyber operates a specialized infrastructure security practice built for water, wastewater, and industrial organizations. We translate operational risk into measurable, audit-ready defense:

External Attack Surface & Exposure Audits

Rapid discovery of exposed controllers and shadow IT across your public footprint.

IT/OT Architecture & Zero-Trust Segmentation

Custom DMZ and secure jump-box design to isolate control systems from the enterprise network.

24/7 Managed Detection & Response (MDR)

Real-time perimeter and gateway threat monitoring, with rapid containment of active intrusions.

Ransomware & Incident Recovery Planning

Custom tabletop exercises and operational recovery playbooks to restore control systems under pressure.

Is Your Operational Technology Exposed?

Don't wait for an active lockout to discover your perimeter blind spots. Schedule a confidential infrastructure review with the 5D Cyber engineering team.