Connect your PLCs to the Internet: What could possibly go wrong?

Why CISA is urging an immediate off-grid shift for OT devices

Key Highlights

  • CISA issued an alert warning that cyber threat actors are actively targeting exposed programmable logic controllers (PLCs) in the water/wastewater sector to lock out operators and disrupt operations.
  • Infrastructure owners and operators are strongly urged to remove publicly exposed PLCs and operational technology (OT) devices from the Internet immediately to prevent unauthorized access.
  • Automation suppliers like Rockwell Automation are addressing these vulnerabilities by providing security advisories and guidance to help utilities restore access and secure their environments.

The threat is real. In case you hadn’t heard by now, the Cybersecurity & Infrastructure Security Agency (CISA) issued an alert on July 30 regarding a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the water/wastewater sector.

While the U.S. government has not at this point made a public attribution of the activity, CISA has urged all critical infrastructure owners, operators and integrators to remove publicly exposed PLCs and other OT devices from the internet ASAP. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing IP addresses, according to the CISA alert.

“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” explains CISA Acting Director Nick Andersen. “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the Internet as soon as possible. We also encourage all organizations to review the latest guidance on CISA.gov and to report suspected incidents or anomalous activity to us for further support.”

Control Design’s longest standing columnist, automation industry veteran Jeremy Pollard, spoke with me about the vulnerabilities of PLCs; the evolution of their connectivity to the Internet; the use of virtual private networks (VPNs) and gateways; and what machine builders can learn from this to keep industrial equipment secure.

Rockwell Automation has addressed the alert with a published security advisory including guidance on restoring access to MicroLogix 1400 and MicroLogix 1100 controllers when the password is unknown. Its corporate communications spokesperson indicated: "Rockwell Automation takes the security of its products and solutions seriously and has been working with customers, partners and government agencies regarding reports of unauthorized cyber activity and disruptions at some utilities. Rockwell Automation has provided customers with guidance and published security advisories that include recommendations for strengthening the security of operational technology environments."

Chapters

  • 00:00 – CISA Security Alert Overview
  • 01:41 – Why Are PLCs Susceptible to Attacks?
  • 03:29 – Boundary Checks
  • 04:45 – Password Management
  • 09:05 – Wastewater SCADA Architecture
  • 12:23 – Understanding VPNs & Nodes

About the Author

Mike Bacidore

Editor in Chief

Mike Bacidore is chief editor of Control Design and has been an integral part of the Endeavor Business Media editorial team since 2007. Previously, he was editorial director at Hughes Communications and a portfolio manager of the human resources and labor law areas at Wolters Kluwer. Bacidore holds a BA from the University of Illinois and an MBA from Lake Forest Graduate School of Management. He is an award-winning columnist, earning multiple regional and national awards from the American Society of Business Publication Editors. He may be reached at [email protected] 

Sign up for our eNewsletters
Get the latest news and updates