Beyond the air gap: How to secure PLCs in the wake of the CISA alert

Why publicly exposed OT devices need protection

Key Highlights

  • Critical infrastructure facilities must immediately disconnect publicly accessible OT devices and thoroughly audit hidden pathways, such as undocumented cellular modems, that put industrial controllers at risk.
  • Facilities can significantly reduce vulnerabilities across the hardware lifecycle by applying foundational engineering controls, including default credential changes, restricted workstation access, role-based authentication and off-line logic backups.
  • Because legacy controllers and protocols like Modbus lack inherent encryption, security must be built into system architectures from the start rather than bolted on after deployment.

 

Following the July alert from the Cybersecurity & Infrastructure Security Agency (CISA), American water/wastewater plants are battening down the hatches on operational technology (OT).

CISA has urged all critical infrastructure facilities to remove publicly exposed OT devices from the Internet. All organizations should validate any external connections, as the targeting has included cellular modems that may not be documented.

Jagannathan Raghunathan is director of cyberphysical security services at Bureau Veritas and co-chair of the PLC Security Top 20 List. In this interview, he outlines how the PLC Security Top 20 List addresses programmable logic controller (PLC) vulnerabilities by offering practical, engineering-focused guidance across the hardware lifecycle. Rather than relying solely on high-level IT security frameworks, the initiative leverages the built-in capabilities of industrial controllers to enforce core hardening principles. His recommendations include eliminating direct Internet exposure, replacing default credentials, restricting engineering workstation access, enforcing granular role-based authentication and maintaining off-line logic backups to ensure controllers remain in a known secure state.

Legacy PLCs were originally engineered decades ago with a focus on uptime and availability within physically isolated networks. However, the shift toward remote operations during the COVID-19 pandemic, alongside the rise of cloud-hosted SCADA platforms, cellular modems and AI-driven programming, has expanded the attack surface. Because foundational industrial protocols like Modbus were designed without native encryption or authentication, modern connectivity options have left legacy hardware susceptible to basic Internet scans and open-source intelligence tools, says Raghunathan.

He urges industry stakeholders to eliminate undocumented remote access pathways, secure unavoidable connections and adopt a security-by-design methodology, rather than attempting to bolt on safeguards post-commissioning. 

Chapters

  • 00:00 – CISA Warning on PLC Threats
  • 01:17 – PLC Security Top 20 Initiative
  • 03:13 – History & Purpose of the PLC Top 20 Group
  • 04:50 – Why PLCs Are Vulnerable by Design
  • 09:10 – Remote Access, Cloud SCADA & AI Impacts
  • 15:20 – System Integrators & Machine Builders
  • 17:46 – Security by Design

About the Author

Mike Bacidore

Editor in Chief

Mike Bacidore is chief editor of Control Design and has been an integral part of the Endeavor Business Media editorial team since 2007. Previously, he was editorial director at Hughes Communications and a portfolio manager of the human resources and labor law areas at Wolters Kluwer. Bacidore holds a BA from the University of Illinois and an MBA from Lake Forest Graduate School of Management. He is an award-winning columnist, earning multiple regional and national awards from the American Society of Business Publication Editors. He may be reached at [email protected] 

Sign up for our eNewsletters
Get the latest news and updates