Nation-state actors are exploiting internet-exposed PLCs. See why OT/SCADA security requires more than IT tools — and how InfoSight closes the gap.
In April 2026, CISA and its federal partners issued advisory AA26-097A, warning that Iranian-affiliated cyber actors were actively exploiting internet-connected programmable logic controllers (PLCs) across U.S. critical infrastructure. By July, the agencies updated it — not to close the case, but to widen it. What started as targeting of Rockwell Automation/Allen-Bradley devices now includes Schneider Electric and Siemens PLCs, with water and wastewater systems named specifically among the affected sectors.
The details change with every update.
The underlying problem doesn't: PLCs, HMIs, and SCADA systems that were never designed to be internet-facing keep ending up exposed anyway, and attackers are exploiting that gap with legitimate remote engineering tools and valid credentials — not exotic zero-days. This is the reality of OT security in 2026, and it's exactly the gap InfoSight was built to close.
Why OT Security Isn't IT Security
Traditional IT security tools were built for a world of laptops, servers, and cloud workloads that get patched monthly and rebooted without consequence. Operational technology doesn't work that way. A PLC controlling a chemical dosing pump or a substation breaker might run the same firmware for a decade. Taking it offline for a patch can mean a production line stops or a community loses water pressure.
That's why the CISA advisory's core recommendation — remove PLCs from direct internet exposure via secure gateways and firewalls — sounds simple but is operationally hard. It requires understanding exactly what's connected, how it's connected, and what breaks if you change it. Most organizations converging IT and OT don't have that map. InfoSight builds it for them.
Where InfoSight Fits: Assessment, Detection, and Response
ICS/SCADA security assessments. Before you can secure an environment, you need to see it. InfoSight's industrial control and OT assessments map the entire ICS/SCADA network and perform critical path analysis to surface dependencies most teams don't know exist — which PLC talks to which HMI, which remote access path was set up for a vendor three years ago and never closed. From there, our risk reduction planning prioritizes vulnerabilities based on actual exploitability and asset criticality, not just CVSS scores, so remediation dollars go where they matter.
24x7 ICS, SCADA & OT managed detection and response. Visibility on its own doesn't stop an active intrusion. InfoSight's SOC provides continuous, protocol-aware monitoring across Modbus, DNP3, OPC, IEC 104, and BACnet — the languages PLCs and SCADA systems actually speak, and the traffic most IT-focused tools never inspect. When someone pushes an unauthorized project file change or a device gets switched to run mode without validation, our analysts see it and act, instead of finding out after a shutdown function has already been disabled.
Credential and access hardening. The AA26-097A actors aren't breaking encryption — they're using valid credentials and legitimate remote engineering software. InfoSight helps organizations enforce MFA on external OT access, isolate cellular modem architecture, retire default device passwords, and put real controls around who can touch a PLC and from where.
Built for the Sectors Where This Matters Most
InfoSight works across the industries where IT and OT convergence carries the highest stakes: water and wastewater, energy and utilities, oil and gas, manufacturing, and government. Each of these sectors runs on control systems that were built for reliability, not internet exposure — and each shows up repeatedly in CISA's critical infrastructure advisories. Our teams bring sector-specific context, from NERC CIP considerations for utilities to the segmentation and uptime constraints unique to manufacturing floors.
This Advisory Won't Be the Last
AA26-097A is a snapshot of a much longer trend: adversaries — state-sponsored and criminal alike — have learned that OT environments are softer targets than hardened IT networks, and that the consequences of a successful intrusion are more severe. The manufacturers and models named in this advisory will change in the next one. The underlying exposure won't fix itself.
Organizations running PLCs, SCADA, or ICS environments don't need to wait for the next advisory to find out where they stand. InfoSight's assessments and managed OT security services are built to answer that question now — and to keep answering it as the threat landscape shifts.
Ready to find out what's actually exposed on your OT network? Talk to InfoSight's team about an ICS/SCADA security assessment.