Sentinel Insights

Finished intelligence for the people who run the plant.

Free, plain-language OT/ICS security analysis for operators, facility teams, and small defense suppliers. No vendor noise. No fear marketing. Every issue tells you what it is, whether you're exposed, and what to do this week.

TLP:CLEAR

The Publications

Monthly

Advisory Translations

Advisories that actually matter to a five-person utility or shop floor, rewritten in plain English: what it is, are you exposed, three actions. Read free below.

Read the latest ↓
Quarterly • Email

Sector Threat Brief

Long-form sector analysis: key judgments, observed tradecraft, and tiered actions. Full briefs, free, no gate. Subscribe to get the next one by email.

Subscribe below ↓
Quarterly

Exposure Report

Original data: aggregate internet-exposed control-system statistics by sector and region, quarter over quarter. Counts and trends only — never operator identification.

First issue coming

Get the Sector Threat Brief

Quarterly. Finished intelligence, not a sales sequence.

No spam. No list sales. Unsubscribe anytime. We treat this list the way we treat client data.
Not sure whether an advisory applies to your plant?
Five-minute sanity check. No charge, no pitch. info@sentdyne.com

Latest — Advisory Translations

TLP:CLEAR SD-AT-2026-001 CISA Alert — Water & Wastewater Systems Sector 30 July 2026 Severity: active exploitation. If a controller of yours is reachable from the internet, this is a today problem.

Attackers are going after exposed plant controllers, and the way in is often something nobody wrote down

What it is

The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on 30 July after a sharp increase in attacks on programmable logic controllers in water and wastewater systems. A programmable logic controller, or PLC, is the small industrial computer that actually runs your pumps, valves and treatment steps.

The attackers are not stealing data. They are changing controller passwords so operators are locked out, and changing controller IP addresses so equipment drops off the network entirely. In the incidents behind this alert, that meant boil water notices and crews running plants by hand.

More than thirty community water systems in a single state were disrupted in one coordinated push. CISA states that entities of every size are being targeted, including utilities with mature security programs. The Environmental Protection Agency and the FBI contributed to the alert.

Are you exposed?

  • Can you reach any part of your plant control system from home, from your phone, or from a hotel? If you can, so can someone else. That includes your vendor’s remote support connection.
  • Is there a cellular modem anywhere on the plant floor? CISA calls these out specifically, because they are frequently installed by an operator, a vendor or a system integrator and never documented. A modem nobody wrote down will not appear in any inventory or scan you have run.
  • If your controllers went dark right now, could your crew run the plant manually, and has anyone actually practiced it recently?

Three actions this week

  1. Find what is reachable. Walk the plant. Inventory every device with a cellular antenna, a network cable heading somewhere outside the control network, or a vendor support connection. Ask your integrator directly what they installed and how they connect to it. This is a walk-around, not a software project.
  2. Take controllers off the internet. CISA’s guidance is to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. Where remote access is operationally necessary, it belongs behind a VPN with multifactor authentication, never exposed directly. Change default and shared passwords while you are in there.
  3. Get a free outside look. CISA runs a no-cost vulnerability scanning service for water utilities that shows what your systems look like from the internet, with weekly reports. The EPA runs a 24/7 water cybersecurity help desk that responds within two days and offers no-cost assessments. Neither costs anything, and neither requires you to have security staff.

If your control network is genuinely isolated, has no cellular modems and carries no vendor remote access, your urgency drops from this week to your next maintenance window. In our experience, most small utilities discover during step one that at least one of those three assumptions is wrong. That discovery is the entire point of doing it.

Sources: CISA alert, 30 July 2026, and CISA’s water sector resource page at cisa.gov/water. Assessment ours. Questions about your specific plant: info@sentdyne.com — no charge for a five-minute sanity check.