Finished intelligence for the people who run the plant.
Free, plain-language OT/ICS security analysis for operators, facility teams, and small defense suppliers. No vendor noise. No fear marketing. Every issue tells you what it is, whether you're exposed, and what to do this week.
TLP:CLEARThe Publications
Advisory Translations
Advisories that actually matter to a five-person utility or shop floor, rewritten in plain English: what it is, whether your SCADA, PLCs, or building controls are exposed, and three actions. Read free below.
Sector Threat Brief
Long-form sector analysis: key judgments, observed tradecraft, and tiered actions. Full briefs, free, no gate. Subscribe to get the next one by email.
Get the Sector Threat Brief
Finished intelligence, not a sales sequence.
Latest — Sector Threat Briefs
Three Weeks In
- The campaign did not stop, it widened. Incidents reported in at least seven states on 30 July have since been reported across at least a dozen.
- Outcomes divide along one line. Utilities that could isolate affected equipment and keep running kept water safe. Utilities that could not issued boil-water notices.
- The structural cause predates the campaign and is officially documented. EPA inspections found more than 70 percent of inspected systems not fully compliant with Safe Drinking Water Act section 1433 requirements.
- A delivery model has arrived. The DEF CON Franklin project, with the National Rural Water Association, will fund free managed detection and response for utilities serving under 10,000 people. If you qualify, take it.
- Free monitoring is real help that does not close the gap. Monitoring designed for IT environments may not register a direct interaction with a controller, and an alert still requires someone with capacity to act on it.
- The 72-hour actions are three weeks past. The 30-day list comes due at the end of August.
Coordinated Cyberattacks on U.S. Water Utilities
- More than thirty Minnesota community water systems were hit on 26–27 July. Utilities in at least seven states reported incidents to the FBI in the days that followed.
- The access vector was the simplest one available: controllers reachable from the internet, many of them through cellular modems and LTE routers.
- The tradecraft was operational lockout rather than theft. Actors changed device addresses and set passwords, cutting operators off from monitoring and, in some cases, from control.
- Outcome severity tracked two things a utility decides in advance: whether its controllers were reachable from the internet, and whether it could actually run in manual mode.
Latest — Advisory Translations
Someone is casing Siemens plant controllers, and their tools are dressed up as the monitoring software you might actually install
What it is
On 19 August, five federal agencies issued a joint advisory on an active threat to Siemens S7 series controllers: the National Security Agency, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Department of Energy, and the Environmental Protection Agency (EPA). The EPA co-signing tells you who this is written for. Water is a primary audience. The advisory names the whole S7 family: from the small S7-200 up through the S7-300, S7-400, S7-1200 and S7-1500, including the F-series safety controllers. If your panels say Siemens, you are in scope.
What the actors are doing, precisely: finding reachable controllers through internet scanning services, and building attack tools disguised as legitimate monitoring software. The agencies say the scripts are AI-generated. The advisory documents read and write access to controller memory, configuration data, and ladder logic. It does not report an outage anywhere. That precision matters in both directions. Nothing has broken, and write access to ladder logic is everything someone needs to break something later, on a schedule they choose.
Coverage is leading with the AI angle. The operational fact is simpler. Siemens has said publicly that this advisory contains no new vulnerabilities and that it has not detected increased attack levels; the techniques exploit known weaknesses and misconfigurations. That is not reassurance, it is the point. The hard part of attacking a controller was never writing the exploit, it was reaching the controller, and reachability is still the thing you control. July’s water campaign was loud: lockouts and boil water notices. This is the quiet version, someone doing homework. The agencies also state plainly that the targeting is wider than Siemens, so if your plant runs Rockwell or Schneider gear, treat this as your advisory too.
Are you exposed?
- Do Siemens controllers run anything in your plant? If you are not sure, the panel schedule or your integrator’s as-built drawings answer it in ten minutes.
- Can anything outside the control network reach a controller on TCP port 102? That is the S7 communication port, and the advisory’s guidance is to block it at the perimeter firewall entirely.
- Where does the engineering laptop live? The computer with TIA Portal or STEP 7 on it is the real prize, because a disguised monitoring tool needs somewhere to land. If that laptop also browses the internet or reads email, that is the gap.
- The three questions from our July translation still govern: any cellular modem nobody wrote down, any vendor remote path, and whether your crew could actually run manual.
Three actions this week
- Inventory the Siemens gear. Model numbers come off the DIN rail or the as-builts. The advisory’s first mitigation is knowing what you have. Note firmware versions while you are at the panel, because that is the patch conversation with your integrator, and Siemens publishes the fix list through its ProductCERT advisories.
- Close port 102 to the outside. Block TCP port 102 at the perimeter, keep controllers off the public internet, and put any necessary remote access behind a VPN with multifactor authentication. Turn on the controller’s own password protection and protection levels while you are in there. They are commonly never switched on.
- Ask one hunting question. If anyone watches your network, a managed service provider, your integrator, county IT, ask them exactly this: any port 102 traffic outside maintenance windows, and any snap7 or unexpected Python on the engineering workstation? Those are the advisory’s own tells. If you find one, that is a call to CISA’s 24/7 line at 1-844-729-2472 or your local FBI field office. If nobody watches your network, CISA’s free scanning service and the EPA’s water help desk from our July translation both still stand, at no cost.
If no Siemens equipment runs your plant, your action is one email asking your integrator what brand does, because the agencies are explicit that this targeting is wider than one vendor. If you run Siemens but nothing is reachable from outside and the engineering laptop never touches the internet, your urgency drops to the next maintenance window for patches and protection levels. Either way, the advisory tells operators to share it with their integrator and ask them to implement the mitigations, so forwarding the link is itself an action. The July walk-around still finds the modem nobody wrote down, and it is still the highest-value hour you can spend.
Attackers are going after exposed plant controllers, and the way in is often something nobody wrote down
What it is
The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on 30 July after a sharp increase in attacks on programmable logic controllers in water and wastewater systems. A programmable logic controller, or PLC, is the small industrial computer that actually runs your pumps, valves and treatment steps.
The attackers are not stealing data. They are changing controller passwords so operators are locked out, and changing controller IP addresses so equipment drops off the network entirely. In the incidents behind this alert, that meant boil water notices and crews running plants by hand.
More than thirty community water systems in a single state were disrupted in one coordinated push. CISA states that entities of every size are being targeted, including utilities with mature security programs. The Environmental Protection Agency and the FBI contributed to the alert.
Are you exposed?
- Can you reach any part of your plant control system from home, from your phone, or from a hotel? If you can, so can someone else. That includes your vendor’s remote support connection.
- Is there a cellular modem anywhere on the plant floor? CISA calls these out specifically, because they are frequently installed by an operator, a vendor or a system integrator and never documented. A modem nobody wrote down will not appear in any inventory or scan you have run.
- If your controllers went dark right now, could your crew run the plant manually, and has anyone actually practiced it recently?
Three actions this week
- Find what is reachable. Walk the plant. Inventory every device with a cellular antenna, a network cable heading somewhere outside the control network, or a vendor support connection. Ask your integrator directly what they installed and how they connect to it. This is a walk-around, not a software project.
- Take controllers off the internet. CISA’s guidance is to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. Where remote access is operationally necessary, it belongs behind a VPN with multifactor authentication, never exposed directly. Change default and shared passwords while you are in there.
- Get a free outside look. CISA runs a no-cost vulnerability scanning service for water utilities that shows what your systems look like from the internet, with weekly reports. The EPA runs a 24/7 water cybersecurity help desk that responds within two days and offers no-cost assessments. Neither costs anything, and neither requires you to have security staff.
If your control network is genuinely isolated, has no cellular modems and carries no vendor remote access, your urgency drops from this week to your next maintenance window. In our experience, most small utilities discover during step one that at least one of those three assumptions is wrong. That discovery is the entire point of doing it.