If you think cyber threats only affect laptops and cloud apps, think again. A new advisory from CISA warns Iranian-affiliated actors are actively targeting internet-connected PLCs in US critical infrastructure. That means your factory floor or building management system could be a target—and that risk isn’t limited to big organizations.
What happened
The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and EPA, published an advisory about Iranian-affiliated cyber actors exploiting internet-connected programmable logic controllers (PLCs) across United States critical infrastructure. The advisory notes ongoing activity and provides mitigations, indicators of compromise, and steps to reduce risk. It also calls on organizations to ensure service providers are informed and aware of active threats.
Why this matters
PLCs control processes in utilities, manufacturing, building management, and other critical sectors. If threat actors can influence PLCs, they can affect safety and operations. For most readers, the takeaway is to ensure your OT/ICS assets are properly segmented from IT networks, monitored, and kept up to date with vendor guidance.
Practical steps you can take
- Audit exposure: Identify PLCs and OT devices that are reachable from IT networks or the internet. Remove or restrict remote access where possible.
- Segmentation and access control: Ensure OT networks are isolated from IT networks; use firewalls and strict access controls for any cross-border traffic.
- Monitor and detect unauthorized changes: Enable logging on PLCs and OT monitoring tools; use vendor integrity checking tools; compare running PLC code against known good baselines.
- Patch and vendor guidance: Check with your PLC and OT vendors for the latest advisories and apply recommended updates or mitigations.
- Coordinate with service providers: If you rely on third-party integrators or MSPs, ensure they are aware of active threats and follow least-privilege practices for remote maintenance.
- Incident response readiness: Have an OT-focused incident response plan, including backups, restoration procedures, and safe restart steps for PLCs.
For a deeper dive, you can read the advisory from CISA and partners here: ICS Advisories on CISA.gov.
Final thought
OT security is everyone’s business. If you manage facilities, plants, or building systems, make PLC security a regular part of your risk assessments. Small steps today can prevent larger disruptions tomorrow.