Ready to upgrade your infrastructure?
586-765-0770
When most people imagine a cyberattack against critical infrastructure, they picture sophisticated malware, highly trained hackers and a complex operation unfolding inside a dark room.
The actual entry point may be far less dramatic.
It could be a programmable logic controller connected directly to the public internet.
It could be a cellular gateway installed years ago and never properly documented.
It could be a default password that was supposed to be changed after commissioning—but never was.
It could be an engineering workstation with more remote-access privileges than anyone realized.
For municipal water departments, wastewater treatment plants, manufacturing facilities, utilities and commercial building operators, these are not theoretical concerns. They are field-level infrastructure problems that can create real operational consequences.
On July 22, 2026, the Cybersecurity and Infrastructure Security Agency, FBI, Environmental Protection Agency and other government partners updated a joint advisory warning that Iranian-affiliated actors were continuing to target internet-connected operational technology, including programmable logic controllers across U.S. critical infrastructure. The updated guidance added newly observed PLC targeting, detection information and additional mitigations.
The message for operators is clear:
An undocumented or unnecessarily exposed PLC is no longer just a network-maintenance issue. It is an immediate operational risk.
What Is Happening to Internet-Connected PLCs?
PLCs help control physical processes. They can operate pumps, valves, motors, blowers, chemical-feed systems, production equipment, HVAC systems and other essential machinery.
That makes them extremely useful—and extremely consequential.
According to the federal advisory, Iran-affiliated threat actors have targeted internet-facing operational technology and interacted maliciously with PLC project files. Reported activity has included manipulating information displayed through human-machine interfaces and SCADA systems. Some affected organizations experienced operational disruption and financial loss.
This activity has affected multiple critical-infrastructure sectors, including:
Water and wastewater systems
Energy operations
Government services and facilities
Industrial and manufacturing environments
Other facilities using remotely accessible control systems
For owners and operators, the most important point is not the name or nationality of the threat actor.
The important point is that attackers are actively looking for reachable, poorly protected industrial devices—and they do not necessarily need an exotic zero-day vulnerability to create problems.
The Primary Weakness Is Often Architecture, Not Advanced Malware
Many PLC and SCADA security problems begin with basic infrastructure decisions.
A device was temporarily connected to the internet for vendor support and remained connected.
A remote pump station was installed using the fastest available cellular solution, but no one documented the public-facing address.
A radio, router or gateway is still running outdated firmware.
Multiple technicians share one administrator login.
An engineering workstation can connect directly to both the corporate network and the OT environment.
A flat network allows unnecessary communication between operational systems.
These weaknesses may not sound as dramatic as “nation-state malware,” but they can create the access path an attacker needs.
EPA guidance urges water systems to reduce exposure to the public-facing internet, conduct cybersecurity assessments, inventory operational technology and information technology assets, change default passwords, maintain backups and reduce exposure to known vulnerabilities.
The practical lesson is straightforward:
Before purchasing another security platform, operators should know exactly what equipment is installed, how it communicates, who can access it and whether it can be reached from outside the organization.
Remote Sites Can Become the Biggest Blind Spot
The main treatment plant or production facility may have managed firewalls, monitored switches, controlled access and documented network diagrams.
Remote facilities are often a different story.
Consider the number of field locations that may connect to a municipal or industrial SCADA system:
Wells and pump stations
Lift stations
Water towers and storage facilities
Chemical-feed locations
Remote metering equipment
Electrical substations
Tank monitoring systems
Building automation panels
Warehouse and production-line controls
Environmental monitoring sites
Each location may contain some combination of PLCs, SCADA radios, antennas, routers, cellular gateways, industrial Ethernet switches, power supplies, fiber converters and field enclosures.
Over time, equipment may be replaced by different contractors. Temporary connections may become permanent. Documentation may fall behind actual field conditions.
Eventually, the organization may have no single, reliable inventory showing:
What is installed
Where it is installed
Which firmware version it uses
How it communicates
Whether it is internet-accessible
Which vendor or employee accounts can reach it
Whether a backup communications path exists
That is precisely why a field-level SCADA exposure review is so important.
What a SCADA Remote-Site Exposure Review Should Cover
A useful assessment should go beyond a generic vulnerability scan. It should connect cybersecurity findings with the physical communications infrastructure operating at each location.
A fixed-scope SCADA Remote-Site Exposure Review should address the following areas.
1. Field Device Inventory
Document the operational and communications equipment at every selected location, including:
PLC manufacturer and model
HMI equipment
SCADA and telemetry radios
Cellular routers and gateways
Industrial Ethernet switches
Fiber-optic equipment
Antennas and wireless bridges
Engineering workstations
Remote-access appliances
Power supplies, batteries and UPS equipment
Asset inventories should also include firmware versions, serial numbers, network addresses and equipment-support status when available.
2. Public Internet Exposure
Determine whether PLCs, HMIs, routers, gateways or management interfaces are directly accessible from the public internet.
Remote access should not be confused with unrestricted internet exposure. Operators may need remote connectivity, but that access should be intentionally designed, authenticated, monitored and limited to authorized systems.
3. VPN and Remote-Administration Controls
Review how employees, vendors and service providers reach the environment.
Questions should include:
Is remote access routed through a managed VPN?
Is multifactor authentication enabled?
Does each person have a unique account?
Are former employees and vendors removed promptly?
Are remote sessions logged?
Can vendor accounts reach more systems than necessary?
Is remote access disabled when it is not required?
4. Network Segmentation
A compromised office computer should not have an unrestricted path to a pump controller or production PLC.
Segmentation can help separate business systems, engineering workstations, SCADA servers and field devices. It can also limit which systems are permitted to communicate across the IT and OT boundary.
Network segmentation does not eliminate every threat, but it can substantially reduce unnecessary access pathways.
5. Firmware and Lifecycle Condition
Older field devices may remain operational for many years, even after manufacturer support or security updates become limited.
An exposure review should identify:
Outdated firmware
Unsupported hardware
Unnecessary services and ports
Default configurations
Devices without secure-management capabilities
Equipment that should be upgraded or replaced
6. Communications Resilience
Cybersecurity and operational resilience are closely connected.
A secure connection that fails whenever a carrier goes down, an antenna is damaged or a fiber strand is cut still creates operational risk.
Remote-site planning should consider:
Primary and backup communications paths
Fiber and wireless redundancy
Cellular carrier diversity
Antenna condition and alignment
Environmental enclosure condition
Battery and backup-power capacity
Failover procedures
Manual operating procedures
The objective is not only to keep unauthorized users out. It is also to keep authorized operators connected when conditions are at their worst.
Finding the Exposure Is Only Half the Job
A cybersecurity consultant may identify an exposed IP address, an unsupported device or an improperly segmented network.
But identifying the problem does not automatically correct the field infrastructure.
Someone still has to:
Replace or reconfigure the cellular gateway
Install the firewall or managed industrial switch
Repair or replace the antenna system
Build the fiber connection
Correct the enclosure and power deficiencies
Remove an unnecessary communications path
Create a redundant radio or network link
Label and document the equipment
Coordinate testing without disrupting operations
That is where the distinction between a report and a resolution becomes important.
Trendset Communications Group helps organizations connect the assessment to the physical correction.
TCG provides structured cabling, fiber-optic infrastructure, wireless networking, SCADA and control-system connectivity, network infrastructure and ongoing service for municipal, utility, industrial and commercial environments. As a Michigan-based, WBE-certified systems integrator, TCG supports organizations that need both technical accountability and field-level execution.
Instead of handing an operator a list of findings and walking away, TCG can help develop a practical remediation path for the communications infrastructure carrying critical OT and SCADA traffic.
Seven Questions Every Operator Should Ask Today
Municipal and industrial leaders do not need to wait for a security incident to begin reducing exposure.
Start by asking:
Do we have a current inventory of every PLC, HMI, radio, router, switch and cellular gateway?
Can any operational device or management interface be reached directly from the public internet?
Are any systems still using factory-default or shared credentials?
Is remote access protected by a VPN, multifactor authentication and individual user accounts?
Are our business, engineering and operational networks properly segmented?
Do we know which devices are running outdated or unsupported firmware?
Can our operators maintain visibility and control if the primary communications connection fails?
An uncertain answer does not automatically mean the system has been compromised.
It does mean the organization has a visibility gap that should be addressed.
From Uncertainty to a Prioritized Remediation Plan
A SCADA Remote-Site Exposure Review can help an organization move from assumptions to documented facts.
A properly scoped review can provide:
A field-verified device inventory
Identification of potentially exposed equipment
Documentation of remote-access methods
Review of network-segmentation conditions
Identification of aging or unsupported infrastructure
Communications-path and redundancy findings
Site photographs and equipment records
A prioritized corrective-action plan
Budgetary guidance for remediation projects
Recommendations for ongoing inspection and maintenance
The goal is not to create fear.
The goal is to give operators a manageable list of actions that can reduce risk without unnecessarily disrupting production, treatment or public services.
Michigan Water, Wastewater and Industrial Operators: Take the First Step
The July 22 advisory is a credible reason to review PLC and SCADA exposure now—not during the next outage, audit or emergency response.
Trendset Communications Group is offering a fixed-scope SCADA Remote-Site Exposure Review for municipal water departments, wastewater facilities, utilities, manufacturers and building operators.
TCG can help your organization document the field environment, identify communications-infrastructure weaknesses and develop a practical path for correcting exposed or unreliable remote connections.
Schedule a SCADA Remote-Site Exposure Review
Call 586-765-0770 to speak with a TCG infrastructure specialist.
Whether the issue involves a PLC connection, SCADA radio, cellular gateway, fiber route, industrial switch, antenna system or remote enclosure, TCG can help turn an identified risk into a field-ready solution.
Do not wait for an unfamiliar login, unexplained PLC change or failed remote connection to reveal what your organization does not know.
Find the exposure. Document the infrastructure. Prioritize the correction.
Frequently Asked Questions
What is PLC security?
PLC security is the process of protecting programmable logic controllers from unauthorized access, configuration changes, malicious project files and communications disruptions. It includes credential management, network segmentation, secure remote access, firmware maintenance, monitoring and physical infrastructure protection.
Why are internet-connected PLCs dangerous?
A PLC that is directly exposed to the public internet may be discoverable and accessible to unauthorized users. Weak passwords, open management ports, outdated firmware and poor access controls can increase the likelihood of manipulation or disruption.
How can a water utility improve SCADA cybersecurity?
Water utilities should begin with an accurate inventory of PLCs, HMIs, radios, routers, cellular gateways and engineering workstations. They should reduce public internet exposure, change default credentials, strengthen remote access, segment IT and OT networks, maintain backups and monitor remote activity. EPA recommends these and other basic cybersecurity actions for water systems.
What is a SCADA Remote-Site Exposure Review?
A SCADA Remote-Site Exposure Review is a field-focused assessment of the devices, network connections, remote-access methods and communications infrastructure supporting remote operational locations. The review identifies exposure, documentation gaps, aging equipment, segmentation concerns and communications-resiliency issues.
Does network segmentation prevent every PLC cyberattack?
No single control prevents every attack. Network segmentation can, however, reduce unnecessary connectivity and make it more difficult for an attacker to move from a business network, remote workstation or compromised device into critical operational systems.
Who should conduct a PLC and SCADA infrastructure review?
The review should involve operations personnel, IT and cybersecurity staff, control-system specialists and a qualified communications-infrastructure integrator. This combination helps ensure that both digital risks and physical field conditions are addressed.
Ready to talk to a Michigan communications expert?
Get a Free Estimate