ES&E Focus

CISA Warns of Active Cyber Threats Targeting Industrial Control Systems: What Your Facility Should Do Now

Written by ES&E | Jul 22, 2026 4:15:05 PM

On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) released Cybersecurity Advisory AA26-097A, warning of active and ongoing cyberattacks targeting Industrial Control Systems (ICS) used in water, wastewater, and other critical infrastructure sectors.

 

While the advisory highlights municipal utilities, the recommendations apply to any organization operating industrial automation and control systems. If your PLCs or operational technology (OT) environment is internet-exposed or lacks proper network segmentation, now is the time to evaluate your cybersecurity posture.

 

 

Why This Matters

Industrial control systems continue to be attractive targets for cybercriminals because they directly impact production, safety, and critical services. Facilities with aging infrastructure, unsecured remote access, or limited network visibility face increased risk of unauthorized access and operational disruption.

Taking proactive steps today can help reduce the likelihood of costly downtime, equipment damage, and cybersecurity incidents tomorrow.

 

Immediate Actions Recommended by CISA

CISA recommends asset owners take the following actions as soon as possible to reduce exposure:

 

Remove PLCs from Direct Internet Exposure

PLCs should never be directly accessible from the internet. Protect your control systems by implementing:

  • Firewalls
  • Secure gateways
  • Proper network segmentation
  • Secure remote access solutions

Restricting direct access significantly reduces the attack surface available to cyber threats.

 

Review Logs for Indicators of Compromise

Examine available system and security logs for any indicators of compromise (IOCs) identified in the CISA advisory.

Review historical logs during the recommended timeframes to determine whether unauthorized activity may have occurred.

 

Monitor for Suspicious OT Network Traffic

Monitor your OT environment for unexpected or unauthorized communications, especially on common industrial ports, including:

  • 44818 (EtherNet/IP)
  • 2222
  • 102
  • 502 (Modbus)

Pay particular attention to traffic originating from unfamiliar or overseas hosting providers.

 

Secure Rockwell Automation Controllers

For Rockwell Automation PLCs, verify that the physical mode switch is set to RUN when no programming changes are being made. This simple step helps prevent unauthorized logic modifications.

 

How ES&E Can Help

Responding to today's threats isn't just about reacting to alerts—it's about building a more resilient industrial network for the future.

 

Secure Remote Access

Many facilities have accumulated remote access methods over the years that may no longer meet today's cybersecurity standards.

 

ES&E can help you:

  • Identify unsecured remote connections
  • Implement secure, monitored remote access
  • Reduce unnecessary exposure while maintaining operational support

Reduce Risk from Aging Control Systems

Legacy automation equipment often introduces both operational and cybersecurity challenges, particularly when products are no longer supported.

Our team can:

  • Assess your current control system
  • Identify modernization opportunities
  • Develop a phased upgrade strategy that aligns with your budget and minimizes downtime

Improve Visibility Across Your OT Environment

You can't protect what you can't see.

 

ES&E helps organizations gain visibility into connected assets, identify vulnerabilities, prioritize remediation efforts, and develop a cybersecurity roadmap aligned with industry best practices and evolving security standards.

 

Take Action Before an Incident Occurs

Cybersecurity is no longer just an IT responsibility—it's an operational priority.

 

Whether you're looking to improve remote access security, modernize aging infrastructure, or better understand your OT cybersecurity posture, ES&E can help you develop a practical plan that protects your people, production, and critical assets.

 

Ready to evaluate your environment? Contact ES&E to schedule a cybersecurity assessment and discuss the next steps for strengthening your industrial control systems.

 

Additional Resources

For more guidance, best practices, and cybersecurity recommendations, explore the Rockwell Automation Critical Infrastructure Resource Guide to help protect your industrial operations against today's evolving cyber threats.