On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) released Cybersecurity Advisory AA26-097A, warning of active and ongoing cyberattacks targeting Industrial Control Systems (ICS) used in water, wastewater, and other critical infrastructure sectors.
While the advisory highlights municipal utilities, the recommendations apply to any organization operating industrial automation and control systems. If your PLCs or operational technology (OT) environment is internet-exposed or lacks proper network segmentation, now is the time to evaluate your cybersecurity posture.
Industrial control systems continue to be attractive targets for cybercriminals because they directly impact production, safety, and critical services. Facilities with aging infrastructure, unsecured remote access, or limited network visibility face increased risk of unauthorized access and operational disruption.
Taking proactive steps today can help reduce the likelihood of costly downtime, equipment damage, and cybersecurity incidents tomorrow.
CISA recommends asset owners take the following actions as soon as possible to reduce exposure:
PLCs should never be directly accessible from the internet. Protect your control systems by implementing:
Restricting direct access significantly reduces the attack surface available to cyber threats.
Examine available system and security logs for any indicators of compromise (IOCs) identified in the CISA advisory.
Review historical logs during the recommended timeframes to determine whether unauthorized activity may have occurred.
Monitor your OT environment for unexpected or unauthorized communications, especially on common industrial ports, including:
Pay particular attention to traffic originating from unfamiliar or overseas hosting providers.
For Rockwell Automation PLCs, verify that the physical mode switch is set to RUN when no programming changes are being made. This simple step helps prevent unauthorized logic modifications.
Responding to today's threats isn't just about reacting to alerts—it's about building a more resilient industrial network for the future.
Many facilities have accumulated remote access methods over the years that may no longer meet today's cybersecurity standards.
ES&E can help you:
Legacy automation equipment often introduces both operational and cybersecurity challenges, particularly when products are no longer supported.
Our team can:
You can't protect what you can't see.
ES&E helps organizations gain visibility into connected assets, identify vulnerabilities, prioritize remediation efforts, and develop a cybersecurity roadmap aligned with industry best practices and evolving security standards.
Cybersecurity is no longer just an IT responsibility—it's an operational priority.
Whether you're looking to improve remote access security, modernize aging infrastructure, or better understand your OT cybersecurity posture, ES&E can help you develop a practical plan that protects your people, production, and critical assets.
Ready to evaluate your environment? Contact ES&E to schedule a cybersecurity assessment and discuss the next steps for strengthening your industrial control systems.
For more guidance, best practices, and cybersecurity recommendations, explore the Rockwell Automation Critical Infrastructure Resource Guide to help protect your industrial operations against today's evolving cyber threats.