Responding to CISA's Latest ICS Cybersecurity Advisory: What Industrial Facilities Should Do Next
CISA's latest cybersecurity advisory highlights the growing threat to industrial control systems. Learn the recommended actions to secure PLCs, protect OT networks, strengthen remote access, and improve the cybersecurity resilience of your manufacturing operations.
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued Cybersecurity Advisory AA26-097A, warning of active cyber threats targeting Industrial Control Systems (ICS) used in water, wastewater, and other critical infrastructure sectors.
While the advisory specifically highlights municipal utilities, the recommended actions apply to manufacturers, OEMs, system integrators, and any organization operating industrial automation systems.
If your PLCs, industrial networks, or remote access infrastructure have not been reviewed recently, now is the time to assess your environment and strengthen your cybersecurity posture.
Why This Advisory Matters
Industrial control systems are increasingly connected, making them more efficient—but also more attractive targets for cyberattacks.
Exposed PLCs, unsecured remote access, and aging control systems can create vulnerabilities that impact:
- Production uptime
- Worker safety
- Equipment reliability
- Regulatory compliance
- Business continuity
Taking proactive steps now can significantly reduce operational and cybersecurity risks.
Immediate Actions Recommended by CISA
CISA recommends that industrial asset owners take the following actions as soon as possible.
Remove PLCs from Direct Internet Exposure
PLCs should never be directly accessible from the public internet.
Protect control systems by implementing:
- Firewalls
- Secure gateways
- Network segmentation
- Secure remote access solutions
Proper segmentation limits exposure and reduces the attack surface available to threat actors.
Review Logs for Indicators of Compromise
Review available system and security logs for indicators of compromise (IOCs) referenced in the CISA advisory.
Monitoring historical activity may help identify unauthorized access before it impacts production.
Monitor Industrial Network Traffic
Pay close attention to unexpected or unauthorized traffic on common industrial communication ports, including:
- 44818 (EtherNet/IP)
- 2222
- 102
- 502 (Modbus)
Traffic originating from unfamiliar or overseas hosting providers should be investigated immediately.
Secure Rockwell Automation Controllers
For Rockwell Automation PLCs, verify that the physical mode switch is set to RUN whenever programming changes are not actively being performed.
This simple step helps prevent unauthorized logic modifications.
How ES&E Can Help Secure Remote Access
Many industrial facilities have accumulated remote access methods over the years that may no longer meet today's cybersecurity expectations.
ES&E can help you:
- Identify insecure remote connections
- Implement secure remote access solutions
- Reduce cyber risk without disrupting operations
Modernize Aging Control Systems
Legacy automation equipment often introduces both operational and cybersecurity challenges.
Our specialists can:
- Evaluate your installed base
- Identify unsupported or aging components
- Develop a phased modernization roadmap that minimizes downtime and fits your budget
Improve OT Visibility
You can't protect what you can't see.
ES&E can help you gain better visibility into your operational technology (OT) environment by:
- Identifying connected assets
- Prioritizing cybersecurity risks
- Improving network segmentation
- Building a long-term cybersecurity strategy aligned with industry best practices
Best Practices for Improving Industrial Cybersecurity
While every facility is different, these best practices can significantly strengthen your cybersecurity posture:
- Remove internet-facing industrial devices
- Implement secure remote access
- Segment IT and OT networks
- Regularly back up PLC programs and configurations
- Monitor controller changes and network activity
- Keep firmware and software up to date
- Conduct periodic cybersecurity assessments
- Develop an incident response and disaster recovery plan
Don't Wait for an Incident
Cybersecurity is no longer just an IT concern—it's an operational priority.
Whether you're looking to improve network security, modernize aging infrastructure, or assess your overall cybersecurity posture, ES&E can help you take practical steps to protect your people, production, and critical assets.
Contact ES&E today to schedule a cybersecurity assessment and begin building a more resilient industrial automation environment.
Additional Resource
For additional guidance and recommendations, download the Rockwell Automation Critical Infrastructure Resource Guide to learn more about protecting industrial control systems from evolving cyber threats.