CISA, FBI, and International Partners Release Guidance on Effective Communication During Service Outages

The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, released joint guidance Communicating Under Pressure: Best Practices for Service Providers to help organizations plan to communicate clearly and effectively during service outages impacting IT and operational technology (OT) systems.
Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing the uncertainty and potential for panic. This guidance describes how service providers can prepare and execute clear, timely, and audience-appropriate messaging that articulates accurate information while still aligning with operational security, law enforcement, and containment efforts.
Key actions for communicating during service outages:
• Lead with confirmed facts, scope, and affected systems
• Tailor updates to each audience
• State what is known, unknown, and under investigation
• Explain operational impact and any customer actions
• Avoid vague language, speculation, and public relations “spin”
• Provide frequent, time-stamped updates
• Align messaging with legal, regulatory, and law enforcement requirements
CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover their vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.

Nepal Landslide Triggers Catastrophic Flash Flood on Tibet Border

Nepal flood (library pic)

A catastrophic flash flood has struck Nepal’s northern Rasuwa district after a massive landslide and glacial collapse in the Himalayas triggered a devastating surge of water, ice and debris through valleys along the Nepal–Tibet border.

The disaster on 26 August swept through communities and infrastructure near the Bhote Koshi River, destroying homes, roads, bridges and other critical infrastructure. The impact has extended into neighbouring Tibet, including the strategically important Gyirong border area.

The US Geological Survey has determined that seismic activity initially thought to indicate an earthquake was instead generated by the collapse of a glacier and associated landslide/debris flow. Satellite analysis indicates that a large mass of ice and rock descended thousands of metres, generating an exceptionally powerful and rapid flood.

The human cost remains uncertain, with at least 160–180 deaths reported across Nepal and Tibet and more than 1,000 people potentially missing. Among those unaccounted for are foreign tourists, pilgrims, local residents, police officers and workers at infrastructure projects.

Rescue operations have been severely complicated by damaged roads and bridges, disrupted communications and power supplies, and difficult mountainous terrain. Authorities are also monitoring rivers for the possibility of further flooding caused by unstable debris blockages.

For the security and resilience community, the disaster highlights the vulnerability of critical infrastructure and transport corridors to cascading natural hazards, particularly in mountainous regions where climate-driven glacial instability can create rapid, low-warning threats to communities, energy infrastructure and cross-border connectivity.

CISA Issues Internet Exposure Reduction Guidance

Many organizations unknowingly leave common vulnerabilities and weaknesses exposed to the internet, making them easy targets for exploitation. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software that they can exploit to gain unauthorized access. By following the guidance below, organizations can proactively identify internet exposures, remove those that are unnecessary, and secure those that are necessary, strengthening their cybersecurity posture.
The range and number of internet-accessible assets—including industrial internet of things (IIoT), supervisory control and data acquisition systems (SCADA), industrial control systems (ICS), and remote access technologies—continues to grow. In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem. Directly connecting PLCs to the internet through cellular modems can create significant security risks. However, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary.
Steps to Reduce Internet Exposure
1. Assess Your Current Exposure. Begin by identifying which of your assets are accessible via the internet. Utilize tools and services (e.g., CISA’s Cyber Hygiene Vulnerability Scanning service as well as the Web-Based Tools for Identifying Internet-Exposed IT and OT Assets below) that can scan for publicly exposed systems to gain visibility into your organization's online footprint.
a. Determine whether integrators, managed security services providers (MSSPs), vendors, or other third parties have remote access to your systems or networks. This access may include VPN credentials, cellular modems, or other remote access technologies.
b. Verify your third-party connections. Demand the external internet protocol (IP) addresses of anything set up by the integrator as well as updates if those IP addresses change. Use the web-based tools (described below) to verify that the integrator is securing those connections.
2. Evaluate Your Necessity of Exposure. Determine which assets need to be internet-accessible for operational purposes. For those that do not need to be internet accessible, implement measures to remove or restrict access.
3. Mitigate Risks to Remaining Exposed Assets. Follow these steps to protect any assets that must remain internet-accessible:
a. Change default passwords.
b. Ensure systems are up to date with the latest security patches.
 i. Replace software and devices that are no longer receiving security support.
c. Use a jump host to provide secure, monitored access.
d. Monitor ingress and egress traffic to identify anomalous activity that requires further investigation.
e. Implement and enforce multifactor authentication (MFA) where possible, even if only at the jump host level.
f. Review the considerations in the Secure Remote Access to OT Environments section below.
4. Establish Routine Assessments. Regularly review and monitor your internet-accessible assets. As your organization's IT and OT environments evolve, continuous assessments help maintain a secure posture and quickly identify new exposures.
Secure Remote Access to OT Environments
CISA urges all critical infrastructure organizations to route all necessary remote access through a secure gateway, firewall, VPN, or other centrally managed access solution, rather than connecting directly to a PLC, human-machine interface (HMI), or remote terminal unit (RTU).
Additionally, organizations should require unique usernames, strong passwords, and phishing-resistant MFA for all remote access. Authentication controls should withstand brute-force attempts and other credential-based targeting.
The July 2026 malicious cyber activity targeting WWS Sector entities demonstrates the consequences of directly exposing PLCs to the internet. Threat actors remotely accessed internet-exposed PLCs, changed device IP addresses and passwords, and caused loss of monitoring and control functionality and, in some cases, operational disruptions.
For more information on securing remote access to OT environments, see the joint guidance, Secure Connectivity Principles for Operational Technology (OT).
Web-Based Tools for Identifying Internet-Exposed IT and OT Assets
In addition to securing remote access, entities should routinely use web-based exposure discovery tools to identify internet-exposed IT and OT assets associated with their organization. Entities should use these tools to search for both known organizational IP space and any assets that the entity could possibly be improperly exposing under vendor, contractor, or legacy infrastructure.
Many web-based exposure discovery tools offer unique capabilities for assessing and indexing IP addresses, parsing transport layer security (TLS) certificates, and tracking domains to provide a comprehensive view of an organization's internet attack surface. Examples include: Shodan, Censys, Thingful, and Shadowserver.
These web-based tools support attack surface reduction activities by providing visibility into various internet-exposed assets. They integrate with vulnerability tools, logging aggregators, and other scanning systems, which facilitates their incorporation into an entity’s infrastructure.
Note: The inclusion of these tools in this guidance does not imply endorsement by CISA or the U.S. government.
Organizations should routinely scan their public IP address ranges to identify ports and services that are accessible from the internet. Investigate any unexpected open ports and determine whether the associated system or service requires internet access. Close or restrict access to ports that do not have a documented operational need.

Defending Against an Active Threat to Siemens S7 Series PLCs

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.
The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.
The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:
- are properly protected with all applicable security patches and updates,
- are isolated from the Internet wherever possible,
- have strong access controls, and
- employ security tooling to monitor ICS environments for anomalous or malicious activity.
These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.
Technical details
Note: This advisory uses the MITRE ATT&CK® Matrix for ICS1 framework, version 19, and the MITRE ATT&CK Matrix for Enterprise framework, version 19. This advisory also uses MITRE D3FENDTM, version 1.5.0. See Appendix A and Appendix B for tables of the activity mapped to MITRE ATT&CK and MITRE D3FEND tactics, techniques, and countermeasures.
Threat actor targeting
Threat actors are actively targeting the following Siemens PLC models:
- S7-200 Series (all CPU variants)
- S7-300 Series (all CPU variants including 314, 315, 317 models)
- S7-400 Series (all CPU variants)
- S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)
- S7-1500 Series (all CPU variants, including F-series safety controllers)
Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.
Note: Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.
Threat actors are leveraging open source industrial automation libraries—specifically snap7.dll/python-snap7—combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol.
Threat actor techniques
Threat actors are:
- Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [T1596.005]
- Rapidly iterating exploit code through AI-assisted development, lowering technical barriers to ICS attacks [T1587.004, T1588.007]
- Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication [T1694]
- Deploying AI-generated Python scripts that incorporate the snap7.dll library from public repositories [T0834] to gain read/write access to the PLC and mimic legitimate tools
- Masquerading malicious scripts as legitimate monitoring tools to evade detection by security teams [T0849]
- Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [T0893, T0821]
The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts.
Potential operational impacts
The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Additionally, Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), and could be targeted there as well. Unauthorized access to PLCs could result in:
- Disruption of critical industrial processes affecting production throughput, product quality, and public services
- Safety incidents affecting personnel through manipulation of safety interlocks, emergency shutdown systems, or process parameters
- Equipment damage and extended operational downtime from process upsets, improper sequencing, or forced equipment operation outside design parameters
- Compromise of sensitive operational data, including proprietary process recipes, control strategies, and facility configurations
- Cascading impacts across interconnected systems affecting supply chains, dependent facilities, and integrated business operations
- Regulatory compliance violations and potential liability from process safety management failures
Mitigation actions
Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs.
Detection opportunities
Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [D3-PM]:
- Anomalous S7comm behavior: Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows
- Reconnaissance indicators: Sequential IP scanning on port 102, repeated connection attempts with varying parameters, or enumeration of CPU properties
- Tool artifacts: Snap7.dll library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations
- Temporal anomalies: S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets
- Geographic anomalies: Connections originating from unexpected countries or IP ranges not associated with vendors or integrators
Preventative hardening actions
To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance Primary Mitigations to Reduce Cyber Threats to Operational Technology.

Algorithmic Amplification Is Now a Critical Infrastructure Risk

Critical infrastructure incidents no longer unfold only across physical assets and cyber systems. They also unfold in an infospace shaped by digital platforms whose algorithms favour speed, emotional intensity, and visibility over verification. For operators, this means that rumour, distortion, and misleading narratives can become part of the incident environment before the first official statement is issued. That is no longer just a communications issue. It is a resilience issue.

The problem is not limited to deliberate disinformation campaigns by hostile actors. A significant part of the risk arises from the normal operation of large social media platforms. During an outage, transport failure, communications disruption, or industrial accident, there is almost always an early information vacuum. Official facts are incomplete, technical assessments are still underway, and restoration timelines remain uncertain. Into that gap flows the content platforms are most likely to amplify. In practice, that often means the most dramatic, emotionally charged, or speculative interpretation of events.

The consequences are operational, not merely reputational.

First, algorithmically amplified misinformation can distort public behaviour. False or exaggerated claims about the scale of an incident, the existence of secondary hazards, or the reliability of official updates can influence how people respond in real time. In an infrastructure emergency, resilience depends partly on public cooperation: passengers need clear guidance, consumers may need to reduce demand, and affected communities need to know which channels to trust. Confusion in the information environment weakens that cooperation.

Second, it can place additional strain on response systems. When misleading narratives spread quickly, emergency services, customer contact centres, and public authorities may face surges of enquiries, complaints, or panic-driven reactions that do not correspond to the technical reality of the event. This diverts attention and capacity at precisely the moment when disciplined prioritisation matters most.

Third, it can damage trust in ways that outlast the incident itself. Even where restoration is technically successful, the dominant online narrative may frame the event as evidence of incompetence, secrecy, or negligence. Once that framing becomes established, later incidents become harder to manage because the baseline level of trust has already been weakened.

For this reason, critical infrastructure operators should stop treating the infospace as a downstream issue to be handled only after the technical response is underway. In the platform age, the narrative environment develops in parallel with the operational incident, and often faster than formal communication processes can respond. The information dimension therefore needs to be built into resilience planning in advance.

Three practical steps would make a real difference.

The first is to treat narrative monitoring as part of situational awareness during significant incidents. Operators already monitor technical status, cyber indicators, and service impacts. They should also have a structured way to assess what claims are circulating online, which narratives are gaining traction, and whether those narratives are affecting behaviour. While this is established practice in advanced crisis communication teams, it remains rare in CIP incident management structures — and that gap needs to close.

The second is to invest in trusted communication channels and pre-prepared messaging frameworks before a crisis occurs. Credibility cannot be improvised in the middle of a major outage. Organisations that have already established visible, consistent, and recognisable public channels — whether through direct social media presence, relationships with local authorities, or pre-agreed communication protocols with emergency services — are in a much stronger position to reach the public quickly with accurate information when it matters. Equally important is preparing draft holding lines and narrative frameworks for the most foreseeable incident types: a grid outage, a transport disruption, a communications failure. When the information vacuum opens, the difference between responding in minutes and responding in hours is often the difference between shaping the narrative and chasing it.

The third is to update crisis training and exercises. Tabletop exercises should not simulate only the technical disruption. They should also simulate the platform dynamics surrounding it: rumour cascades, miscaptioned images, false attributions of cause, and competing unofficial narratives. That is now part of the real operating environment, and preparedness should reflect it.

Critical infrastructure protection has always required attention to the wider conditions that shape disruption. Today, one of those conditions is the infospace. Algorithmic amplification is not an abstract media issue or a secondary public relations concern. It is part of the environment in which incidents are interpreted, escalated, and managed. Resilience planning should reflect that reality.

Antonio Scala is a physicist and Research Director at CNR-ISC. His research focuses on complex networks, information dynamics, and critical infrastructure resilience.

OSCE expands access to its technical guidance on the physical security of critical infrastructure

The OSCE Centre in Ashgabat and the OSCE Transnational Threats Department launched the Turkmen version of their Technical Guide on Physical Security Considerations for Protecting Critical Infrastructure from Terrorist Attacks. The launch event was accompanied by a training course on enhancing the physical security of critical infrastructure from terrorist attacks, using the Technical Guide as a training aid.
Developed under the OSCE’s Project PROTECT with support from Germany and the United States of America, the Technical Guide provides practical guidance to policymakers, critical infrastructure owners and operators, and security practitioners on enhancing the protection of critical infrastructure sites from terrorist attacks. The publication consolidates publicly available practices and examples from across the OSCE area and is designed to support stakeholders in developing security measures tailored to their specific risk environment. It was released in November 2025 in the English and Russian. The launch of the Turkmen language version of this Guide, initiated by the OSCE Centre in Ashgabat, is a testament to the Guide's growing value in OSCE participating States.
A representative of the Ministry of Internal Affairs of Turkmenistan presented the country's approach to protecting critical infrastructure, highlighting current practices, the national legislative framework and ongoing efforts to strengthen the security and resilience of critical infrastructure.
The training course brought together government officials responsible for critical infrastructure protection to strengthen their understanding of physical security principles and practices. Participants examined approaches to security system design as well as technical measures including perimeter protection, intrusion detection systems, security lighting, video surveillance, access control and security screening. During the event, participants explored practical ways to apply the Guide’s principles through security assessments, emergency planning, business continuity measures and training exercises.
“The Organization for Security and Co-operation in Europe serves as a vital pillar in global counter-terrorism efforts by actively strengthening the resilience and protection of critical infrastructure across its 57 participating States. Bearing in mind that security is not a task for a single agency or nation, we designed this training programme to build our collective resilience. It is our firm belief that this programme, together with the Guide, will strengthen inter-agency communication and help upgrade security protocols to more effectively protect critical infrastructure from terrorist attacks,” said William Leaf, Head of the OSCE Centre in Ashgabat.
The event featured contributions from international experts and practitioners, as well as the Government of Kazakhstan, another key stakeholder in the OSCE’s Project PROTECT. A representative of the Anti-Terrorism Centre of the Committee of National Security of the Republic of Kazakhstan delivered a presentation on the country's approach to protecting critical infrastructure from terrorist threats.
The event forms part of the OSCE Centre in Ashgabat's project Building Capacity of Law Enforcement and Security Officials of Turkmenistan in Countering Transnational Threats Related to Organized Crime and Terrorism – 2026 and the OSCE's extrabudgetary Project PROTECT, which supports participating States in strengthening national approaches to protecting vulnerable targets from terrorist threats and other hazards.

INTERPOL report finds AI linked to more than half of cybercrime in Africa

Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026.

With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly.

However, cybercrime legislation is fragmented and AI readiness in law enforcement agencies remains alarmingly low.

The 40-page report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem.

East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware.

Business email compromise and romance scams targeting both corporate and individual victims were prolific in Central and West Africa.

Southern Africa’s ultra-high connectivity makes it a magnet for global threat actors seeking maximum disruption.

The financial toll of cybercrime in Africa is significant.

Since 2024, cybercrime-related losses have more than doubled, from USD 192 million to USD 484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.

According to the report, in 2025, online scams continued to be the most reported type of cybercrime, with attackers leveraging mobile money platforms, social media and AI to reach their targets.

Notably, 72 per cent of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa.

AI-enabled cyberthreats
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, remained pervasive, with some 600,000 sextortion detections recorded by TrendAI, one of several partners working with INTERPOL.

Similarly, the sophistication of Business E-Mail Compromise (BEC) schemes increased dramatically, with AI used to generate highly convincing e-mail correspondence, with Africa-based threat actors targeting victims in Europe and North America using infrastructure located across multiple jurisdictions.

The report reveals that the absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud.

This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities.

Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.

Neal Jetton, Director of INTERPOL’s Cybercrime unit said, “Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.

“However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled.”

Meaningful transnational progress is visible. In 2025, 17 countries enacted or amended cybercrime legislation, including the launch of an online reporting platform in Senegal aimed at enhancing the response to online violations affecting children.

At the same time, regionally coordinated capacity building initiatives continue to strengthen long-term cyber resilience.

Operational cooperation is also delivering noteworthy results.

Four high impact cybercrime operations coordinated by INTERPOL including Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel and Operation Red Card 2.0 collectively led to more than 1,500 arrests, the seizure of hundreds of devices and the recovery of over USD 100 million.

In its recommendations, the report calls for standardized digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal-public private partnership to support effective prevention, detection and response.

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.

These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.

CISA recommends organizations implement the following mitigations:

- Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.

After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity.

To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:

- CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology
- United Kingdom's National Cyber Security Center: Secure Connectivity Principles for Operational Technology
- Federal Bureau of Investigation (FBI): Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions

For additional support, contact the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for the Water Sector.

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) released an updated joint Cybersecurity Advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.

This update re-emphasizes the ongoing threat from Iranian-affiliated advanced persistent threat (APT) actors targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other brands/manufacturers. These attacks have resulted in operational disruptions and financial losses across multiple U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy.

What’s New in This Update:

• Expanded Targeting: The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, in addition to Rockwell Automation/Allen-Bradley and potentially other branded/manufacturer devices.
• Updated Technical Details: New information on threat actor tactics, including use of configuration software to exfiltrate device project files, and expanded details on targeted ports and device models.
• Enhanced Mitigations: Additional recommendations for securing cellular modems, implementing isolated architectures, validating project files, and detecting malicious changes in reusable code modules (such as Add-On Instructions/AOIs).
• New Indicators of Compromise (IOCs): Updated tables of internet protocol (IP) addresses and timeframes associated with Iranian-affiliated APT activity.

Iranian-affiliated APT actors continue to adapt their tactics, targeting a wider range of devices and sectors. Proactive review of this advisory and implementation of the recommended mitigations are critical to defending your organization’s OT assets and ensuring operational resilience.

Detection vs. Deterrence: What Actually Stops Intruders

Across critical infrastructure sectors such as energy, transportation, water, utilities, and other facilities, physical security threats are increasing in frequency and complexity. Assets are more distributed, sites are often remote or unstaffed, and essential operations cannot afford disruptions. Meanwhile, many organizations continue to rely on security frameworks focused primarily on detection rather than prevention.
The common approach is familiar: detect an intrusion, verify the threat, and initiate a response. Cameras, alarms, analytics, and monitoring centers form the backbone of this model, providing visibility into events as they unfold. In many cases, these systems are well-integrated and operationally necessary. However, detection-led security is inherently reactive. It assumes an intrusion attempt will occur and focuses on managing the outcome rather than reducing the likelihood of the event. In environments where response times vary and sites span large geographic areas, even rapid detection is unlikely to prevent loss, damage, or disruption.
This raises a broader strategic question for global infrastructure leaders: Is it enough to recognize when a breach occurs, or should the primary goal be preventing the attempt altogether?
The Structural Imbalance Between Detection and Deterrence 
Detection and deterrence are not competing concepts, but in practice, they are often treated disproportionately. As industry threats evolve and expectations for resilience rise, that imbalance is becoming harder to ignore.
Most physical security strategies are built around detection. According to the Physical Security Market 2025-2030 report, video surveillance systems dominated the global market, accounting for more than 50.5% (Grand View Research). This includes systems that detect activity once it has begun and trigger a response, such as cameras, motion sensors, alarms, and monitoring centers — tools that provide visibility into events as they occur.
• Detection systems answer necessary questions: What is happening? What happened? What response is required? They provide situational awareness to support incident verification and create a record for investigation, compliance, insurance, or operational review. In well-designed environments, they can be integrated into response protocols that guide how teams react once a threat is identified.
• Deterrence systems, by contrast, focus on influencing behavior before an intrusion attempt occurs. These include visible barriers, controlled access points, lighting, active perimeter security, signage, and environmental design that signal a higher level of risk, effort, and consequence to potential intruders.
The critical infrastructure industry continues to prioritize detection over deterrence. The global video surveillance market is projected to grow from $95.1 billion (USD) in 2026 to 261.65 billion (USD) by 2034 (Fortune Business Insights). The issue is not that detection is unnecessary. It is that a detection-first approach can create a security gap when visibility and response are emphasized more heavily than perimeter-based prevention strategies.
The Reality of Infrastructure Intrusions
To develop effective security strategies, it is necessary to understand how most violations take place in practice. While high-profile incidents may be sophisticated or targeted, most security breaches across critical infrastructure are less complex.
Many crimes are opportunistic, driven by theft, vandalism, trespassing, or easy access rather than coordinated attacks. The continued rise in material theft, such as copper, components, and equipment, reflects this pattern. These incidents typically occur where assets are visible, access is predictable, and resistance is low. In this context, intruders tend to follow a straightforward logic: they weigh effort against reward and choose the path of least resistance. Therefore, sites with inconsistent perimeter control, limited deterrents, or predictable operating patterns are more likely to be targeted.
For infrastructure operators, the consequences often extend far beyond the value of the stolen material or damaged asset. A single intrusion can create emergency repairs, downtime, safety concerns, crew diversion, insurance involvement, regulatory scrutiny, and operational disruption. For electric utilities, water providers, transportation operators, and other critical infrastructure organizations, the incident itself is often only the beginning of the cost.
When applied to security design, systems that primarily detect activity after entry can still leave infrastructure exposed. When the environment signals low resistance, the likelihood of an attempt remains high — even if detection capabilities are strong.
Where Detection-First Systems Fall Short
Detection systems identify events effectively, but once someone initiates an intrusion that triggers the system, the damage may already be done, and an unavoidable gap remains. Because these systems depend heavily on post-alarm intervention, monitoring teams — even those with AI — must assess alerts, filter out false alarms, and determine the appropriate response. In the United States alone, 94-98% of police alarm calls are false alarms, costing the public about $1.5 billion per year in police time (U.S. Department of Justice). Over time, delayed escalation or false calls can lead to a lack of response, especially in highly distributed areas.
The operational and financial impacts extend beyond the incident itself. A single breach can cause downtime, safety issues, and regulatory scrutiny, diverting resources and straining teams. From a financial perspective, downstream expenses such as replacements, insurance, and productivity losses tend to rapidly surpass prevention costs.
For many infrastructure sites, the issue is not whether detection works. The issue is whether detection happens early enough, and whether the response can arrive quickly enough, to prevent meaningful loss or damage.
How Deterrence Influences Behavior
A prevention-focused approach shifts the point at which security is activated. It moves the risk outward to the perimeter, where decisions are made and potential threats can be deterred from escalating.
At its core, deterrence operates on perception. Visible security measures create clearly defined boundaries and alter how a potential intruder evaluates risk versus reward. When effort increases and uncertainty rises, the likelihood of an attempt decreases. Essentially, security begins as a psychological barrier before any physical action is taken; it begins in the decision-making process. This premise also aligns with principles in criminology. Individuals seeking opportunity tend to favor environments with lower resistance and higher predictability. When those conditions change, behavior changes with them. In most cases, the outcome is not confrontation but displacement; intruders will move on to less-protected sites.
For critical infrastructure, many assets are located in remote or minimally staffed environments where response times are inherently constrained. In these settings, visible deterrence and clear boundary enforcement must be foundational measures. Physical barriers and well-defined perimeters heighten avoidance instincts and reinforce a simple message: access is controlled, and intrusion carries consequences. When security is designed with human behavior in mind, it reduces the likelihood that unlawful activity progresses in the first place.
The Case for a Layered Security Approach
Detection and deterrence should work together, not compete; relying on only one creates gaps. A more effective approach is organized, multi-layered, and aligned with how intrusions occur and how human behavior responds.
This model organizes security into three functional layers at critical infrastructure sites:
• Outer layer: Deter. Establish visible boundaries through barriers, active perimeter deterrence, lighting, signage, and controlled access gates to discourage intrusion attempts before they begin.
• Middle layer: Delay. Introduce intrusion sensors, lighting, audible alerts, secondary barriers, and other physical obstacles that slow or complicate movement, increasing the time and effort required to proceed.
• Inner layer: Detect and Respond. Use cameras and real-time monitoring systems to identify activity and initiate an appropriate response in the event of a confirmed breach.
In this framework, detection remains essential, but it is no longer the first or only line of defense. Its role is to reinforce a system designed to prevent intrusion, not simply manage it after the fact. For infrastructure operators, the objective is to align these layers with asset value, operational scale, and acceptable risk levels. A well-designed multi-layer approach minimizes perimeter exposure while enhancing response effectiveness and supporting continuity across critical systems.
Operational Considerations for Infrastructure Leaders
For industry leaders, the shift from detection toward layered deterrence is strategic. It requires moving from a reactive posture to proactive risk mitigation, with the objective of reducing exposure before incidents happen. This shift also changes how security effectiveness is evaluated. The focus moves beyond response capability to include prevention, visibility, and resilience across the entire operating environment.
A few questions can help assess whether your current strategies are aligned:
• Are we primarily reacting to incidents, or preventing them?
• How visible and defined is our security posture at the perimeter?
• Would a potential intruder view this site as difficult, risky, and time-consuming to enter?
How does our anticipated response time compare to the speed of a typical intrusion?
Are cameras and alarms being used as part of a layered strategy, or are they carrying most of the burden?
What is the full cost of an incident beyond replacement material or repair expense?
• Can the current model scale across distributed assets without creating unnecessary operational complexity?
At the same time, practical constraints remain. Security decisions must balance cost, coverage across distributed assets, and the ability to maintain and scale systems over time. The most effective strategies integrate these considerations without introducing unnecessary complexity or operational burden.
Selecting a partner that can manage all aspects of compliance, risk management, and connectivity for multi-site operations within a layered security strategy can reduce the need to juggle multiple vendors.
The Evolving Threat Landscape and Industry Expectations
The responsibilities assigned to critical infrastructure operators are expanding. Security is no longer evaluated solely on the ability to detect and report incidents, but on the ability to maintain continuity under increasing pressure. Regulatory scrutiny is intensifying, public safety expectations are rising, and insurance and liability considerations are becoming more closely tied to how risk is managed — not just how it is documented.
In response, there is a broader shift toward proactive risk mitigation. Resilience frameworks emphasize reducing exposure and ensuring operational stability rather than relying solely on post-incident reporting. Therefore, a perimeter-first, layered approach is a strategic foundation for addressing risk at the boundary, reducing the likelihood of intrusion, and limiting the need for downstream response. This shift also reflects a closer integration between physical security and operational resilience. Protection strategies are no longer isolated functions; they are part of a connected effort to safeguard uptime, reliability, public safety, and trust across critical systems.
As these expectations evolve, so must the standard for what constitutes effective security. Monitoring alone cannot secure critical infrastructure. The outdated sequence of detect, verify, and respond is no longer sufficient on its own. A more comprehensive model prioritizes deterrence and delay immediately, with detection and response as needed. As a result, success depends not only on how incidents are handled, but more importantly, on how often they can be avoided entirely.
Redefining Effective Security in CIP
Detection answers an important question: “What happened?” Yet deterrence addresses a more consequential one: “How do we reduce the likelihood that it happens in the first place?”
The most effective security strategies recognize this distinction. They prioritize preventing incidents where possible, while maintaining the ability to detect, verify, and respond when necessary. For infrastructure leaders, this requires a shift in how success is defined.
Success should not be measured only by how efficiently incidents are managed after they occur. It should also be measured by how effectively a security posture discourages attempts, delays escalation, reduces preventable losses, and supports operational continuity.
Detection will always matter. But detection alone is not prevention.
As threats evolve and expectations for resilience increase, the strongest critical infrastructure security strategies will be those that move risk outward, strengthen the perimeter, and combine deterrence, delay, detection, and response into a coordinated model designed to prevent more incidents from happening in the first place.
Jonathan Ratledge leads AMAROK’s Critical Infrastructure and Government strategy, helping utilities, public agencies, and infrastructure operators strengthen perimeter security across high-value sites.
1 2 3 64