CISA Issues Internet Exposure Reduction Guidance

Many organizations unknowingly leave common vulnerabilities and weaknesses exposed to the internet, making them easy targets for exploitation. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software that they can exploit to gain unauthorized access. By following the guidance below, organizations can proactively identify internet exposures, remove those that are unnecessary, and secure those that are necessary, strengthening their cybersecurity posture.
The range and number of internet-accessible assets—including industrial internet of things (IIoT), supervisory control and data acquisition systems (SCADA), industrial control systems (ICS), and remote access technologies—continues to grow. In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem. Directly connecting PLCs to the internet through cellular modems can create significant security risks. However, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary.
Steps to Reduce Internet Exposure
1. Assess Your Current Exposure. Begin by identifying which of your assets are accessible via the internet. Utilize tools and services (e.g., CISA’s Cyber Hygiene Vulnerability Scanning service as well as the Web-Based Tools for Identifying Internet-Exposed IT and OT Assets below) that can scan for publicly exposed systems to gain visibility into your organization's online footprint.
a. Determine whether integrators, managed security services providers (MSSPs), vendors, or other third parties have remote access to your systems or networks. This access may include VPN credentials, cellular modems, or other remote access technologies.
b. Verify your third-party connections. Demand the external internet protocol (IP) addresses of anything set up by the integrator as well as updates if those IP addresses change. Use the web-based tools (described below) to verify that the integrator is securing those connections.
2. Evaluate Your Necessity of Exposure. Determine which assets need to be internet-accessible for operational purposes. For those that do not need to be internet accessible, implement measures to remove or restrict access.
3. Mitigate Risks to Remaining Exposed Assets. Follow these steps to protect any assets that must remain internet-accessible:
a. Change default passwords.
b. Ensure systems are up to date with the latest security patches.
 i. Replace software and devices that are no longer receiving security support.
c. Use a jump host to provide secure, monitored access.
d. Monitor ingress and egress traffic to identify anomalous activity that requires further investigation.
e. Implement and enforce multifactor authentication (MFA) where possible, even if only at the jump host level.
f. Review the considerations in the Secure Remote Access to OT Environments section below.
4. Establish Routine Assessments. Regularly review and monitor your internet-accessible assets. As your organization's IT and OT environments evolve, continuous assessments help maintain a secure posture and quickly identify new exposures.
Secure Remote Access to OT Environments
CISA urges all critical infrastructure organizations to route all necessary remote access through a secure gateway, firewall, VPN, or other centrally managed access solution, rather than connecting directly to a PLC, human-machine interface (HMI), or remote terminal unit (RTU).
Additionally, organizations should require unique usernames, strong passwords, and phishing-resistant MFA for all remote access. Authentication controls should withstand brute-force attempts and other credential-based targeting.
The July 2026 malicious cyber activity targeting WWS Sector entities demonstrates the consequences of directly exposing PLCs to the internet. Threat actors remotely accessed internet-exposed PLCs, changed device IP addresses and passwords, and caused loss of monitoring and control functionality and, in some cases, operational disruptions.
For more information on securing remote access to OT environments, see the joint guidance, Secure Connectivity Principles for Operational Technology (OT).
Web-Based Tools for Identifying Internet-Exposed IT and OT Assets
In addition to securing remote access, entities should routinely use web-based exposure discovery tools to identify internet-exposed IT and OT assets associated with their organization. Entities should use these tools to search for both known organizational IP space and any assets that the entity could possibly be improperly exposing under vendor, contractor, or legacy infrastructure.
Many web-based exposure discovery tools offer unique capabilities for assessing and indexing IP addresses, parsing transport layer security (TLS) certificates, and tracking domains to provide a comprehensive view of an organization's internet attack surface. Examples include: Shodan, Censys, Thingful, and Shadowserver.
These web-based tools support attack surface reduction activities by providing visibility into various internet-exposed assets. They integrate with vulnerability tools, logging aggregators, and other scanning systems, which facilitates their incorporation into an entity’s infrastructure.
Note: The inclusion of these tools in this guidance does not imply endorsement by CISA or the U.S. government.
Organizations should routinely scan their public IP address ranges to identify ports and services that are accessible from the internet. Investigate any unexpected open ports and determine whether the associated system or service requires internet access. Close or restrict access to ports that do not have a documented operational need.

Leave a Reply