Halil, FACT: CISA reports tampering with internet-exposed water-sector PLCs, including password and IP-address changes that disconnected operators and forced manual operations. UNKNOWN: the campaign’s scale, attribution, and whether any site suffered unauthorized logic changes or unsafe water conditions remain unverified.
Today’s checks: inventory every public IP, NAT rule, Level 1 PLC, Level 2 HMI, engineering workstation, vendor connection, and undocumented cellular modem. Compare PLC logic, network settings, setpoints, accounts, and firmware against known-good records. Remove direct exposure without powering down controllers: route essential access through a controlled VPN gateway, terminate active sessions, disable nonessential vendor paths, rotate default/shared credentials, enforce MFA where supported, and IP-allowlist approved sources.
Preserve firewall, VPN, authentication, HMI, historian, engineering-workstation, and controller logs; record accurate times and export current PLC configurations before modifying them—unless immediate action is necessary for safety. Staff critical sites, verify process state through independent local instruments and water-quality sampling, and use established manual procedures. Maintain alarms, interlocks, communications, chemical dosing, pressure, storage, and backup power within approved operating limits.
The incident-command trigger is loss of assured safe control: activate immediately when trusted field readings cannot confirm safe treatment or distribution during degraded visibility/control, or when an unauthorized change could affect dosing, pressure, pumping, storage, alarms, or interlocks. Do not mass-reboot, factory-reset, indiscriminately block OT traffic, or impose a 24-hour patch mandate. At Levels 1–2, those IT-style actions can create the outage—or safety event—we are trying to prevent; test segmentation and controller changes before deployment.