Original Coverage & Source Attribution: www.smartindustry.com
However, for the affected organization, they are not likely to have any impact on the outcome of the situation. For the operator, the consequences of a cyber event depend much more on practical questions such as:
- What assets are accessible via the internet?
- Who has access to these assets?
- Can any changes in the controller logic be identified?
- Is it possible to operate safely even in case of digital systems failure?
- Does the recovery and backup process exist and is it verified?
Those organizations that can positively answer these questions are usually able to recover relatively quickly. Other organizations often discover their vulnerabilities after the fact. And the reasons for it are rarely related to the technology. They are usually related to preparedness.
Why are PLCs still connected to the internet?
One of the most common reactions to incidents such as the recent attacks on the water systems is the disbelief in their occurrence. Some might ask, “How could there still be a PLC directly connected to the internet?”
For those who spent some time in water treatment facilities, manufacturing plants, energy operations or municipal infrastructures, the response is quite different. Most of the exposed systems were not intentionally installed to represent a cybersecurity risk.
See also: Who’s winning the cybersecurity arms race? A region-by-region scorecard
They were just the result of decades of decisions that had to do with operational requirements to ensure reliability, availability, and supportability.
Remote access was enabled primarily to troubleshoot processes and respond quickly to issues, reduce travel costs and provide support to third parties.
Each decision was reasonable at the moment it was made. But, as time goes on, they can lead to a state of unintended exposure that is no longer completely understood by the entity operating the system.
In many small-scale utilities, the same people that operate the water treatment facility may also perform networking, SCADA administration, compliance reporting and cybersecurity-related duties. It’s not usually about the neglect. It’s about the lack of resources and OT cybersecurity specialists.
The expertise gap as the vulnerability
The cyber industry always tends to frame its conversations around acquisition of technology. The organization is supposed to buy:
- Endpoint protection solution
- Network monitoring
- Firewall
- Security information and event management platform
- Threat detection solution
These technologies are valuable. However, many critical infrastructure organizations face a far greater issue that they simply lack OT cybersecurity expertise among their personnel.
{
“@context”: “https://schema.org”,
“@type”: “NewsArticle”,
“headline”: “What recent PLC attacks reveal about the state of OT cybersecurity”,
“datePublished”: “2026-10-06 12:56:00”,
“image”: “https://img.smartindustry.com/files/base/ebm/smartindustry/image/2026/10/6ac4d976b6b13f5963973042-figure_2_industrial_routers.png?auto=format,compress&fit=fill&fill=blur&w=1200&h=630”,
“author”: {
“@type”: “Organization”,
“name”: “Pune.Media Editorial Desk”,
“url”: “https://pune.media”
},
“publisher”: {
“@type”: “Organization”,
“name”: “Pune.Media”,
“logo”: {
“@type”: “ImageObject”,
“url”: “https://pune.media/wp-content/uploads/logo.png”
}
},
“isBasedOn”: “https://www.smartindustry.com/benefits-of-transformation/cybersecurity/article/55409795/what-recent-plc-attacks-reveal-about-the-state-of-ot-cybersecurity”,
“mainEntityOfPage”: “https://www.smartindustry.com/benefits-of-transformation/cybersecurity/article/55409795/what-recent-plc-attacks-reveal-about-the-state-of-ot-cybersecurity”,
“creativeWorkStatus”: “Editorial-assisted Curation”,
“comment”: {
“@type”: “Comment”,
“text”: “This article was curated, verified, and structured under organizational human editorial guidelines by the Pune.Media Editorial Desk.”
}
}

