How to defend critical infrastructure: Don’t Put the PLC on the Internet for Iran to find /s
Ah, the exciting world of industrial cybersecurity, where some genius apparently looked at a PLC controlling pumps, valves, and critical infrastructure and thought: “You know what this needs? A public IP address.” Because clearly the best way to manage a water system is to put the industrial equivalent of a steering wheel on the side of the road and hope nobody grabs it.
Then along comes an Islamo-fascist state-backed hacking group (or any random person with a scanner and too much time), discovers an exposed controller, and suddenly everyone is shocked that the Internet did exactly what the Internet does. The attackers didn't need some mythical cyber superweapon. They just needed the ability to find a device that someone had accidentally advertised to the entire planet. A PLC is not a website, not a cloud service, and not a remote desktop. It is a machine controller. It belongs behind layers of protection, not hanging directly off the public Internet like a forgotten home router from 2005.
The real vulnerability wasn't a zero-day exploit or some Hollywood-style cyber attack. The vulnerability was the timeless industrial classic: “temporary remote access turned permanent” “the integrator needed it for maintenance” “nobody knows who owns that box anymore” or “we'll fix it next budget cycle”. Congratulations: you have invented the world's most expensive IoT device by taking a critical infrastructure controller and making it searchable by anyone on Earth. The hackers may have been the ones turning the knobs, but someone first left the control panel sitting outside with a neon sign saying, “Please have a look.”