Exposed by Default: OT/ICS Security Gaps in Critical Infrastructure
A structured red team engagement against a regional energy utility revealed operational technology systems accessible from the internet that the client's security team did not know existed.
The Systems Nobody Knew About
The engagement began as a standard external penetration test. We were given a scope: the client’s corporate IT network and publicly facing web properties. Standard terms, standard methodology.
On day three, we found industrial control systems.
They were not in scope. They were not supposed to be accessible from the internet. The client’s security team had no record of them being exposed. The engineering team that managed them had no idea they could be reached from outside the facility’s network.
This is not unusual. It is, based on our research, common.
How This Happens
Operational technology systems — the software and hardware that control physical processes in utilities, manufacturing, water treatment, and similar environments — were designed before internet connectivity was a consideration. Security was not designed in. Network separation was assumed to be permanent.
Over time, connections are added for legitimate operational reasons: remote monitoring, vendor support access, system updates. Each connection is added by the team that needs it. Security teams are rarely in the loop. The aggregate effect is exposure that no single person authorized and no single team fully understands.
What We Found
From the internet, without credentials, we were able to reach:
- SCADA interfaces for substation monitoring
- Historian servers containing years of operational data
- Remote access panels for field equipment controllers
We stopped. We documented. We reported immediately. We did not proceed further, and we never do in these situations.
The client’s response was appropriate: the exposure was treated as a critical incident. Systems were isolated. An investigation was opened into how the exposure occurred.
The Systemic Issue
The specific vulnerabilities we found were remediable. The systemic issue — the absence of a process for tracking and reviewing OT exposure as networks evolve — is harder. It requires organizational changes that cross the traditional boundary between IT security and operational engineering.
That boundary is precisely where attackers are looking. They know it exists. They know it is unguarded. They are patient.