Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treat an internet-exposed water-system PLC as urgent, but do not switch it off blindly: it may be controlling a live treatment or distribution process. Notify the utility’s OT/controls and incident-response leads, assess what is reachable and whether remote access is needed, then remove direct public-internet access if responsible staff can make that change safely under site procedures.

Stabilize the situation and assign responsibility

Bring together the people who understand both the control system and the water operation: the OT/controls lead, operational supervisor, incident-response lead, and, where appropriate, the system integrator or PLC vendor. If the process may be affected, follow the facility’s established operating and emergency procedures.

  • Record when and how the exposure was discovered, the public address and service if known, observed process conditions, and any actions already taken.
  • Use the facility’s incident-response plan to coordinate decisions and reporting. A public connection is an urgent exposure, but it does not by itself prove that anyone accessed or changed the system.
  • Do not power down the PLC, alter its logic, update firmware, or apply an unreviewed firewall rule. Any of those changes could interrupt treatment or distribution.

Find out what is actually exposed

“The PLC is on the internet” can describe several different arrangements. Establish which device or service is reachable before choosing a containment action.

  • Identify the endpoint: Determine whether the public connection reaches the PLC, a human-machine interface (HMI), an engineering workstation, a remote-access gateway or VPN, or a vendor access service.
  • Map the route: Check which services are reachable, what network zones the endpoint can access, and whether it connects to business systems or other control equipment.
  • Check the intended need: Confirm whether the connection is authorized and whether operations or support genuinely require remote access.
  • Consult current records: Compare the finding with the site’s asset inventory and network diagrams, and update them if they are inaccurate.

An exposed HMI may reveal control views and settings as well as provide a path to unauthorized changes. In a 2024 fact sheet, EPA and CISA described water-system incidents in which malicious actors changed HMI settings, including set points and alarms; some affected operators reverted to manual operation. The fact sheet does not establish a sector-wide count of exposed PLCs or affected systems.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a process-safe containment path

CISA’s joint PLC advisory says: “Disconnect the PLC from the public-facing internet.” That is the preferred direction for a PLC that does not need public access. Apply it through the facility’s process-safety and change-control procedures, with the responsible OT personnel assessing dependencies before the change.

Situation Safer direction What to account for
No remote access is needed Remove direct public-internet exposure and isolate control networks and remote devices behind appropriate network boundaries. Assess operational dependencies and make the change through authorized site procedures; do not assume that simply disconnecting a device is harmless.
Remote access is needed for operations or support Place a controlled gateway, proxy, firewall, or VPN between remote users and the PLC rather than exposing the PLC programming interface directly. Limit access to named users and necessary routes, use strong authentication and MFA where available, monitor sessions, and maintain the access system securely.

If immediate disconnection is not operationally safe or authorized, constrain reachability promptly with the responsible OT staff. Remove default credentials, set strong unique credentials, and place an access-control boundary in front of the device. A VPN or gateway is not automatically safe: it also needs secure configuration, maintenance, and monitoring.

Rank #2
PLC Industrial Controller Kit, Interface and Software, Automation with Ladder Logic Training Course Ai Industrial GX Developer
  • 1 PLC Controller 20 i/o; 12 DC Inputs, 8 Relay Outputs
  • PLC Ladder Logic Software
  • 1 USB Interface Cable
  • Operation 24VDC, Bonus PLC ladder logic Training Course
  • For Windows 10, at 32bit

Check for signs of access and preserve evidence

Investigate rather than assuming either compromise or safety. Review available network, HMI, PLC, VPN, firewall, and account logs with people familiar with the equipment. Preserve relevant records before rotating credentials or rebuilding systems where feasible, following the incident-response plan.

  • Look for unrecognized logins, unusual remote sessions, or unexpected account lockouts and password changes.
  • Compare set points, alarms, PLC configurations, and ladder logic with authorized values and trusted engineering records.
  • Ask operators about unexplained process behavior or changes in how alarms and controls respond.

EPA and CISA’s account of 2024 water-system incidents describes actors changing set points and settings, disabling alarms, and changing passwords. These are useful items to check, not proof that a particular exposed system was accessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Restore safely and reduce the chance of recurrence

Recovery should be based on a known-good system state and approved change control, not on guesswork. Validate safe process operation and compare PLC logic and configurations with trusted engineering records. Restore only from known-good backups, then review credentials, vendor accounts, remote-access paths, firewall rules, and network segmentation.

  • Keep separately stored, tested copies of PLC logic, configurations, network settings, and engineering drawings.
  • Maintain accurate OT/IT topology information so responders can identify connected assets and dependencies.
  • Patch or upgrade using the equipment vendor’s guidance and test procedures appropriate to the PLC and process.
  • Inventory internet-accessible assets regularly, decide which genuinely need remote reachability, and reassess access as systems and operational needs change.

The appropriate response depends on the PLC model, reachable services, network topology, process consequences, vendor support, and evidence of access. Those details require assessment by the utility’s operational and incident-response personnel; general guidance cannot determine a safe site-specific change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.