Recommended Free Tools
In a 2022 survey of 125 senior port and terminal personnel, SCADA was named in two different ways: 36% of respondents who reported a data breach identified it among the vulnerabilities involved, while 74% of respondents named it as a cybersecurity vulnerability of concern. Those figures show what survey respondents reported and feared; they do not count breaches across all U.S. ports or prove that SCADA caused an incident.
What the survey says about SCADA and breaches
Jones Walker LLP’s 2022 Ports and Terminals Cybersecurity Survey collected responses from 125 C-suite executives, directors, security and compliance officers, and general counsel. It asked both about vulnerabilities in breaches respondents said they had experienced and about vulnerabilities they perceived across U.S. ports and terminals. These are self-reported survey answers, not an audited national incident database.
| Survey question | SCADA result | What the figure means |
|---|---|---|
| “What vulnerabilities were involved in the data breach?” | 36% | Among respondents who reported a breach, this share named SCADA among the vulnerabilities involved. |
| “Which of the following do you consider to be the cybersecurity vulnerabilities of US ports and terminals?” | 74% | This share identified SCADA as a vulnerability of concern in the broader perception question. |
The two percentages have different question contexts and respondent groups. The 36% figure does not mean SCADA was involved in 36% of all port breaches, and neither figure establishes that SCADA was the entry point or cause of a breach. The survey landing page describes the respondents and scope; the percentages and question wording appear in its 2022 survey and survey results.
How SCADA compares with other concerns in the survey
Other systems and issues also appeared in the survey. These values answer the same respective questions as the SCADA figures, rather than measuring independently verified compromises.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
| Survey context | Technology or issue | Reported share |
|---|---|---|
| Perceived vulnerability question | SCADA | 74% |
| Perceived vulnerability question | ERP software | 72% |
| Perceived vulnerability question | IoT | 70% |
| Vulnerabilities named in reported breaches | IoT | 52% |
| Vulnerabilities named in reported breaches | Unpatched vulnerabilities | 42% |
| Vulnerabilities named in reported breaches | ERP software | 34% |
| Vulnerabilities named in reported breaches | Field device management systems | 32% |
The table summarizes respondents’ answers in the 2022 survey; it should not be read as a ranking of confirmed attack causes. The questions measure different things from official threat advisories or incident counts, so their figures cannot be directly compared.
What SCADA means in a port environment
SCADA—supervisory control and data acquisition—refers to systems used to monitor and supervise industrial processes. It is part of the broader operational technology (OT) environment: programmable systems and devices that interact with the physical world, including equipment that monitors or controls processes. In a port or terminal, disruptions to OT can affect physical operations, so security measures must account for safety, reliability, and availability as well as cybersecurity.
Rank #2
NIST’s SP 800-82 Rev. 4 Initial Public Draft, published September 21, 2026, discusses OT’s distinct performance, reliability, and safety requirements and includes transportation and maritime considerations. It is an initial public draft, not a final revision; NIST lists November 30, 2026, as its comment deadline.
What current CISA advisories establish—and what they do not
A CISA advisory originally issued April 7, 2026, and revised July 22, 2026, warns that Iranian-affiliated actors targeted internet-exposed programmable logic controllers (PLCs) in multiple U.S. critical-infrastructure sectors. CISA describes malicious interactions with PLC project files and manipulation of human-machine interface (HMI) and SCADA displays; in some cases, the activity caused operational disruption and financial loss. The advisory names government services and facilities, water and wastewater, and energy. It is cross-sector evidence, not evidence of new port-specific attacks or proof that SCADA caused port breaches.
The July 2026 update names observed PLC targets from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens, while cautioning that other devices may be affected. CISA’s advisory recommends installing PLCs according to manufacturer guidance, removing direct internet exposure through a secure gateway and firewall, checking logs for suspicious traffic, and coordinating among IT/OT staff and integrators. It does not endorse a particular product.
Steps ports and terminals can take to reduce OT risk
CISA’s recommendations are general organizational guidance, not a port-specific incident response. Their practical application needs to be coordinated with the people responsible for safe and reliable operations.
- Eliminate direct PLC internet exposure. Identify internet-reachable PLCs and remove that exposure through a secure gateway and firewall, as CISA advises. Plan changes with IT/OT staff and integrators so they do not disrupt operations.
- Follow device-specific installation guidance. Install and configure PLCs according to the relevant manufacturer’s guidance rather than assuming a single setting applies to every device.
- Review logs for suspicious activity. Monitor relevant network and device logs for unexpected connections or interactions, and ensure staff know how to escalate findings.
- Coordinate security with operational requirements. Include OT operators, IT/security teams, and integrators in decisions that affect control systems. Evaluate changes against safety, reliability, and availability needs.
CISA’s May 6, 2025 OT mitigation bulletin explains why basic weaknesses matter: “Although these activities often include basic and elementary intrusion techniques, the presence of poor cyber hygiene and exposed assets can escalate these threats, leading to significant consequences such as defacement, configuration changes, operational disruptions and, in severe cases, physical damage.” This is general critical-infrastructure guidance; it references energy and transportation systems, not a particular port breach.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to interpret the headline
The defensible conclusion is that some respondents to Jones Walker’s 2022 survey named SCADA among vulnerabilities involved in breaches they reported, and many more considered it a vulnerability of concern. The survey does not establish how many U.S. port incidents involved SCADA, whether it was a cause, or whether the reported experiences represent all ports and terminals. CISA’s later PLC advisory demonstrates that exposed control systems are a cross-sector concern, but it does not fill that port-specific evidence gap.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

