When CISA & the FBI Issue a Joint Advisory, OT Teams Take Notice
Security
When an advisory hits from CISA, the FBI, NSA, and Department of Energy all at once, critical infrastructure teams pay attention.
CISA’s joint advisory (AA26-097A) highlights ongoing exploitation of internet-facing Programmable Logic Controllers (PLCs) and OT devices across key sectors - specifically targeting industrial controllers (like Rockwell Automation/Allen-Bradley and Siemens) in Energy, Water/Wastewater, and Government facilities.
The core issue isn't a complex zero-day - it's visibility and internet exposure. Threat actors are finding internet-accessible PLCs, interacting directly with project files, and manipulating SCADA/HMI display data to disrupt real-world operations.
Key Immediate Steps for OT & Security Teams:
- Remove PLCs from direct internet exposure immediately. Use secure gateways, firewalls, or VPNs with strict access controls.
- Lock down physical controller switches. Ensure hardware mode switches on PLCs are set to "RUN" mode rather than "REMOTE" to block unauthorized remote programming changes.
- Audit common OT communication ports. Monitor inbound traffic on ports
44818,2222,102,502, and22for unauthorized connection attempts or overseas IP activity. - Enforce network segmentation. Air-gap or isolate control networks (Purdue Model Levels 0–2) from IT environments and direct external routing.
The Bigger Picture
Industrial cybersecurity is no longer just an IT policy discussion - it directly impacts operational uptime, safety, and grid resilience. As OT environments become increasingly connected, maintaining non-intrusive visibility and strict isolation across critical assets is vital.
At Argen Energy, we work alongside operators and infrastructure teams to ensure control networks remain resilient, secure, and fully operational against evolving threat vectors. Security in OT works best when it supports continuity rather than getting in the way of it.


