Cyber Decision LedgerTechnology

ICS / OT

24 public Decision Records in the whole ledger carry this label. Back to the full Ledger →

Decision Records

OT remote-access compromise incident handlingCRT-2026-02362026.08.11Afternoon roundtable6 references

Safety-first response to OT remote-access compromise

OT operators should treat remote-access compromise patterns as safety incidents, pairing incident leadership with operations, independently verifying physical conditions, freezing PLC and HMI changes, preserving remote-access logs, revoking sessions, restricting vendor access, and avoiding unsafe recovery steps.

When remote-access compromise may affect operational technology, handle the response as a safety event: coordinate with operations, verify physical conditions independently of screens, freeze unsafe control changes, preserve remote-access evidence, revoke sessions, restrict vendor access, and avoid untested recovery steps. Use incident examples only with appropriate caveats.

ActiveLast revised 2026-08-11
TechICS / OTAreaBreachRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/8 backed · 2 gaps
Same-day OT remote-access safety reviewCRT-2026-02322026.08.11Morning roundtable8 references

OT remote-access safety sweep for small utilities

Small water, wastewater, and energy operators should perform a controlled OT safety sweep: verify physical process state locally, remove public PLC and HMI exposure, restrict vendor VPNs, cellular routers, private APN paths, and edge management access, rotate default credentials with OT staff present, preserve logs, and test manual fallback procedures before disruptive segmentation changes.

Small water, wastewater, and energy operators should run a safety-first remote-access review with operations staff: verify local process state, remove public controller and HMI exposure, tighten vendor and cellular access paths, change default credentials carefully, preserve logs, and test manual fallback before disruptive network changes. Avoid unsupported attribution or incident-specific details.

ActiveLast revised 2026-08-11
TechICS / OTAreaPatch prioritization
SeverityHigh
ConfidenceHigh confidence · 0/8 backed · 2 gaps
Exposed OT remote access continuityCRT-2026-02172026.08.08Afternoon roundtable6 references

Physical-process validation for exposed OT access

Treat exposed control-system and unsafe remote-access activity at water utilities and similar OT environments as an operational continuity incident. Remove direct internet exposure, require logged VPN and multifactor authentication where remote access remains necessary, preserve controller and access evidence, reset credentials carefully, and validate manual operations against physical instrumentation before trusting SCADA alone.

Water utilities and operators of exposed OT should remove direct controller exposure, route necessary remote access through logged VPN and multifactor authentication, preserve controller and access evidence, and validate physical process state with field instrumentation before relying on SCADA readings. Broader sector claims should be added only with sector-specific evidence.

ActiveLast revised 2026-08-08
TechICS / OTAreaRisk acceptanceSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water utility OT incident responseCRT-2026-02062026.08.07Morning roundtable5 references

Operational emergency handling for water-utility PLC and HMI activity

When a water utility has reported or suspected PLC or HMI compromise, stand up an operations-led OT incident bridge, disable unnecessary remote access, tightly gate vendor access, validate physical plant state outside the HMI path, preserve controller state, and avoid blind PLC or SCADA changes during service risk.

For water utilities facing reported or suspected PLC or HMI compromise, treat the response as a service-affecting OT incident rather than a normal IT patch ticket: coordinate with operations, reduce unnecessary remote access, preserve state, validate plant conditions independently of the HMI, and avoid unreviewed controller changes.

ActiveLast revised 2026-08-07
TechICS / OTAreaSOC escalationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water and wastewater control-path containmentCRT-2026-02012026.08.07Afternoon roundtable5 references

Water-sector exposed control-path containment

Operators should remove public exposure from controllers, HMIs, engineering workstations, VPNs, cellular modems, and vendor remote-access paths; preserve controller state; verify physical process conditions; and restore only after safe local control and trusted access paths are validated.

Water and wastewater teams with exposed control or remote-access paths should prioritize same-day containment: remove public exposure, preserve state, check physical process conditions, and restore through trusted access. Treat attribution and reported incident scale as secondary unless primary advisories are added.

ActiveLast revised 2026-08-07
TechICS / OTAreaPatch prioritizationRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water and wastewater OT incident handlingCRT-2026-01982026.08.07Afternoon roundtable7 references

Water and wastewater OT safety-first continuity handling

Yes. Treat reported water and wastewater OT activity as a safety and continuity incident: verify local process state first, remove exposed cellular, PLC, HMI, and remote-access paths in an OT-safe sequence, rotate compromised credentials, prepare manual-safe operations, and coordinate with public-sector and public-health partners where needed.

For reported water and wastewater OT activity, use a safety-first continuity posture. Verify process state locally, remove exposed remote paths in an OT-safe sequence, rotate compromised credentials, prepare manual-safe operation, and coordinate with appropriate public authorities if service or water quality could be affected.

ActiveLast revised 2026-08-07
TechICS / OTAreaBreachSOC escalation
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water control system isolationCRT-2026-01902026.08.05Afternoon roundtable8 references

Isolate exposed water control paths

Yes. If a water or wastewater control path is reachable from the internet, isolate or firewall it now, verify the physical process locally, preserve controller and network evidence, and require engineering approval before PLC logic, restart, patching, or network changes.

Where water or wastewater control paths are reachable from the internet, operators should isolate or firewall them, verify physical process state locally, preserve controller and network evidence, and require engineering approval before changes to PLC logic, restarts, patching, or network paths.

ActiveLast revised 2026-08-05
TechICS / OTAreaPatch prioritizationRisk acceptance
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water and wastewater PLC exposure responseCRT-2026-01752026.08.04Morning roundtable6 references

Exposed water control assets require safety-first response

When water or wastewater control equipment is directly exposed to the internet, or operators see tampering symptoms, remove exposure, verify the physical plant state, lock down remote access, and preserve evidence before making changes. Treat this as a safety-and-continuity response, not routine IT patching.

Organizations operating exposed water or wastewater control equipment should treat confirmed direct exposure or tampering signs as a safety-and-continuity event: remove direct internet exposure, verify physical operations, secure remote access, and preserve evidence before broader remediation.

ActiveLast revised 2026-08-04
TechICS / OTAreaPatch prioritizationRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT public reachability removalCRT-2026-01702026.08.04Morning roundtable5 references

Safely remove public PLC reachability

Remove direct internet reachability from PLCs and OT paths as a controlled safety operation: verify local process state, preserve logs and configurations, check remote-access dependencies, and prepare manual operation before closing paths.

Water and field-device operators should remove direct public reachability from PLCs and related OT paths only through a controlled safety process that verifies process state, preserves logs and configurations, checks remote-access dependencies, and prepares manual operation.

ActiveLast revised 2026-08-04
TechICS / OTAreaPatch prioritizationRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water utility PLC tampering responseCRT-2026-01612026.08.02Afternoon roundtable4 references

Water utility response to exposed PLC tampering

Stabilize the physical water process before cyber changes, verify controller and HMI state from trusted sources, preserve controller and workstation evidence, then remove direct internet exposure through gateway, firewall, and allowlist controls. Avoid blind reboots, resets, or configuration changes before engineering review.

For water utilities facing reported exposed Rockwell or Allen-Bradley controller tampering that affects monitoring or control, put process safety first, preserve evidence, and move controllers behind controlled access paths. Avoid unsupported resets or reboots until engineering impact is understood.

ActiveLast revised 2026-08-02
TechICS / OTAreaPatch prioritizationRisk acceptance
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Same-day OT containment for exposed Rockwell and Allen-Bradley PLC environmentsCRT-2026-01572026.08.01Afternoon roundtable6 references

Same-day containment for exposed industrial controllers

Operators with exposed Rockwell or Allen-Bradley PLCs or suspicious control-system behavior should begin same-day OT containment as a control-trust emergency, while coordinating changes with plant engineering and not treating exposure alone as proof of compromise.

Operators with exposed or suspicious Rockwell and Allen-Bradley PLC environments should move into same-day containment: confirm process state with engineering, preserve evidence, remove direct internet exposure or unsafe remote access, and coordinate notifications where service or safety is affected. Avoid asserting compromise solely from internet exposure.

ActiveLast revised 2026-08-01
TechICS / OTAreaRisk acceptanceSOC escalationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water utility OT loss-of-control responseCRT-2026-01522026.07.31Morning roundtable5 references

Municipal water OT loss-of-control response

Municipal water operators should treat credible signs of remote-control loss as an OT safety and trust problem before debating attribution. They should verify pumps, tanks, valves, dosing, and alarms; confirm manual fallback; restrict vendor and remote access; carefully rotate shared or default credentials with OT operators involved; segment exposed control paths; and report suspected activity.

Water and wastewater operators that see credible signs of remote-access loss or control-system tampering should first verify physical operations and manual fallback, restrict remote and vendor paths, review credentials with OT staff involved, segment exposed control paths, and report suspected activity before focusing on attribution.

ActiveLast revised 2026-07-31
TechICS / OTAreaPatch prioritizationSOC escalationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Mitsubishi MELSEC MX vulnerability triageCRT-2026-01502026.07.31Afternoon roundtable4 references

Mitsubishi OT vulnerability triage for small utilities

No for most utilities. Treat the issue as immediate only where an affected Mitsubishi control deployment is confirmed in an active control cell and reachable from an HMI, engineering workstation, vendor remote access, cellular router, or less-trusted path.

Do not let a Mitsubishi OT vulnerability replace the broader small-utility OT containment playbook for most utilities. Treat it as immediate only after confirming that affected equipment and firmware are present in an active, reachable control path; otherwise fold it into inventory, segmentation, remote-access, and maintenance-window planning.

ActiveLast revised 2026-07-31
TechICS / OTAreaPatch prioritizationVulnerability
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water utility OT containment and evidence preservationCRT-2026-01492026.07.31Afternoon roundtable6 references

Water utility OT containment before patch-first changes

Yes. For exposed water and wastewater controller or HMI paths, remove direct internet exposure, restrict vendor and remote access through verified routes, preserve controller and access evidence, and validate local or manual operations before making controller changes.

For water and wastewater utilities with exposed controller or HMI access paths, prioritize containment over a patch-first response: remove direct exposure, restrict remote access, preserve controller and access logs where feasible, and validate safe manual or local operations before making controller changes. Avoid precise incident counts or named guidance claims unless primary sources are added.

ActiveLast revised 2026-07-31
TechICS / OTAreaPatch prioritizationVulnerability
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water-sector OT exposure responseCRT-2026-01422026.07.30Morning roundtable6 references

Safe-continuity response for exposed water-sector control paths

For internet-connected PLC, HMI, SCADA, or vendor remote-access paths in water or similar critical-infrastructure environments, treat exposure or suspected intrusion as a safety and continuity incident. Verify process state locally, shift to controlled local or manual operation when needed, isolate external command paths without breaking plant visibility, freeze engineering changes, preserve project files, and rotate engineering and vendor credentials from clean systems.

Water and critical-infrastructure operators should treat exposed or suspected-compromised control paths as urgent safety and continuity events. Confirm plant state locally, preserve evidence, use controlled local or manual operation where needed, isolate risky remote command paths carefully, and rotate engineering or vendor credentials from clean systems.

ActiveLast revised 2026-07-30
TechICS / OTAreaRisk acceptanceSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT exposure containmentCRT-2026-01342026.07.27Afternoon roundtable5 references

Contain internet-exposed OT access paths

Operators should treat directly internet-exposed PLC, HMI, SCADA, and engineering access paths as untrusted, remove exposure immediately, preserve project evidence, compare controller logic and project files with known-good backups, independently verify HMI and process values, and avoid logic changes without OT owner approval.

Treat direct internet exposure of PLCs, HMIs, SCADA interfaces, and engineering paths as unsafe. Remove that exposure, preserve relevant project evidence, compare logic and project files to trusted backups, verify process readings independently, and coordinate any changes with OT owners. Keep actor attribution tied to the reported warning unless the underlying advisory is separately attached.

ActiveLast revised 2026-07-27
TechICS / OTAreaPatch prioritizationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT controller and display manipulation responseCRT-2026-01302026.07.26Morning roundtable6 references

PLC and HMI manipulation process-integrity response

Reported PLC and HMI manipulation should be handled as a safety and process-integrity response: remove direct internet access for controllers, HMIs, engineering workstations, and vendor remote paths; freeze risky changes; preserve evidence; compare running logic with known-good baselines; and validate display state through independent checks.

When reported controller or HMI manipulation is present, treat the response as a safety and process-integrity matter: remove direct exposure, pause risky changes, preserve OT evidence, compare running logic with trusted baselines, and independently validate process state.

ActiveLast revised 2026-07-26
TechICS / OTAreaPatch prioritizationRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT exposure containmentCRT-2026-01232026.07.24Morning roundtable6 references

Contain internet-exposed PLC and SCADA access

Operators with internet-exposed PLC, HMI, or SCADA paths should remove direct public reachability using OT-safe change control, preserve controller and firewall evidence, validate controller logic and operator views, and move engineering access behind allowlisted VPN or jump-host paths.

Organizations with internet-reachable industrial controller, HMI, or SCADA access should treat that exposure as urgent: remove public reachability through OT-safe change control, preserve relevant evidence, validate controller logic and operator views, and move engineering access behind approved VPN or jump-host controls. Avoid relying on actor attribution or exact exposure counts for the action.

ActiveLast revised 2026-07-24
TechICS / OTAreaRisk acceptanceVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
KNX building-automation remediation ownershipCRT-2026-01102026.07.20Morning roundtable6 references

KNX facilities-led safety remediation

Treat exposed KNX and building-management remediation as a facilities-led safety operation. Facilities and OT teams should lead safe isolation, verify manual or safe operating modes, preserve recovery materials, and avoid blind mass resets or reprogramming.

Handle exposed KNX/IP and building-management remediation with facilities and OT involvement: isolate safely, verify manual or safe operating modes, preserve recovery materials, and avoid blind mass resets or reprogramming.

ActiveLast revised 2026-07-20
TechICS / OTAreaPatch prioritization
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Validate IT and OT separation before claiming segmentation heldCRT-2026-01052026.07.19Morning roundtable6 references

IT and OT separation validation after administrative-system malware

Do not rely on diagrams or public reassurance alone. Validate the infected zone, identity crossover, Level 4-to-Level 3 paths, OT choke points, data flows, engineering workstation integrity, and controller or SCADA change history before claiming separation held.

When malware is found on administrative or contractor systems, do not rely on diagrams or reassurance to claim IT and OT separation held. Validate identity paths, network routes, choke points, data flows, engineering workstations, and controller or SCADA change history before making that claim.

ActiveLast revised 2026-07-19
TechICS / OTAreaRisk acceptanceVulnerability
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT/critical-infrastructure exposure triage and patch sequencingCRT-2026-00852026.07.16Afternoon roundtable6 references

Triage OT edge and ICS advisories without blind patching

Pull engineering into triage for exposed router and edge paths and packet-flagged ICS/OT advisories. First isolate exposure, restrict management access, confirm backups and configuration exports, add segmentation and monitoring, then patch during approved outages unless active exploitation or unsafe exposure is confirmed.

OT and critical-infrastructure teams should triage packet-flagged router, edge-node, and ICS advisory pressure with engineering involvement before patch execution. Prioritize exposure isolation, management-access restriction, backup/config-export validation, segmentation, and monitoring; patch in approved outages unless confirmed exploitation or unsafe exposure requires faster action.

ActiveLast revised 2026-07-16
TechICS / OTAreaPatch prioritizationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
OT safety-led containmentCRT-2026-00512026.07.10Morning roundtable5 references

Use safety-led OT containment for Poland-style disruption

Operate in loss-of-view or loss-of-control mode: verify safe manual local operation first; freeze or tightly ACL remote and vendor access; preserve firewall, VPN, and HMI logs and images; surgically isolate enterprise, DMZ, remote-access, engineering, HMI, and controller networks; validate RTU and PLC firmware or controller logic and HMI project files; rotate default and vendor credentials; and reintroduce access only through logged jump hosts.

For Poland-style destructive OT disruption, treat response as safety-led containment rather than routine IT ransomware recovery: verify safe local operation, tightly control remote/vendor access, preserve OT and access logs, isolate surgically, validate controller and HMI state, rotate vendor/default credentials, and restore through logged jump hosts with operations signoff.

ActiveLast revised 2026-07-10
TechICS / OTAreaRisk acceptanceSOC escalation
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water utility OT exposure reductionCRT-2026-00162026.06.28Morning roundtable6 references

Small Water Utilities Should Remove Internet-Exposed PLC/HMI Access First

Remove PLC/HMI management from the public internet, put remote access behind VPN/MFA or disable it, change Unitronics/default/shared credentials, inventory devices controlling pumps, tanks and chemical feeds, add basic logging, and prepare manual operations if compromise indicators appear.

Small water utilities should prioritize immediate OT exposure reduction: remove PLC/HMI management from the public internet, disable or protect remote access with VPN/MFA, replace default or shared credentials, inventory process-control devices, add basic logging and prepare manual operations. Avoid actor-attribution claims unless primary advisory support is added.

ActiveLast revised 2026-06-28
TechICS / OTAreaPatch prioritizationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Lantronix EDS5000 CVE-2025-67038 OT containmentCRT-2026-00102026.06.25Afternoon roundtable6 references

Contain Lantronix EDS5000 management-plane exposure

Inventory EDS5000/EDS5008 exposure, remove internet and direct IT reachability, restrict management to OT subnets or jump hosts with ACLs, verify vendor-supported fixed firmware before upgrading, and monitor admin logins, configuration changes, and shell or command-execution indicators.

For Lantronix EDS5000/EDS5008-class OT management devices, start with exposure inventory and network containment: no internet reachability, no direct IT-to-device access, and management limited to OT subnets or jump hosts with ACLs. Verify vendor-supported fixed firmware before scheduling upgrades, and monitor admin logins, configuration changes, and command-execution indicators.

ActiveLast revised 2026-06-25
TechICS / OTNetwork infrastructureAreaPatch prioritizationRisk acceptance
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps

Unified Search

Search the public record.