Halil, operators should assume tonight that any PLC, HMI, SCADA server, or engineering path reachable from the internet is not merely “exposed” — it may already be untrusted. FACT: CISA/FBI say Iranian-affiliated actors are targeting internet-connected OT devices/PLCs across U.S. critical infrastructure, and the updated advisory says actors extracted project files, modified or deleted logic including AOIs, and manipulated HMI/SCADA display data. That is not just nuisance screen defacement; in Purdue terms, this starts at Level 2/3 visibility and engineering access, but the safety concern is Level 1 process behavior being changed while operators are shown a false picture.
To separate defacement from unsafe process manipulation, I would ask for three evidence streams immediately: first, compare the running controller logic and project files against the last known-good offline backup, especially AOIs and recent downloads; second, compare HMI/SCADA values against historian trends and independent field readings where available; third, review engineering workstation and PLC access logs for vendor tool use — CISA/FBI specifically name Studio 5000 Logix Designer, EcoStruxure Control Expert, and Siemens TIA Portal in observed activity. If the screen changed but controller logic, setpoints, interlocks, and field values agree, that leans nuisance. If logic changed, AOIs disappeared, setpoints moved, outputs were forced, or the HMI disagrees with the physical process, treat it as unsafe manipulation until proven otherwise.
Immediate action: remove direct internet exposure, but do not let IT make blind firewall changes in the middle of a live process. CISA’s key action is to remove PLCs from direct internet exposure via secure gateway and firewall, and to work with IT/OT members or integrators. Do that in an OT-controlled sequence: freeze nonessential engineering changes, capture current PLC/project evidence first, identify all remote vendor and engineering routes, block only confirmed internet-facing paths, restrict remaining access to named engineering workstations, and have an operator/controls engineer verify the process after each change. A segmentation fix that breaks HMI-to-PLC visibility or a safety PLC communication path can create the incident we are trying to prevent.
Attribution matters for scope and intent: Lena and I agree the Iranian-affiliated label from CISA/FBI should make water, energy, and local government operators share IOCs quickly and assume disruptive intent, not just espionage. But attribution does not matter for tonight’s plant-floor decision. If a PLC is internet-exposed or the HMI may be lying, the response is the same: preserve evidence, validate logic, validate the physical process, and remove exposure without destabilizing operations.