By Franklyn C. Adams
Timehri Networks
August 2026
Industrial Control Systems are increasingly connected to corporate networks, remote support platforms, cellular gateways, cloud services, and third-party vendors. That connectivity provides significant operational benefits, but it also creates opportunities for attackers.
For many water and wastewater utilities, municipalities, and other critical-infrastructure operators, cybersecurity improvement does not always begin with an expensive new platform.
Two of the most important actions are also among the most basic:
1. Remove default passwords. 2. Eliminate unnecessary direct Internet exposure of ICS and SCADA devices.
These steps sound simple. Yet when overlooked, they can turn an otherwise manageable cybersecurity weakness into an operational emergency.
Default Credentials Are an Unnecessary Risk
PLCs, RTUs, HMIs, cellular gateways, industrial switches, firewalls, cameras, engineering workstations, and other devices may arrive with manufacturer-default usernames and passwords.
Those credentials are often publicly documented.
A default password should therefore never be considered a secret.
If an attacker discovers an exposed device and the organization has not changed its factory credentials, the attacker may not need a sophisticated exploit. They may simply log in.
Organizations should establish a process to:
- Identify equipment that still uses manufacturer-default credentials
- Replace default passwords during commissioning
- Use strong, unique credentials for administrative accounts
- Eliminate unnecessary shared accounts
- Restrict privileged access to personnel who require it
- Store administrative credentials securely
- Review vendor and contractor accounts regularly
- Disable unused accounts
- Implement MFA wherever the technology supports it
Legacy OT equipment may not support modern authentication controls. In those situations, organizations should use compensating safeguards such as network segmentation, access control lists, jump servers, firewall restrictions, and tightly controlled remote access.
The objective is straightforward:
Possession of a manufacturer’s manual should never be enough to access a critical control system.
A PLC Should Not Need to Be Directly Accessible From the Internet
The second issue is direct Internet exposure.
PLCs, RTUs, HMIs, historians, engineering interfaces, cellular gateways, and other operational devices should not be reachable directly from the public Internet unless there is an exceptionally well-understood and controlled requirement.
Internet-exposed OT dramatically changes the threat model.
Instead of an attacker first having to compromise the enterprise network, bypass segmentation, and move toward the control environment, an exposed device may provide a direct path toward operations.
Search engines and automated scanners continuously identify Internet-connected systems. Attackers can perform the same discovery.
Utilities should therefore ask:
What OT assets can currently be reached from outside our organization?
If the answer is unknown, that is itself a cybersecurity issue.
Remote Access Is Not the Same as Internet Exposure
Utilities often need legitimate remote connectivity.
Operators may need emergency access. Integrators may support PLCs. Vendors may troubleshoot specialized equipment. Remote sites may communicate through cellular networks.
The answer is not to eliminate useful connectivity.
The answer is to architect it securely.
Instead of:
Internet → PLC
use controlled architectures such as:
Authorized User → MFA → VPN / Secure Access Gateway → Firewall → Jump Host → OT Network
Additional controls may include:
- Private APNs for cellular-connected sites
- Site-to-site encrypted tunnels
- Firewall allowlisting
- Role-based access
- Vendor-specific accounts
- Time-limited remote access
- Session logging
- Network segmentation
- OT DMZs
- Passive network monitoring
- Alerts for unusual authentication or configuration changes
Remote access should be something the organization deliberately grants, not something that exists simply because a device was connected to a modem or router years ago.
Don’t Forget Cellular Gateways
Cellular connectivity deserves particular attention.
A utility may have a well-designed enterprise firewall while a remote pump station, lift station, well field, or telemetry site communicates through a cellular gateway that was installed independently.
If that gateway is improperly configured, it can become an alternative route around the organization’s normal security perimeter.
Every utility should maintain an inventory of:
- Cellular routers and gateways
- SIMs and eSIMs
- Associated OT equipment
- Public versus private addressing
- Remote-management interfaces
- Firmware versions
- Administrative credentials
- Responsible vendors and internal owners
The principle is the same:
You cannot secure infrastructure you do not know exists.
Start With Visibility
Before purchasing another cybersecurity product, utilities should answer several basic questions:
What OT assets do we have?
Which devices still use default or shared credentials?
Which systems are reachable from the Internet?
Who can remotely access the environment?
How is that access authenticated?
Who monitors it?
How quickly would we know if unauthorized access occurred?
These questions form the foundation of practical OT cybersecurity.
Cybersecurity Must Support Operations
OT cybersecurity cannot be approached exactly like traditional enterprise IT.
Water must continue flowing. Wastewater must continue being treated. Pumps, chemical-feed systems, telemetry, controls, and safety processes must remain available.
Security improvements therefore need to account for operational risk, equipment limitations, maintenance windows, safety requirements, and system availability.
That is why effective OT cybersecurity is not simply about deploying technology.
It is about understanding how the process operates, identifying the most consequential risks, and applying controls without jeopardizing the mission.
Two Actions to Take This Week
For organizations beginning or strengthening their OT cybersecurity program, start with these two questions:
Are any of our OT devices still using default credentials?
Are any ICS or SCADA devices directly exposed to the Internet?
If either answer is yes—or if the organization cannot confidently answer—the issue deserves immediate attention.
Cybersecurity maturity is built incrementally.
Sometimes the most meaningful risk reduction begins with removing a default password and closing an unnecessary path from the Internet to the control system.
Timehri Networks helps utilities and critical-infrastructure organizations strengthen OT/ICS cybersecurity through practical assessments, secure architecture, continuous monitoring, and risk-based cybersecurity strategies.
Securing Operations. Strengthening Communities.