Protecting Critical Infrastructure. Securing Our Future.
Florida Caribbean East Africa Email (786) 529-5851
Back to Blogs & Articles

Two Simple OT Security Actions That Can Prevent a Major Incident

Two simple OT cybersecurity gaps can create significant risk: default credentials and unnecessary Internet-facing ICS/SCADA devices.

By Franklyn C. Adams
Timehri Networks

August 2026

Industrial Control Systems are increasingly connected to corporate networks, remote support platforms, cellular gateways, cloud services, and third-party vendors. That connectivity provides significant operational benefits, but it also creates opportunities for attackers.

For many water and wastewater utilities, municipalities, and other critical-infrastructure operators, cybersecurity improvement does not always begin with an expensive new platform.

Two of the most important actions are also among the most basic:

1. Remove default passwords. 2. Eliminate unnecessary direct Internet exposure of ICS and SCADA devices.

These steps sound simple. Yet when overlooked, they can turn an otherwise manageable cybersecurity weakness into an operational emergency.

Default Credentials Are an Unnecessary Risk

PLCs, RTUs, HMIs, cellular gateways, industrial switches, firewalls, cameras, engineering workstations, and other devices may arrive with manufacturer-default usernames and passwords.

Those credentials are often publicly documented.

A default password should therefore never be considered a secret.

If an attacker discovers an exposed device and the organization has not changed its factory credentials, the attacker may not need a sophisticated exploit. They may simply log in.

Organizations should establish a process to:

  • Identify equipment that still uses manufacturer-default credentials
  • Replace default passwords during commissioning
  • Use strong, unique credentials for administrative accounts
  • Eliminate unnecessary shared accounts
  • Restrict privileged access to personnel who require it
  • Store administrative credentials securely
  • Review vendor and contractor accounts regularly
  • Disable unused accounts
  • Implement MFA wherever the technology supports it

Legacy OT equipment may not support modern authentication controls. In those situations, organizations should use compensating safeguards such as network segmentation, access control lists, jump servers, firewall restrictions, and tightly controlled remote access.

The objective is straightforward:

Possession of a manufacturer’s manual should never be enough to access a critical control system.

A PLC Should Not Need to Be Directly Accessible From the Internet

The second issue is direct Internet exposure.

PLCs, RTUs, HMIs, historians, engineering interfaces, cellular gateways, and other operational devices should not be reachable directly from the public Internet unless there is an exceptionally well-understood and controlled requirement.

Internet-exposed OT dramatically changes the threat model.

Instead of an attacker first having to compromise the enterprise network, bypass segmentation, and move toward the control environment, an exposed device may provide a direct path toward operations.

Search engines and automated scanners continuously identify Internet-connected systems. Attackers can perform the same discovery.

Utilities should therefore ask:

What OT assets can currently be reached from outside our organization?

If the answer is unknown, that is itself a cybersecurity issue.

Remote Access Is Not the Same as Internet Exposure

Utilities often need legitimate remote connectivity.

Operators may need emergency access. Integrators may support PLCs. Vendors may troubleshoot specialized equipment. Remote sites may communicate through cellular networks.

The answer is not to eliminate useful connectivity.

The answer is to architect it securely.

Instead of:

Internet → PLC

use controlled architectures such as:

Authorized User → MFA → VPN / Secure Access Gateway → Firewall → Jump Host → OT Network

Additional controls may include:

  • Private APNs for cellular-connected sites
  • Site-to-site encrypted tunnels
  • Firewall allowlisting
  • Role-based access
  • Vendor-specific accounts
  • Time-limited remote access
  • Session logging
  • Network segmentation
  • OT DMZs
  • Passive network monitoring
  • Alerts for unusual authentication or configuration changes

Remote access should be something the organization deliberately grants, not something that exists simply because a device was connected to a modem or router years ago.

Don’t Forget Cellular Gateways

Cellular connectivity deserves particular attention.

A utility may have a well-designed enterprise firewall while a remote pump station, lift station, well field, or telemetry site communicates through a cellular gateway that was installed independently.

If that gateway is improperly configured, it can become an alternative route around the organization’s normal security perimeter.

Every utility should maintain an inventory of:

  • Cellular routers and gateways
  • SIMs and eSIMs
  • Associated OT equipment
  • Public versus private addressing
  • Remote-management interfaces
  • Firmware versions
  • Administrative credentials
  • Responsible vendors and internal owners

The principle is the same:

You cannot secure infrastructure you do not know exists.

Start With Visibility

Before purchasing another cybersecurity product, utilities should answer several basic questions:

What OT assets do we have?

Which devices still use default or shared credentials?

Which systems are reachable from the Internet?

Who can remotely access the environment?

How is that access authenticated?

Who monitors it?

How quickly would we know if unauthorized access occurred?

These questions form the foundation of practical OT cybersecurity.

Cybersecurity Must Support Operations

OT cybersecurity cannot be approached exactly like traditional enterprise IT.

Water must continue flowing. Wastewater must continue being treated. Pumps, chemical-feed systems, telemetry, controls, and safety processes must remain available.

Security improvements therefore need to account for operational risk, equipment limitations, maintenance windows, safety requirements, and system availability.

That is why effective OT cybersecurity is not simply about deploying technology.

It is about understanding how the process operates, identifying the most consequential risks, and applying controls without jeopardizing the mission.

Two Actions to Take This Week

For organizations beginning or strengthening their OT cybersecurity program, start with these two questions:

Are any of our OT devices still using default credentials?

Are any ICS or SCADA devices directly exposed to the Internet?

If either answer is yes—or if the organization cannot confidently answer—the issue deserves immediate attention.

Cybersecurity maturity is built incrementally.

Sometimes the most meaningful risk reduction begins with removing a default password and closing an unnecessary path from the Internet to the control system.


Timehri Networks helps utilities and critical-infrastructure organizations strengthen OT/ICS cybersecurity through practical assessments, secure architecture, continuous monitoring, and risk-based cybersecurity strategies.

Securing Operations. Strengthening Communities.

Request Assessment