Back Appgate How CISA's PLC Warning Reinforces the Case for Zero Trust in OT
Critical infrastructure organizations have spent years balancing two realities that are often in tension: industrial systems were never designed for internet exposure, yet modern operations increasingly depend on remote access to keep distributed environments running. When CISA warns organizations to disconnect PLCs from public-facing networks, the immediate concern may appear sector-specific. The larger implication is broader and more consequential. The problem is not just that water utilities are at risk. The operating model behind many OT environments still assumes that direct connectivity can coexist safely with legacy perimeter defenses, even as that assumption becomes harder to defend.
That shift matters because OT security is no longer only protecting isolated systems from external intrusion. It is managing access across a highly distributed ecosystem of employees, vendors, engineers, service providers and remote operations centers, all of whom increasingly need to interact with systems built for reliability rather than constant connectivity. CISA's advisory is best understood not as a narrow warning one sector, but as evidence that the old model of industrial access is reaching its limits.
Industrial control systems were designed around a different set of assumptions than the ones shaping today's operating environments. PLCs, supervisory control and data acquisition (SCADA) platforms and distributed control systems were meant to run in tightly bounded environments where the number of users was small, the physical location of assets was known and access was largely controlled by proximity. In that context, security was often framed as a matter of segmentation, controlled physical access and trust in known operators.
That model has changed significantly. Organizations now depend on remote engineers, third-party service providers, system integrators, managed service teams and centralized support groups to keep facilities running across wide geographies. The increase in remote access was not a temporary pandemic-era adjustment or a convenience layered onto stable operations. It became a structural requirement of how industrial systems are maintained, repaired and optimized.
The problem is that many organizations introduced remote connectivity incrementally rather than redesigning access around the reality of distributed operations. Virtual private networks (VPNs) were added for vendor support. Firewalls were opened for troubleshooting. Remote desktop tools were used to shorten response times. Cellular gateways were installed to reach equipment in hard-to-access locations. Each decision may have been reasonable on its own, but together they created an environment in which systems intended to remain inside controlled industrial networks are now directly or indirectly reachable from outside those networks.
This is how exposure accumulates in OT: not through one dramatic architectural failure, but through years of practical decisions that solve immediate operational problems while quietly expanding the attack surface.
One of the most important aspects of the CISA guidance is not simply its recommendation to remove public exposure, but its acknowledgment that many organizations may not fully know where exposure exists. The advisory notes that undocumented cellular modems, vendor-installed access paths and operator-added connectivity can all create external reachability that does not appear in routine assessments.
That point should resonate far beyond water utilities. OT environments are typically layered over decades of equipment deployments, vendor relationships, acquisitions, maintenance cycles and incremental modernization efforts. As a result, organizations may have a reasonably good inventory of the devices they own, but a much weaker understanding of every pathway that can reach those devices. A plant may know which PLCs are in production and which systems are critical to operations, yet still lack a reliable picture of all the remote connections that can interact with them.
This is an important distinction because security teams often focus on asset visibility while underestimating connectivity visibility. Knowing that a controller exists is not the same as knowing who can reach it, through what method, under which circumstances and for how long. In many OT environments, that second layer of visibility is the one that matters most.
The risk here is not theoretical. When remote access is distributed across multiple vendors, tools and business units, the environment develops a form of infrastructure drift. Temporary access becomes persistent access. A project-specific connection remains after the project ends. A vendor modem survives long after the original technician has left. Over time, the organization ends up with a network of access paths that were never designed as a coherent system and were never fully retired as conditions changed.
The latest attacks against exposed industrial controllers reinforce a pattern that is becoming increasingly common in OT: attackers do not always need advanced malware, deep technical exploitation or novel zero-day techniques to cause operational disruption. In the incidents referenced by CISA, threat actors modified passwords, changed configurations, locked operators out of systems and interfered with monitoring and control. Those actions are effective precisely because control systems are built to run continuously and predictably. Once an attacker gains access, even limited actions can have outsized operational consequences.
This is one reason the traditional security conversation around patching, while still important, is no longer sufficient on its own. Patch management addresses vulnerabilities that may eventually be exploited. Exposure determines whether an attacker can reach the system in the first place. If a PLC is directly accessible from the public internet, or if a vendor connection effectively creates that condition, the organization has already moved the problem from theoretical to practical.
That distinction changes how risk should be prioritized. Reducing unnecessary exposure often delivers more immediate security value than trying to harden a system after it has already been made reachable. The first question is not whether the controller is patched enough to survive an attack. It is whether it should be reachable at all.
For a long time, OT security was organized around the same basic logic that shaped enterprise network security: define the perimeter, segment what matters and allow trusted users through controlled pathways. Firewalls, VPNs and virtual local area networks (VLANs) were all useful tools in that model, and they still have a place in modern architectures. The problem is that those controls were designed for a world in which network location carried more meaning than it does today.
That assumption is now outdated. A technician may be working from . A vendor may be supporting multiple facilities from a remote service center. A maintenance partner may need narrow access to a single piece of equipment for a limited period. A cloud-based management platform may interface with local industrial systems. In this environment, simply being inside the network says very little whether a person should be trusted to interact with a control system.
This is the deeper architectural shift underway in OT security. The security boundary is moving away from the network and toward identity, device posture, policy and session context. Organizations increasingly need to ask not whether a user has connected, but whether a verified user, on an approved device, at an approved time, should be allowed to access a specific asset for a specific purpose. That is a more precise and defensible model than the older notion of network-based trust.
The recommendations in CISA's advisory are practical, but they also point to a broader architectural conclusion. Disconnect PLCs from the public internet. Remove unnecessary direct access. Restrict remote connectivity. Require strong authentication. Limit access to authorized workstations. These are not isolated controls. Taken together, they describe a move away from implicit trust and toward verified, narrowly scoped access.
That is the essence of Zero Trust.
Although Zero Trust is often discussed in enterprise IT contexts, its relevance in OT is especially strong because industrial organizations cannot simply remove remote access. Operations depend on it. The challenge is not whether to allow remote access, but how to allow it without recreating the same exposure that legacy approaches created. Zero Trust Network Access (ZTNA) solves that problem by changing the access model itself. Instead of granting broad network reach and hoping segmentation will contain the risk, organizations can establish access only after identity has been verified and policy conditions have been satisfied.
This is where many organizations need to rethink their starting point. The goal should not be to secure exposed PLCs more effectively. The goal should be to eliminate unnecessary exposure altogether. That is a subtle but important distinction. One approach tries to protect a risky condition. The other removes the condition that makes the risk exploitable.
If the CISA advisory is read narrowly, organizations may treat it as a checklist item: for public-facing controllers, remove obvious exposures and move on. That would miss the more important lesson. The real issue is not only whether a device is directly exposed today, but whether the organization has a sustainable model for controlling access across an OT environment that has become more distributed, more connected and more dependent on third-party support.
That means leaders should begin asking different questions their environments. Which controllers, human-machine interfaces (HMIs), engineering workstations and remote support paths are reachable from outside the organization? Which vendor connections are still active, and which have become permanent by default? Which access methods were created for temporary use but never retired? Can access be limited to only the specific systems a user or contractor needs? Are remote sessions authenticated, approved, monitored and revoked with the same discipline as other critical operational processes?
These are not just technical questions. They are governance questions, operational questions and resilience questions. Organizations that can answer them with confidence are in a stronger position to reduce cyber risk without disrupting the work OT teams need to do.
The lesson in CISA's warning is not limited to water and wastewater operators. It reflects a broader reality for critical infrastructure: the more industrial environments depend on remote connectivity, the less defensible it becomes to treat that connectivity as a low-risk convenience. OT security now depends on making access precise, temporary and conditional rather than broad, persistent and assumed.
That is why the most effective response is not to add more layers around an outdated model. It is to replace the model itself. Organizations need access architectures that can support distributed operations while reducing the number of systems that are visible and reachable at any given moment. They need a way to keep industrial assets hidden until trust is established, based on identity, device context and policy rather than network location.
AppGate ZTNA gives organizations that foundation by closing the specific gaps this advisory exposes: uncontrolled exposure, weak visibility into who can reach what, and remote access built around broad network trust rather than verified identity.
Together, these capabilities give security and operations teams the visibility CISA found lacking: a clear, continuously verified record of who can reach which OT asset, through what method and for how long.
AppGate has built this approach specifically for industrial environments. In March 2026, AppGate extended its Zero Trust portfolio with a purpose-built offering for OT , drawing on its experience securing enterprise-scale deployments in defense and critical infrastructure to deliver native, on-premises, direct-routed secure access.
The result is not merely tighter control over sessions. It is a more resilient operating model for industrial environments that can no longer rely on perimeter assumptions that no longer hold.
The organizations that move first will not just respond more effectively to the CISA alert. They will build an access model that makes the incident harder to execute in the first place.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
