Back to all lessons
Awareness Lessons
last month

OT Devices on Public Cellular Networks Create Invisible Attack Surface

Water and wastewater facilities became targets because operational technology (OT) controllers were connected directly to public cellular networks, placing them entirely outside the visibility of traditional IT network scans and asset inventories. Without formal ownership or oversight, these devices accumulated vulnerabilities and misconfigurations with no accountability structure to catch them. This 'shadow OT' problem is widespread in critical infrastructure where IT and OT responsibilities are siloed or undefined. The involvement of Iranian-affiliated threat actors underscores that nation-state adversaries are actively hunting for exactly these kinds of unmonitored, internet-adjacent industrial systems. The consequences of a successful attack on water treatment infrastructure extend far beyond data loss — they carry direct public health and safety implications.

Tactical Insight

Immediate actions

  • Conduct a full asset discovery sweep that includes cellular-connected and out-of-band OT devices not visible to standard IT network scans.
  • Place all internet-facing industrial controllers behind a VPN or private APN to remove them from the public internet.
  • Audit access credentials on all OT devices and eliminate default or shared passwords immediately.

Long-term improvements

  • Establish a formal OT asset inventory program with designated ownership for every device, including those managed by third-party vendors or utilities.
  • Implement network segmentation that isolates OT/ICS environments from both IT networks and direct public internet exposure.
  • Define clear cross-departmental accountability policies so OT devices are never left outside the scope of both IT and operational teams.

Detection measures

  • Deploy passive OT-aware network monitoring tools (e.g., Claroty, Dragos, Nozomi) capable of detecting anomalous traffic on cellular and OT network segments.
  • Integrate OT device telemetry and alerts into a centralized SIEM so security teams receive visibility across all environments.
  • Establish baseline behavioral profiles for industrial controllers and alert on any deviation in command patterns or communication endpoints.