What is internet-exposed OT?

Internet-exposed OT is the situation in which industrial control systems such as PLCs, HMIs and SCADA servers can be reached directly from the public internet, so that anyone can find them and connect to them. Search engines such as Shodan and Censys scan the entire internet continuously and make such devices discoverable with a single query. Because many industrial protocols have no authentication, an exposed controller is often not merely visible but can be operated or reprogrammed straight away.


🧠 What does it mean for OT to be β€˜exposed’?

A device is exposed when it has a public IP address, or is reachable through port forwarding on a router, and answers arbitrary senders on an industrial port. That is different from a device that opens an outbound connection to a cloud service itself: with exposure, the attacker can take the initiative.

Exposure does not automatically mean a system has been compromised. It does mean the device has lost the protection that network segmentation, a DMZ and a firewall are supposed to provide. In the Purdue Model a PLC belongs at level 1, several layers removed from the internet; exposure skips all of those layers in one go.


πŸ” How do search engines like Shodan find industrial systems?

Shodan was launched by John Matherly in 2009 as the first search engine for devices rather than web pages. Censys was created in 2015 at the University of Michigan, building on the open-source scanner ZMap. ZoomEye, released in 2013 by the security firm Knownsec, is the Chinese counterpart.

All of them rely on banner grabbing: they send a request to an IP address and port and store the response. A PLC that answers a Modbus or S7 request often reveals its vendor, model, firmware version and sometimes even the project name. Shodan adds an ics tag to recognised industrial banners, so they can be searched for specifically.

Port Protocol Typical device Risk when exposed
TCP 502 Modbus TCP PLCs, energy meters, inverters Registers read and written without authentication
TCP 102 S7comm Siemens S7 PLCs CPU stopped, program read or changed
TCP/UDP 44818 IP (CIP) Rockwell/Allen-Bradley PLCs Device identification, tags read and written
TCP 20000 DNP3 RTUs in power and water Commands sent to substations and pumping stations
UDP 47808 BACnet/IP Building management systems HVAC, lighting and access control manipulated
TCP 4840 OPC UA OPC UA servers Low if configured well, high with anonymous access

πŸ“Š How much OT is exposed in the Netherlands?

Global counts vary widely depending on which protocols and which search engine are included; estimates range from tens of thousands to hundreds of thousands of devices. For the Netherlands there is a concrete benchmark: the University of Twente, commissioned by the WODC (the research centre of the Dutch Ministry of Justice and Security), analysed Shodan data from 2018 covering 39 industrial protocols. The report was sent to the Dutch House of Representatives in September 2019.

Finding Number
Dutch IP systems in Shodan just over 3 million
Classified as ICS/SCADA 989
Of which made by Tridium (Niagara, mostly building management) 557
With one or more known vulnerabilities 63
Of which remotely exploitable 60

The researchers stress that these figures are lower bounds: they only looked at IPv4, default ports and known vulnerabilities. At the same time, they did not know what each device was used for, and some may have been test or research set-ups. Even so, each of those systems could in principle control a pumping station, an HVAC installation or a production line. A snapshot also ages quickly: every new 4G router or forgotten port forwarding rule adds another device.


⚠️ Which incidents started with an exposed controller?

The best-known recent example is the campaign by CyberAv3ngers, a group linked to Iran’s Islamic Revolutionary Guard Corps. From late November 2023 they attacked Unitronics Vision PLCs with integrated HMIs, targeting them because the equipment is made in Israel. According to the US agency CISA, at least 75 devices were compromised between November 2023 and January 2024, at least 34 of them in the US water and wastewater sector.

At the Municipal Water Authority of Aliquippa in Pennsylvania, a propaganda message appeared on the screen of a booster station on 25 November 2023. The utility switched to manual operation and drinking water was never at risk. The attackers needed no sophisticated exploit: the PLCs were reachable from the internet on the default port TCP 20256 and used the default password or no password at all.


🧱 Why do PLCs and HMIs end up on the internet?

  • Vendor access β€” a machine builder wants to provide support remotely and has a port opened instead of using a secure remote access solution
  • 4G routers β€” a stand-alone mobile router in the control cabinet gets a public IP address and bypasses the corporate firewall entirely
  • Port forwarding and NAT β€” a temporary rule for testing stays in place long after commissioning
  • Default passwords β€” factory settings are never changed, or security is switched off altogether
  • Web servers and VNC on panels β€” built-in web interfaces and screen sharing on HMIs are meant for convenience, not for the open internet
  • No overview β€” without an up-to-date asset inventory, nobody knows the device is there

πŸ”§ How do you check whether your OT is exposed?

  1. Map your public IP ranges β€” ask your provider and IT department for every address block, including those of 4G subscriptions and branch sites.
  2. Look yourself up β€” search Shodan and Censys for your ranges (for example net: followed by the address block) and for your company name.
  3. Commission an external scan β€” an outside-in vulnerability scan or penetration test shows which ports are actually open.
  4. Switch on continuous monitoring β€” Shodan Monitor alerts you as soon as a new port or service appears on your ranges.
  5. Act on notifications β€” the Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer-run non-profit founded in 2019, scans the internet for vulnerable systems and warns owners, sometimes via their internet provider. Take such a warning seriously; it follows the principle of responsible disclosure.
  6. Record and repeat β€” make the check part of your regular vulnerability management and of the risk management duties that NIS2 places on essential and important entities.

Mind the legal side: looking up and scanning your own addresses is fine, but intentionally accessing someone else’s system without permission is a criminal offence in the Netherlands (computer intrusion, Article 138ab of the Dutch Criminal Code) and across the EU, even when no password is set.


πŸ” How do you prevent your PLC from being on the internet?

Measure What it solves
Remove from the internet No PLC, RTU or HMI belongs directly on the internet; close ports and remove port forwarding
Secure remote access VPN or a jump server in the DMZ, with connections that are only opened on request
MFA A stolen or guessed password is not enough to get in
Change default passwords Blocks the simplest attack path, as seen in the Unitronics attacks
Segmentation Zones and conduits according to IEC 62443 limit the damage if something is reachable after all
Policy for 4G routers Only managed routers, recorded in the inventory and approved by security

Write these requirements into your contracts with machine builders and system integrators as well: exposure usually arises during commissioning or maintenance, when someone needs quick remote access, not at the design stage.


❓ Frequently asked questions

What should I do if my PLC shows up on Shodan?

If your PLC shows up on Shodan, first close the port or port forwarding rule involved and move remote access to a VPN or jump server with MFA. Then check that the program and passwords in the controller still match your latest backup. Shodan refreshes its data periodically, so the listing only disappears after a new scan.

Shodan is legal: the search engine only collects information that devices themselves show to anyone on the internet. Using Shodan to check your own exposure is common practice. Logging in to a system you found without the owner’s permission, however, is a criminal offence in the Netherlands and most other countries.

What is the difference between Shodan and Censys?

Shodan and Censys both scan the internet and store the responses of devices, but they differ in origin and focus. Shodan has existed since 2009 and is popular for finding industrial systems; Censys grew out of research at the University of Michigan and focuses strongly on certificates and attack surface management for organisations.

Is a cloud-connected PLC also internet-exposed OT?

A cloud-connected PLC is not internet-exposed as long as the PLC or gateway opens an outbound, encrypted connection itself and accepts no inbound connections. The risk then shifts to the cloud platform and the gateway, which need to be secured just as carefully. If the connection does open a port to the outside world, the device is exposed.

Is an OPC UA server on the internet dangerous too?

An OPC UA server on the internet is less dangerous than an open Modbus or S7 port, because OPC UA supports encryption and authentication. In practice, however, anonymous access or the security mode β€œNone” is often enabled. An OPC UA server therefore also belongs behind a DMZ or VPN.

How do I know whether an exposed controller has already been attacked?

You can tell that an exposed controller has been misused from unexpected program changes, changed passwords, unknown connections in firewall logs or unusual process displays. Compare the program in the PLC with the latest backup. If in doubt, call in your incident response team or a specialist OT security firm.


πŸ“Œ In summary

Internet-exposed OT means controllers can be reached directly from the internet, and search engines such as Shodan make them quickly discoverable to anyone. The 2023 Unitronics attacks show that attackers need no sophisticated tools. Take OT off the internet, route remote access through a VPN with MFA, change default passwords and monitor your public IP ranges continuously.