H2 Innovations
Insights
Industrial Security Note · August 2026

Nobody meant to leave a way in.Two federal advisories found one anyway.

Nobody sits down and decides to connect the equipment that runs a plant to the open internet. It happens the way most things happen at a working site. A supplier needed to see a machine during commissioning. A remote pump station got its own cellular connection so nobody would have to drive out to it at two in the morning. Somebody opened a path on a Friday so the weekend would go smoothly, and it worked, so it stayed.

This summer two federal advisories went looking, and they found what all those reasonable decisions add up to. In July the warning was about water and wastewater plants. On August 19 a second one arrived from five federal agencies at once, and it was not about water. It named six industries.

I have written about this boundary before, and if you want more detail on that you can read it in What can reach your control layer? What is new is what the advisory actually recommends, in item three of its own list of hardening actions. This is what we have been talking about in the past, and it is good to have it reinforced by the five agencies that signed the advisory.

  • Two federal advisories have identified a major gap in some industries, and both came down to the same thing: the controller could be reached from the internet.

  • The attackers did not need a clever new trick, because AI wrote the tools for them, so being old or obscure stopped being any protection at all.

  • Your readings still have to leave the plant, and the advisory itself points at one-way paths out as the way to do that without leaving a door open.

01 · The gap

The gap both advisories found

A controller is the small, rugged computer that actually runs a piece of your plant. It opens the valve, starts the pump, holds the sequence, and it does that same job for twenty or thirty years without anybody thinking about it. That is the thing both advisories are about.

The July warning went to water and wastewater utilities, and I wrote about that week in After the disconnect. The August one is wider. On August 19 the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, the Department of Energy and the Environmental Protection Agency published a joint advisory about Siemens S7 controllers, and they listed the industries where the activity is concentrated: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Four of those are industries we work in.

Be careful how you read the brand names, because the advisories are not saying what people assume they are saying. Neither one describes a broken product. The July advisory named one manufacturer’s controllers and the August one names another’s, and in both cases the finding is the same: these are controllers that were left reachable from the internet, running old firmware or protected by a password somebody never changed. The equipment is doing exactly what it was built to do. It was simply never built to be reachable by strangers.

I would not soften what the agencies say about it either. They call it an active threat and say plainly that it is not a theoretical risk. Their assessment is that the activity so far looks like preparation, which means looking around and learning the ground rather than breaking anything yet. Both advisories describe the same gap, and it is not a broken product, it is a controller somebody outside can reach.

02 · What changed

Obscurity was the protection, and it just went away

What is new here is not the attack. The way these controllers talk has been openly documented for years, and the free software libraries for talking to them have been on the internet for about as long. What protected most plants was never a lock. It was that learning all of this took real expertise and real time, and there were easier things to go after.

That is what changed. The agencies describe attackers using AI to write their tooling for them, built on those same public libraries and dressed up to look like ordinary monitoring software so it does not stand out. The advisory is blunt about what that does: it dramatically reduces the expertise and the time needed to build working tools. The skill that used to be the barrier is now something you can ask for.

So the comfort a lot of sites have been running on quietly expired. Being old is not protection. Being unusual is not protection. Being small enough that nobody would bother is not protection, because nobody is bothering, a script is. The attackers did not need a clever new trick, because AI wrote the tools for them, so being old or obscure stopped being any protection at all.

03 · The data still leaves

The data still has to leave

What the advisories ask for is not complicated, and it is the same short list both times. Get the controller off the internet. Keep the plant network separate from the business network. Shut the way in at the firewall. Put remote access behind something that checks who is asking. None of that needs a vendor, and if you do nothing else this month, do that.

But work that list honestly and you hit a problem it does not solve. The regulator still wants their numbers. The board still wants the report. The engineer doing a capacity study still wants a year of history. Closing the way in does not make any of those go away, and this is where a lot of sites quietly stop, because the path they were using to get data out was the same path they were just told to close.

The August advisory does something about that, and it is the sentence I did not expect. In the same list where the agencies tell you to make sure controllers are not reachable from the internet, they recommend deploying one-way gateways for getting data to a historian, which is the system that keeps your history. That is their recommendation about a shape of connection, not an endorsement of any product, ours included. But it is a federal advisory saying that data leaving is a different problem from people coming in, and that the two deserve different arrangements. Your readings still have to leave the plant, and the advisory itself points at one-way paths out as the way to do that without leaving a door open.

04 · How we help

How can we help?

Let me be exact about where we fit, because it is narrower than you might expect. We do not find your exposed controllers. We do not scan for them, inventory them, or remove them. That work is yours, and the advisories tell you how to do it.

What we build is the other half of the problem, the part that is left once the way in is closed. Our Flowgate gateway moves your readings out on a connection the plant opens itself, encrypted, with nothing listening on the plant side for anyone outside to find. It holds readings while a link is down so an outage becomes late data instead of missing data, it signs people in against the directory you already run instead of another shared password, and it keeps a timestamped, hash-chained record of changes, so an entry altered after the fact is easy to spot and can be investigated.

That describes how the parts are put together, not what they withstand. It is one path and not all paths, so a remote-access door that already exists does not close because a new path opened beside it, and finding those doors is exactly the inventory work the advisories are asking of you. And because bytes move both ways once a connection exists, whether anything may ever write back into your plant is its own decision, taken and recorded separately. The full argument, along with the questions worth putting to anyone selling you a path across that boundary, is in What can reach your control layer?

05 · Sources

Sources

06 · Take with you

The three things to take with you

Both advisories describe the same gap, and it is not a broken product, it is a controller somebody outside can reach. The attackers did not need a clever new trick, because AI wrote the tools for them, so being old or obscure stopped being any protection at all. And your readings still have to leave the plant, which the advisory itself says is best done on a one-way path out.

If you want one next step this week, ask the person who would know a single question: can any of our controllers be reached from outside this building? If the answer is yes, or if it starts with somebody going to check, that can be cause for concern and investigation.

If you would rather describe your own boundary and ask us what we would do with it, write to us at info@h2innovations.ca.