WarBrief Live | October 6, 2026 | Cyber Intelligence
Power plants, water treatment facilities, hospitals, and railway systems all share one modern habit: their control systems increasingly touch the public internet. That connection is rarely intentional. A technician sets up remote access for a maintenance visit, a cellular modem ships with a default configuration, or an old control panel is plugged into a network that routes to the outside world. From that moment on, anyone on the internet — including an attacker — can see it. Censys critical infrastructure research has become one of the clearest lenses into this hidden exposure, because the company’s internet-wide scans can see every reachable device, whether its owner knows about it or not.
What makes this more than an IT hygiene problem is the physical stakes. These are not office laptops. They are programmable logic controllers (PLCs) that open and close valves, substation switches that move electricity, and human-machine interfaces (HMIs) that let operators run an entire plant from a screen. When such devices face the internet without protection, the risk is not a data leak. It is disrupted water, dark hospitals, or a grid that misbehaves. This guide explains how defenders use internet scan data to find exposed infrastructure before attackers do, and how responsible disclosure turns those findings into fixes.
Key Takeaways
- Censys research has repeatedly documented thousands of internet-exposed industrial control devices — from 149 exposed Unitronics PLCs to 5,219 Rockwell/Allen-Bradley hosts and roughly 400 exposed water-sector HMIs.
- Exposure, not software flaws, is usually the root cause of critical-infrastructure incidents: attackers connect to reachable devices with legitimate tools and weak credentials rather than exploiting zero-days.
- About 70 percent of internet-exposed industrial hosts sit on consumer and mobile networks, which makes finding the actual owner — and notifying them — much harder.
- Internet scan data helps defenders discover their own unknown exposure; when Censys partnered with the U.S. EPA, more than 96 percent of exposed water-facility systems were secured.
What makes internet-exposed critical infrastructure so dangerous?
Critical infrastructure runs on two worlds that were never supposed to meet. On one side is operational technology (OT): the PLCs, sensors, and SCADA systems that physically operate pumps, breakers, and conveyor lines. On the other is the internet, built for open connectivity. When the two collide, the results can be severe.
Attackers do not need to break encryption or discover exotic vulnerabilities. In 2023, Iranian-backed hackers known as the Cyber Av3ngers defaced a Unitronics PLC display at a Pennsylvania water facility; the devices were publicly reachable with default passwords. In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert describing a significant increase in threat actors targeting PLCs in the water and wastewater sector — actors who were changing passwords to lock out operators and altering device IP addresses to disconnect controllers, with real consequences including boil water notices and forced manual operation of plants.
The pattern is consistent across incidents: an internet-reachable device, weak or default authentication, and an attacker using the device’s own normal functions. This is sometimes called “living off the land” — using legitimate engineering software to interact with controllers so the activity blends in with routine maintenance. Censys researchers documented exactly this behavior in 2026, noting Iranian-affiliated actors accessing internet-exposed Rockwell PLCs with the vendor’s own engineering software to manipulate project files and display data.
For a deeper look at how internet scanning finds these devices in the first place, see how internet-wide scan data powers security research. The Cyber Warfare Research: Using Internet Scan Data (2026) article in this series also covers research methods for cyber warfare analysis, where the same scan data plays a different role.
What does Censys critical infrastructure research actually show?
Censys, founded in 2013 in Ann Arbor, Michigan, continuously scans the public internet and publishes much of what it finds through its research team, Censys ARC. Over several years, that research has built one of the most detailed public pictures of industrial exposure. The findings span multiple sectors.
Energy
Industrial protocols from Siemens, Rockwell, and others are used across power generation and distribution. In a controlled experiment, Censys ran a honeypot pretending to be an industrial controller and left four industrial protocols exposed to the open internet between November 23 and December 1, 2025. In just nine days, it logged 764 interactions from 188 unique source IP addresses. Siemens S7comm accounted for more than half of all traffic, while the dangerous payloads arrived over Modbus. Crucially, about one in four sources showed ICS protocol awareness — meaning the scanning was intentional, not random internet noise.
Water and wastewater
Water systems have become the most documented example of exposure. In February 2024, Censys found 149 internet-accessible Unitronics devices with exposed remote-access protocols and web control panels. Later that year, the company identified around 430 exposed HMIs, 94 of them associated with water and wastewater facilities — and roughly half of the water-specific HMIs could be manipulated without any authentication at all. The findings reached the U.S. Environmental Protection Agency, which worked with Censys on a nationwide effort; the collaboration ultimately secured more than 96 percent of the exposed systems.
Healthcare
Hospitals and health systems rely on a mix of clinical devices and building automation — HVAC, access control, medical gas systems — that increasingly connects to networks. As Errol Weiss, chief security officer at Health-ISAC, put it when commenting on Censys’s research program:
“The global health sector faces unique risks, particularly from exposed medical devices, clinical systems, and operational technology that directly impact patient safety. Censys ARC research helps the healthcare community better understand device and system exposures, reduce risk, and strengthen resilience across hospitals, health systems, and medical device environments worldwide.”
Transportation and telecommunications
One of the most surprising findings cuts across all sectors: roughly 70 percent of internet-exposed industrial hosts sit on consumer and mobile networks, according to early findings from the 2026 Censys State of the Internet Report. Field-deployed devices — in pumping stations, substations, and water facilities — often connect through cellular carriers because no wired connection is available. The side effect is an “exposure notification gap”: the device’s registration data points back to the telecom provider, not to the utility that actually operates it, so even finding the right owner to warn is difficult. The report puts the global count of internet-exposed industrial hosts at approximately 138,000.

How do defenders use scan data to monitor their own exposure?
For security teams, internet scan data works like a satellite view of their own perimeter. Instead of relying on internal inventories — which often miss undocumented cellular modems installed by vendors or contractors, a blind spot CISA specifically flagged in 2026 — defenders can search the public internet for devices that carry their organization’s fingerprints: IP ranges, certificates, vendor signatures, and industrial protocol banners.
The standard defensive workflow is straightforward. First, inventory: identify every externally reachable asset that could plausibly belong to your organization, including shadow equipment nobody documented. Second, assess: determine whether a device speaks an industrial protocol, presents an unauthenticated management panel, or runs outdated software. Third, remediate: remove the device from the public internet, move remote access behind a VPN with multi-factor authentication, change default credentials, and disable unused services such as Telnet, FTP, or VNC. CISA’s July 2026 water-sector alert ordered essentially this sequence, urging operators to remove PLCs and other OT from the internet as soon as possible.
There is also value in watching exposure over time. Censys revisited four device families of interest to Iranian actors — Unitronics Vision PLCs, Orpak SiteOmat, Red Lion equipment, and the Tridium Niagara framework — in March 2026 and found that every category had reduced its global exposure since June 2025, with Orpak SiteOmat dropping nearly 31 percent. Repeated measurement lets defenders, regulators, and vendors see whether awareness campaigns and advisories are actually working. This connects directly to our analysis of exposed infrastructure during conflict, and to the Why Internet Intelligence Matters for Military Cybersecurity piece on military and government cybersecurity, where national-scale scanning plays a strategic role.
“You can’t defend what you can’t see, and Censys is providing critical infrastructure operators visibility into their exposed assets. Censys’ focus on operational technology is strengthening the resilience of our most vital systems.” — Laura Galante, former director of the U.S. Cyber Threat Intelligence Integration Center
How does responsible disclosure work when exposures are found?
Publishing aggregate statistics is one thing; handing someone a list of their exposed devices is another. Responsible disclosure norms govern that second step, and the water-sector case is the textbook example. Censys researchers first tried to notify the facility hosts directly, received what they described as a lukewarm response, and then brought the findings to the EPA, which had the authority and the mission to drive remediation across the sector.
The process generally follows a few principles. Researchers aggregate and anonymize: public reports describe the scale and the device types, not the IP addresses of specific facilities. They notify owners or relevant authorities privately first and give them time to remediate. They avoid testing credentials or interacting with live control systems — measurement stays passive. And they coordinate with sector regulators, such as the EPA for water or the Department of Energy for power, when the exposure is systemic rather than a single misconfigured device.
There is a hard ethical line that legitimate research observes: scan data shows that a device is reachable; it does not authorize anyone to log in to it. The defensive value comes from notifying the owner and publishing the trend, not from demonstrating control. The How Internet Intelligence Helps Investigate Cyber Attacks article in this series covers how investigators use this same data responsibly when tracing cyber attacks, and the Tracking Adversary Infrastructure With Censys Data piece explains how adversary infrastructure is mapped through public scanning.
Readers new to the platform behind this research can start with our explainer on what Censys Inspect is and the CensysInspect Explained: Internet Intelligence Guide article in this cluster.

Frequently asked questions
What is the difference between IT and OT security?
IT security protects information systems such as email, databases, and office networks. OT security protects operational technology — the industrial control systems that operate physical processes like water treatment, power distribution, and manufacturing. OT security prioritizes safety and continuous operation, and its worst-case incidents cause physical harm rather than data theft.
Why are industrial control systems visible on the public internet at all?
Almost never on purpose. Common causes include remote-access setups left open after maintenance, cellular modems with default configurations, vendors or integrators installing undocumented connectivity, and legacy equipment that predates modern network security practices.
Can internet scanning of critical infrastructure be used maliciously?
Internet-wide scan data is dual-use: the same visibility that helps defenders find their own exposed devices can also show attackers where to look. That is why legitimate research organizations publish only aggregate findings, withhold specific target details, and notify owners or regulators before going public — and why security teams should find their own exposure first.
What should a critical infrastructure operator do if they discover an exposed device?
Remove it from the public internet immediately, or place remote access behind a VPN with multi-factor authentication. Then change any default credentials, disable unused services, back up the device’s configuration, and check logs for signs of unauthorized access. U.S. operators can also consult CISA guidance and their sector’s information-sharing body.
Has measurement of exposed infrastructure actually reduced risk?
Yes. The Censys–EPA collaboration on exposed water-sector HMIs resulted in more than 96 percent of the identified systems being secured, and repeat Censys measurements in 2026 showed declining global exposure across several previously targeted industrial device families.
Conclusion
The uncomfortable truth of Censys critical infrastructure research is that the most dangerous cyber risk to power plants, water systems, and hospitals is not a sophisticated zero-day. It is a reachable device. Year after year, internet-wide scans keep finding industrial controllers, HMIs, and field equipment sitting on the public internet — sometimes with no authentication at all — while attackers, from opportunistic scanners to nation-state actors, probe the same ports with increasing sophistication.
The defensive playbook is correspondingly simple, if not easy: know what is reachable, remove what should not be, authenticate and monitor the rest, and keep measuring. Scan data gives every defender the same vantage point attackers already have. Used responsibly — with private notification, regulator coordination, and public reporting that informs rather than endangers — it has already taken hundreds of exposed systems offline. The next wave of exposure will be quieter, hidden on mobile networks and behind contractor-installed modems. Finding it first is the whole game.
Sources and Further Reading
- Censys — “Who’s Knocking on Your PLC? A Honeypot View of Internet-Wide Interest in ICS/OT Protocols”
- Censys — “ICS & Iran, Part 2: Revisiting Exposure of Previously Targeted Devices”
- IT Brew — “A cybersecurity firm uncovered hundreds of exposed national water facilities”
- eSecurity Planet — early findings from the 2026 Censys State of the Internet Report
- Help Net Security — “Censys ICS/OT solution closes visibility gaps and secures exposed industrial systems”
- Industrial Cyber — “Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks”