OT Asset Visibility Gaps Expose Critical Infrastructure to Attacks
Attackers are exploiting internet-facing industrial controllers to disrupt water systems, highlighting a critical gap in operational technology (OT) asset visibility beyond traditional IT perimeters.

Recent attacks targeting water systems across at least seven U.S. states underscore a significant vulnerability in operational technology (OT) security. In these incidents, threat actors remotely accessed internet-facing programmable logic controllers (PLCs), leading to a loss of monitoring and control capabilities and degrading water operations. Federal investigators are actively examining potential links between these intrusions and Iran-backed hacking groups, signaling a growing concern for critical infrastructure security.
While OT security programs are designed to protect core industrial controllers, many organizations neglect the security of adjacent systems. These include building automation systems (BAS) that manage heating, cooling, and lighting, as well as devices like chillers, fire panels, badge readers, elevators, and cameras. A failure in these seemingly peripheral systems, such as a chiller malfunction, can cascade into significant operational disruptions, including taking down essential IT infrastructure like data centers.
A recent survey by Honeywell Technologies of over 600 security, risk, and operations leaders in critical infrastructure revealed a widespread lack of continuous monitoring for these "building layer" systems. Only 16% of respondents reported continuously monitoring more than three-quarters of their BAS, and a mere 20% did so for connected IoT devices like cameras and thermostats. This indicates that a substantial portion of an organization's physical infrastructure often operates outside of continuous security oversight.
The survey also highlighted a significant disconnect in asset inventory management. While 88% of organizations describe their security programs as planned or design-led, only 21% report having a complete asset inventory. This means many organizations may not even be aware of all the devices connected to their networks, including critical components like chiller controllers that maintain data center temperatures.
This lack of comprehensive asset visibility directly impacts recovery times. Organizations with a complete or substantial asset inventory were more likely to restore operations within six hours following a significant incident, compared to those with limited or no formal inventory. While the survey shows an association rather than direct causation, the logic is clear: if a device's existence is unknown, it cannot be isolated or effectively managed during an incident.
Interestingly, audit status did not strongly correlate with incident reporting. Organizations with perfect compliance audit records reported significant incidents at nearly the same rate as those with audit failures. However, organizations with clean audits were generally more confident in their recovery capabilities, likely due to practices like tested backups, documented response procedures, and clear ownership, which are often prerequisites for passing audits and are crucial for resilience.
A significant barrier to improving OT security is the prevalence of legacy equipment. Many older controllers were designed for isolated environments and utilize protocols lacking authentication or encryption. Patching these systems can be complex, often requiring planned downtime or vendor intervention, further complicating efforts to maintain a secure and up-to-date operational environment.
The findings emphasize the urgent need for organizations to extend their security perimeters beyond traditional IT assets to encompass the full spectrum of operational technology and building systems. A holistic approach to asset visibility, continuous monitoring, and robust inventory management is crucial for defending against sophisticated threats targeting critical infrastructure.