Researchers have observed a significant rise in the number of industrial control system (ICS) devices exposed to the internet, with the count increasing from approximately 160,000 at the start of 2024 to over 180,000 by the end of the year, and projections suggesting this figure could surpass 200,000 by the end of 2025. This trend has been highlighted by security firm Bitsight, which noted not only the growing number of exposed devices but also an uptick in operational technology (OT)-specific vulnerabilities. These vulnerabilities include remote code execution flaws, logic errors, and broken web authentication, some of which carry the highest possible severity ratings and offer attackers trivial exploit paths. The increase in exposed ICS/OT assets is attributed to the deployment of new devices with internet access, often configured with outdated or insecure protocols, minimal authentication, and insufficient network segmentation. This mismanagement of ICS/OT assets points to a broader issue in how organizations are securing critical infrastructure. The vulnerabilities present in these systems could allow attackers to disrupt essential services, manipulate industrial processes, or gain unauthorized access to sensitive environments. Security experts have warned that the lack of proper segmentation and the use of insecure protocols make these devices attractive targets for both cybercriminals and nation-state actors. The exposure of ICS devices is particularly concerning given their role in critical infrastructure sectors such as energy, water, and transportation. The U.S. government and cybersecurity agencies have issued advisories and called for improved security practices, including regular vulnerability assessments, implementation of strong authentication mechanisms, and network segmentation to reduce the attack surface. The growing attack surface created by these exposed devices increases the risk of large-scale cyberattacks that could have significant operational and safety impacts. Organizations are urged to prioritize the security of their ICS/OT environments by adopting best practices and leveraging available guidance from agencies such as CISA. The trend underscores the urgent need for a coordinated approach to securing critical infrastructure against evolving cyber threats. Failure to address these issues could result in severe disruptions to essential services and pose risks to public safety. The situation is further complicated by the rapid adoption of new technologies in industrial environments, which often outpaces the implementation of adequate security controls. As the number of internet-exposed ICS devices continues to rise, the potential for exploitation by malicious actors grows, making it imperative for organizations to act swiftly to mitigate these risks. The findings serve as a wake-up call for both private and public sector entities responsible for the security of critical infrastructure. Proactive measures, including continuous monitoring and timely patching of vulnerabilities, are essential to defend against the increasing threat landscape targeting ICS/OT systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that researchers observed an increase in internet-exposed industrial control systems devices. The reference does not provide further specifics on scope, vendors, or affected organizations.
CISA announced the release of one Industrial Control Systems advisory. No additional technical details or affected products are provided in the reference.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.