CiberLATAMbywhalemate

LatAm Tightens OT Defenses Amid Industrial Risk

Shieldworkz, the IDB and Cryptonomist warn of growing pressure on OT/ICS in water, energy and manufacturing, with exposure in focus.

Whalemate Labs · AI-assisted researchAug 1, 20262 min read

Shieldworkz says Iranian-linked actors are exploiting exposed PLCs, HMIs, SCADA systems and remote field communications across water, energy, health and manufacturing.

OT Exposure in Water, Energy and Manufacturing

A technical analysis from Shieldworkz on Iranian campaigns against OT/ICS describes a pattern of exploitation targeting PLCs, HMIs, SCADA systems and remote field communications exposed to the internet. The scope includes water and wastewater, energy, government facilities, health care and manufacturing.

The report recommends removing any direct exposure of PLCs, RTUs and HMIs to the public network. It also advises auditing IP ranges with tools such as Shodan and Censys to confirm that no OT ports remain open, including 44818, 502, 102, 2222, 20256 and 22.

Prepositioning and Industrial Legacy

Shieldworkz expands on that assessment in its Americas OT/ICS & SCADA Cybersecurity report, which adds context on the rise in incidents across manufacturing, energy, oil and gas, transportation and water utilities. The report documents prepositioning operations in OT environments tied to energy, water and telecommunications in North America, attributed to groups such as Volt Typhoon, Sandworm and actors linked to the IRGC.

The same report says the Ransomware as a Service model is already deploying operators with knowledge of PLC logic and SCADA architecture. It also warns that legacy ICS exposure with Modbus, DNP3 and BACnet ports left without authentication is critical, and identifies the United States as the country with the largest number of ICS ports accessible from the internet.

Less Time Between IT and OT

To that picture, a Cryptonomist analysis adds recommendations from Dragos on AI-assisted attacks. The piece says these attacks are compressing the time between the compromise of IT networks and the attempted intrusion into OT.

The result, according to that material, is that defenses based only on prevention are no longer enough. For critical infrastructure, the recommendation is to pair firewalls, segmentation and patching with OT-specific visibility and detection capabilities for internal control traffic, in line with SANS's Five Critical Controls for ICS.

Governance and Regional Risk

In Latin America, the IDB guide for boards on cyber risk management in OT environments provides a regional governance framework. The document says the digitalization of energy, water, transportation and manufacturing has increased OT risk exposure, and that boards need to incorporate specific cyber-physical risk metrics, operational disruption scenarios and clear responsibilities for ICS security.

The guide aligns with the emergence of regulatory frameworks such as those defining operators of vital infrastructure in countries across the region. At the same time, a NextGuard Insurance technical note on cyber insurance for data centers in Latin America says these operators concentrate critical OT infrastructure, from cooling and power to humidity and fire suppression, so a compromise can escalate into massive cyber-physical impacts affecting hundreds of companies at once.

NextGuard recommends that policies include explicit coverage for attacks on OT/ICS systems, a sign that the regional insurance market is already factoring in the growing industrial and critical-infrastructure risk tied to OT.

Sources

View all