It is 11:40 on a Tuesday night and line 3 is down. The controls engineer lives ninety minutes away. The OEM's support tech in another state needs to see the drive fault himself, so someone walks out to the panel, plugs the cellular modem back in, and reads him the number off the label.
He connects. He clears the fault. The line runs by midnight and the order ships on time.
Nobody unplugs the modem.
Three years later it is still there. It is not on the network diagram. It is not in the asset inventory. The integrator who installed it has been acquired. The engineer who read the number off the label works somewhere else now.
Underneath that night is a belief most plants run on without saying out loud.
Security is something you add to operational technology after it is running.
The machine comes first. It proves itself on the floor. Then someday, when there is budget and a slower quarter, someone comes back and secures it. Security as a project. A thing you bolt on.
It used to be true, and every incentive pointed that way.
Only the third has changed. The gap the other two leave has a familiar sound. IT says it is the machine. The vendor says it is the network. The line is down and somebody is standing in the middle with no answer.
The connection did not arrive in one decision. It arrived in a hundred small reasonable ones.
Each was right in the moment. The result is a plant floor built to be isolated that is now reachable, and no one decided that.
It started with water utilities. Since late July, utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded operations.
Now read what the FBI, EPA, and CISA published, and notice what is not in it.
No zero day. No custom malware. The joint advisory states it directly: it is not highlighting a new vulnerability. It is describing opportunistic targeting.
What is in it:
Read that last one twice. Your exposure may not be a decision you made. It may be a build standard you inherited.
They did not break the PLC. They logged into it.
But We Have a VPN Gateway
Most manufacturers reading this are ahead of a small municipal utility. There is a real gateway at the edge with multifactor authentication on it. That is the right control, and the advisory recommends exactly that. It is also not the same thing as knowing what happens after someone is through it.
Look at how the agencies wrote it. A gateway in front of the PLC is one mitigation. Access control lists, so only expected control devices can talk to each other, is a separate one. They are listed apart because they do different jobs.
A gateway answers who gets in. An ACL answers what they can reach.
If the tunnel lands on a flat controls network, the OEM who came to look at one drive fault can see every controller on the floor. The gateway did its job. The specification never said where the job ended.
When a controller is compromised, the failure does not look like a data breach. It looks like a production event.
The shift. The operator loses the HMI. The credentials stop working. The line goes manual or it goes down.
The program. Then the harder question. Who has the last known good project file? Not the department. The person. On most floors the honest answer is the integrator, and on too many floors that integrator no longer exists under the same name. Federal guidance now tells operators to compare the running program against known good logic. You cannot run that check without a copy you trust.
The instrumentation. In one case the FBI found a downloaded project file that left the downstream ladder logic intact while adding logic that overrode the instructions holding safe operating parameters. Shutdown and alarm logic went dead, and the operator displays were altered to match. Equipment ran outside safe conditions and the screen said everything was fine.
The paperwork. Everything produced during the window is suspect. Batch records do not reconcile. Your customer's supplier quality group asks what changed, and the honest answer is that something did and you did not authorize it. Now you are writing a corrective action and facing requalification on a process nobody meant to touch.
The line stop is one shift. The paperwork is one quarter.
Here is the sentence that should end the argument.
The advisory says plainly that it is not highlighting a new vulnerability in these products. Seven federal agencies looked at disrupted infrastructure and found no flaw to patch. They found equipment installed in a way that made the attack unnecessary.
There is no upgrade for that. There is only how it was specified.
The government has now said as much. The advisory points owners to a guide called Secure by Demand, built to help OT owners put security requirements into the selection of digital products. Not after go-live. At selection.
That is an RFQ document with a federal seal on it.
A specification sits on the RFQ next to cycle time and spare parts. It answers four questions:
An upgrade is what you fund after the fact, if there is money left, which there rarely is.
Specified means it arrives correct. Bolted on means undoing four years of reasonable decisions with the line running.
The practical test fits on one line.
If it connects, it is in scope.
Not if it is critical. Not if it is new. If it has a path, it belongs in the inventory, in the segmentation plan, and in the next specification.
At InsITe we start by mapping what is actually connected, not what the diagram claims, because those two are almost never the same. We put the controls team and the IT team in one room to decide what each asset is allowed to reach, so there is one team and one call when something breaks at the boundary. Then we write those decisions into the specification for the next machine, before it ships. We stay after go-live, because a specification nobody maintains is just a document.
If your largest OEM lost remote access tomorrow morning, how long would it take you to notice?
Who holds the current program for your most constrained line? Name the person, not the department.
When your OEM comes through the gateway to look at one machine, what else can they see?
The utilities that got hit were not careless. Their equipment became connected faster than their specifications did.
Manufacturing is on the same curve, with the same controllers, and more of them.
You cannot bolt on what you never specified.
Security is a specification, not an upgrade.