EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingMedium

A security auditor is performing a penetration test on an industrial control system (ICS) environment. They discover several programmable logic controllers (PLCs) that are directly accessible from the internet without any firewall protection. Which of the following is the most immediate and critical concern regarding these exposed PLCs?

  1. ACompliance violations related to data privacy regulations.
  2. BPotential for unauthorized modification of control logic.
  3. CIncreased risk of phishing attacks on operational staff.
  4. DHigher bandwidth consumption due to external probes.
Show answer & explanation

Correct answer: B. Potential for unauthorized modification of control logic.

Direct internet exposure of PLCs, which control physical processes, presents an immediate and critical risk of unauthorized modification of their control logic. This could lead to severe physical damage, operational disruption, or safety hazards, far outweighing other concerns.

Why the other options are wrong

  • A. While compliance is important, data privacy is typically not the primary concern for PLCs, which manage industrial processes, not personal data.
  • C. Phishing attacks are a concern for any network but are not the most immediate critical risk directly stemming from exposed PLCs.
  • D. Higher bandwidth consumption is a minor technical issue compared to the catastrophic potential of direct PLC compromise.

OT Direct Internet Exposure

Operational Technology (OT) devices, such as PLCs, directly connected to the public internet without protective firewalls or segmentation.

  • Creates a direct attack path for remote adversaries.
  • Bypasses traditional network perimeter defenses.
  • Can lead to physical damage, safety incidents, and production halts.

Memory trick: Exposed OT means direct control over the factory's heart.

More Mobile Platform, IoT, and OT Hacking questions