Your SCADA System Was Not Designed to Be on the Internet. It Is Now. [2026]

SIGNAL VS. NOISE · CONNECTED OPERATIONS SERIES
Your SCADA System Was Not Designed to Be on the Internet. It Is Now.
2,155 ICS vulnerabilities in 2025. 40% of OT devices insecurely connected to the internet. Ransomware in manufacturing up 56% year over year. The industrial security crisis is documented and unaddressed — and it is creating a subspecialty of information security that pays more and has half the competition.

In December 2025, a malicious actor gained access to Poland’s energy sector — specifically renewable energy plants, a combined heat and power plant, and a manufacturing company — through vulnerable internet-facing edge devices. They deployed wiper malware. They damaged remote terminal units. CISA issued an alert in February 2026 naming the attack vector: internet-exposed OT and ICS systems. The same attack vector documented in 2016 with the Ukraine power grid. The same one documented in 2021 with the Florida water treatment plant. Still exploited in 2025 because the systems are still exposed.

That pattern — the same vulnerability, exploited again, because nothing structurally changed — is the whole story of OT cybersecurity. And it creates one of the most specific and under-filled specializations in information security.

The Receipts

2025 was a record year for ICS vulnerabilities. Forescout Technologies documented 508 advisories covering 2,155 vulnerabilities in industrial control systems — the highest volume since tracking began. The most affected assets were Purdue Level 1 devices: field controllers, RTUs, PLCs. The devices that, when compromised, do not produce a data breach. They produce a production shutdown, a safety incident, or physical damage to infrastructure.

The exposure is documented and widespread. Claroty analyzed a representative sample of OT devices and found that 12% contained known exploited vulnerabilities, 7% had vulnerabilities specifically linked to ransomware campaigns, and — the number that stops conversations — 40% of organizations had those assets insecurely connected to the internet. Not air-gapped. Not segmented. Connected. The remediation has not followed the connectivity.

Attacks are scaling alongside the exposure. More than 12,000 cybersecurity incidents related to industrial control systems were reported in 2024 — a 49% increase in attacks by state-aligned adversaries on energy, transport, and water sectors (Industrial Cyber, March 2026). Manufacturing is now the most targeted sector for ransomware, with attacks rising 56% year over year (OPSWAT, via IIoT World). Dragos tracked 49 oil and gas ransomware incidents and 31 electric sector incidents in a single quarter — Q4 2025. And Shieldworkz reported that 28% of OT reconnaissance activity in 2025 carried an AI signal: adversaries are automating their enumeration of industrial targets.

The OT security market reflects the urgency. The market for securing operational technology systems was valued at $27 billion in 2025 and is projected to reach $122 billion by 2034 (Industrial Cyber). That is not a vendor projection inflated by hope. That is the insurance premium on a recognized and escalating risk that industry has accepted it must address.

Why IT Security Cannot Fix an OT Problem

The standard IT security playbook assumes several things that are untrue in an OT environment: that systems can be patched on a regular cycle, that endpoints can run security agents, that rebooting a device to apply an update is an acceptable operational response, and that a system outage is primarily a business continuity problem rather than a safety or physical-damage event.

OT systems assume none of those things. A PLC on a manufacturing line may run for 20 years without a firmware update — not because the operator is negligent, but because the update process requires taking the line down and validating every process that depends on it, which is measured in days of production loss, not hours of IT downtime. A SCADA system governing a water treatment plant cannot accept an endpoint security agent that consumes CPU cycles the system was not sized to spare. A safety instrumented system (SIS) — the last line of defense against a physical industrial accident — is designed to fail safe, not fail secure; applying IT security principles to it without understanding that distinction is how you turn a cyber incident into a physical one.

The adversaries who attacked Poland’s energy infrastructure understood this. Shieldworkz documented in its 2026 threat report that advanced actors “understood Modbus” and “knew how Purdue model boundaries worked, and exactly where those boundaries had been left unguarded.” The defender gap is not awareness of the threat. It is the absence of people trained specifically for the environment where the threat operates.

What This Means for an Information Security Career

The Information Security Analyst blueprint on this site documents a 29% BLS growth projection, a median of $124,910, and three doors in. OT cybersecurity is not a separate career — it is the subspecialty at the top of that field with three distinguishing features:

It pays a premium. The OT security market is growing at roughly 4.5x the rate of the general IT security market. Demand is being driven by regulatory mandates (NERC CIP for energy, IEC 62443 broadly, NIS2 in Europe) that require dedicated OT security programs — not just IT security teams with an OT annex. Postings specifically requiring OT/ICS security experience consistently clear $100K–$130K at the analyst level; senior and principal roles run $130K–$185K+.

The competition is thin. Every ICS security report published in 2025–2026 names the talent shortage as the primary barrier to remediation. The people who understand both the IT security toolkit (SIEM, vulnerability management, incident response) and the OT environment (Modbus, PROFINET, PLC ladder logic, SCADA architecture, the Purdue model) are assembled from career changers who happened to work at the intersection, not from a formal training pipeline that produces them at scale. The ISA/IEC 62443 certification exists but the number of people who hold it remains small relative to demand.

The entry path is clear. An information security analyst who adds OT-specific knowledge — the Purdue model, the zone-and-conduit segmentation approach from IEC 62443, the industrial protocol basics that the OT/IIoT Network Technician blueprint covers — and pursues the ISA/IEC 62443 Cybersecurity Fundamentals certificate is building toward the OT security specialization from a credential base they already hold. The CISA + CISSP background that an experienced InfoSec analyst brings is the right foundation; the OT layer is the add, not the replacement.

The Career Geography

SeatAnchor BlueprintOT AddPremium
Information Security AnalystInfoSec Analyst blueprintBLS median $124,910
OT Cybersecurity AnalystInfoSec Analyst + OT knowledgeISA/IEC 62443 Fundamentals; Purdue model; industrial protocol basics; SCADA/ICS architecture$100K–$130K analyst; $130K–$185K+ senior
ICS Security ArchitectOT Analyst + architecture scopeFull zone design; NERC CIP / NIS2 compliance program ownership; incident response for OT environments$150K–$225K+; cleared roles higher
THE SCOT FREE TAKE

The Florida water treatment plant incident was 2021. An operator noticed a remote actor increasing the sodium hydroxide level to potentially toxic concentrations and caught it manually. The entire cyber kill chain had been executed against a public water utility’s SCADA system because the remote access software required nothing more than a shared password.

That was five years ago. The 2025 report card, per Forescout, is 2,155 ICS vulnerabilities in a single year — a record. Per Claroty, 40% of industrial organizations have OT assets with known exploitable vulnerabilities connected to the internet. The improvement has not tracked the awareness. The awareness is near-universal. The remediation is not.

The gap between knowing the problem and being able to fix it is a talent gap. Every operator in scope for NERC CIP or IEC 62443 is required to have an OT security program. Most of them are assembling that program from IT security staff who do not understand industrial protocols and OT engineers who do not understand cybersecurity. The hybrid — the analyst who understands both — is what the mandate demands and what the labor market has not yet produced at scale.

The information security career is a 29% growth field. The OT subspecialty of that field is a regulatory mandate with a $122 billion market behind it and a talent shortage that nobody has formally trained their way out of yet. The SCADA system is already on the internet. The question is who is going to protect it.

Where to Start

  • Read the Information Security Analyst blueprint — the SOC 15-1212 career with three doors in, median $124,910, and a 29% BLS growth projection. That is the foundation the OT specialization is built on.
  • Then read the OT/IIoT Network Technician blueprint for the industrial protocol vocabulary that distinguishes an OT security analyst from an IT analyst who rotated into an OT role.
  • The ISA/IEC 62443 Cybersecurity Fundamentals certificate is the credential that signals OT-specific competence to a hiring manager in manufacturing, energy, utilities, or critical infrastructure. It is the add, not the replacement, for a CISA or Security+ holder.

Sources

CISA, "Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps," February 10, 2026 (December 2025 incident; internet-facing edge device attack vector; RTU damage) · Forescout Technologies, ICS cybersecurity research, February 2026 (508 advisories, 2,155 vulnerabilities; record high; Purdue Level 1 most affected) · Claroty OT device analysis (12% KEVs; 7% ransomware-linked KEVs; 40% insecurely connected to internet) · Industrial Cyber, "Rising ICS incidents drive shift from reactive risk models," March 2026 (12,000+ ICS incidents 2024; 49% state-aligned adversary increase; 80% manufacturers reported increase post IT/OT integration; OT security market $27.03B 2025 → $122.22B 2034) · Dragos OT Cybersecurity Year in Review 2026 (Q4 2025: 49 oil/gas incidents, 31 electric incidents) · DeepStrike, "Energy and Utilities Cybersecurity Statistics 2026" (Claroty and Dragos data; FBI IC3 energy sector complaints) · OPSWAT / IIoT World, manufacturing ransomware +56% YoY · Shieldworkz, OT Cybersecurity Threat Landscape Analysis Report 2026 (28% of 2025 OT reconnaissance carried AI signal; adversaries understood Modbus and Purdue model boundaries) · IIoT World, "OT Cybersecurity for Manufacturers: 2026 Guide" (IT vs OT security priorities; patching constraints).

The career that protects the grid starts with the blueprint.
The Information Security Analyst blueprint maps the SOC code, the salary stack, and the three doors in. The OT specialization this piece describes is the premium lane above it — built on the same credential foundation.
READ THE INFOSEC ANALYST BLUEPRINT →
Knock twice. Tell them Scot Free sent you.
Previous
Previous

You Can’t AI a Physical Connection: The Labor Shortage Nobody Is Talking About Is Not the One You Think [2026]

Next
Next

The ATS Shredder: You’re Not Getting Ghosted. You’re Getting Processed.