Five Agencies, One Warning, and Not a Single Number
A fox does not bolt at the first rustle in the undergrowth. It waits, ears flat, to hear which way the noise is walking. Five agencies rustled the hedgerow this week, and everyone selling into ot cybersecurity heard a warning with nothing in it to weigh.
By Katie Delaney · 2026-08-20 · 17 min read
What five agencies said, and what they left unmeasured#
quantified observations published in the five-agency advisory
On 19 August 2026 the NSA, CISA, FBI, DOE and EPA put five names to one document, advisory AA26-231A, titled Defending Against an Active Threat to Siemens S7 Series PLCs. Five authoring agencies is a serious signal on its own, and the sectors it names are the ones that hurt when they stop: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Anyone working in ot cybersecurity should read it twice, once for the threat and once for the silence.
The method is described with unusual precision. Threat actors are said to be pairing open source industrial automation libraries, snap7.dll and python-snap7, with AI-assisted scripting to build custom tools that mimic legitimate OT monitoring software. Reconnaissance runs through commercial scanning services, and the agencies name them: "Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs". The quarry is anything reachable and poorly segmented, which is a wider hedgerow than most operators enjoy admitting.
Intent is stated as an assessment rather than an observation. The authoring agencies assess the pattern is "likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects". Read that slowly, because it describes reconnaissance, capability development and pre-positioning. No plant is said to have stopped, no water system tampered with, no turbine touched. Every honest ot cybersecurity brief written this week has to hold that line, however tempting the taller headline looks.
No count, no hashes, no dates#
Here is the part the trade press skated past. The advisory carries no quantified observation of any kind: no incident count, no affected-facility count, no indicators of compromise, no hashes, no samples, no timeframe and no named actor. It also publishes no evidence that the scripts were written by AI. That claim rests entirely on government assessment, which is a perfectly legitimate thing for an agency to publish and a genuinely difficult thing for a buyer to budget against on Monday morning.
Be fair about the reasons. Agencies protect sources and methods, and a sanitised warning that arrives early beats a fully evidenced one that arrives after the damage. Even so, two of the mitigations name commercial ICS detection products by brand, which joint advisories seldom do, and those vendors will be quoting the document by Friday. A rival ot cybersecurity firm needs measured ground of its own to stand on, not a louder rendition of the same adjective. That is the same problem NIST handed security teams this morning, in a different register.
Writing exploits for OT infra used to require deep expertise. Now AI makes it dramatically easier by just using publicly available information on these PLCs for initial access, credential access, denial of service, and other objectives.
That post is the sector's mood in three sentences: plausible, urgent and unmeasured. Nobody has published a denominator. How many exploitation attempts, against how many devices, across what window, at what success rate, stays unanswered by everyone who holds the telemetry to answer it. Asking for that figure is not scepticism about the threat. It is the difference between a claim a customer can act on and a mood a customer can only absorb.
Set the alert against that disclosure surface and it looks less like a thunderclap and more like weather. The trail runs from 20 advisories in 2010 to 481 in 2025, and this year stands at 331 to 20 August, counted by binning CISA's own sitemap and cross-checked against its published advisory pager. Any ot cybersecurity vendor claiming a sudden inflection has to explain why 2021 stepped and 2013 crawled. Volume here measures what a regulator can process, which is a useful thing to know and a terrible thing to mistake for a threat count.
How many are exposed, and what ot cybersecurity can actually count#
Exposure is the one thing in this story anybody can count, and somebody did. In a snapshot dated 30 July 2026, Censys counted 4,117 internet-exposed hosts fingerprinting as Siemens SIMATIC S7-1200, precisely the family the advisory names. That is the figure an ot cybersecurity brief should open with, because it is dated, sourced, reproducible and boring in the way good evidence is always boring.
The other two bars need their footnotes carried with them. The Rockwell count covers hosts that answer EtherNet/IP and identify themselves as Rockwell Automation or Allen-Bradley. The Schneider figure is vendor-wide, with no model or protocol filter applied, and Censys says plainly it should not be read as Schneider PLC exposure. An ics security claim built on that third bar without the footnote is the kind of thing a journalist unpicks in a single email, and the correction outlives the campaign that caused it.
Where the exposure sits, and who carries it#
The geography is stranger than the totals. Greece, Spain, Italy and Austria together account for 86.0% of the exposure in that snapshot, and in each of them the traffic sits mostly on the country's leading mobile carrier rather than a fixed-line or hosting provider. Industrial kit is reaching the public internet through SIM cards. For critical infrastructure security teams that redraws the map completely, because the asset is not in a rack you can walk to, it is on somebody else's mobile network, behind somebody else's support contract.
There is an earlier snapshot too, from 7 April 2026, counting 5,219 hosts globally that answer EtherNet/IP as Rockwell or Allen-Bradley, with Verizon Business alone accounting for 2,564 of them (49.1%) and AT&T Mobility a further 693 (13.3%). Resist the obvious move. Two points four months apart on one query is not a trend, and a fingerprinting change explains a swing that size as neatly as a clean-up campaign does. Plotting 5,219 against 4,148 as a decline sells a slope, not a scada security finding.
One more detail, and it is the strangest thing in the whole pack. That same Censys page carries a line reading: "The following paraphrases the CISA alert as supplied by the user for this report; it was not independently re-fetched from cisa.gov in this session." Those are an AI research pipeline's working notes, left in a published security page. Be precise about what it means. The scan counts are Censys's own instrumentation and they stand. The advisory summary on that page is second-hand by Censys's own admission, and the fair reading stops exactly there.
It matters because it is this week's argument in miniature: an alert about AI-assisted attack tooling, summarised by AI-assisted content, then quoted onward by firms who read the summary rather than the source. Every ot cybersecurity team in that chain had the option to fetch the original, and the few who did have something to say that the rest simply cannot. Provenance is turning into a product feature, which is why our SEO and GEO practice starts with what a page can prove.
Does AI actually lower the bar?#
Take the AI claim apart gently, because there is real evidence in it. The closest thing to a controlled measurement anybody has is the DARPA AI Cyber Challenge. In the final scored round, teams identified 86% of the competition's synthetic vulnerabilities, up from 37% at the semifinals, and patched 68% of what they identified, up from 25%. Those are published, dated, repeatable numbers, and they belong in your deck with three words carried in the same breath: synthetic, defensive, funded.
The economics are the part worth borrowing. Average cost per competition task came to about $152, patches arrived in an average of 45 minutes, and the competing systems worked through more than 54 million lines of code. Cheap, quick and at scale is a different threat model from clever, and it is the one an ot cybersecurity roadmap should plan for. None of it, though, describes a stranger with a chatbot pointed at a live plant.

Two papers are doing the rounds and both are preprints, which changes how you are allowed to cite them. APIOT, posted 4 May 2026, reports a 90.0% mission success rate on a full attack and remediation cycle across 290 experiment runs, five frontier models, three network topologies and two impairment levels. It runs on a Zephyr RTOS lab testbed over Modbus and CoAP, not the S7comm protocol this advisory concerns, and states no peer review. Interesting, adjacent, and not evidence about Siemens controllers.
MALF, posted 3 October 2025, gets closer to the metal, fuzzing Modbus/TCP, S7Comm and Ethernet/IP with a test case pass rate of 88 to 92%. Deployed in an industrial attack and defence range built for power plants, it found critical vulnerabilities including three zero-day flaws, one of them confirmed and registered by CNVD. A registered zero-day is a genuine result. It is also a preprint, produced by a research team with a testbed, not by an opportunist prowling a mobile network for credentials.
The answer that still holds in March#
So what does an honest ot cybersecurity answer sound like? Roughly this. AI measurably improves vulnerability discovery and patching in controlled settings, run by people who know what they are doing, at costs low enough to change the arithmetic of scale. Whether it does the same for a stranger scanning for exposed S7 devices has not been published by anyone, yet. That sentence survives a hostile question in a budget meeting, and it survives the same question again in March, which is more than most ot cybersecurity claims manage.
What the trend lines say, including the one that disagrees#
Pull back to the trend lines and the picture splits into five instruments pointed at five different things. Advisory volume measures disclosure. Incident counts measure what became public. Ransomware group counts measure criminal supply. Surveys measure what practitioners will admit. Vendor telemetry measures what a product blocked. Only one of them points down, and any ot cybersecurity deck that quietly leaves that one out is a deck waiting to be embarrassed by a sharp prospect.
Waterfall Security's 2026 OT Cyber Threat Report goes first because it states its inclusion criteria. Cyber incidents causing physical impacts in heavy industry and critical infrastructure dropped by 25% in 2025, falling from 76 publicly recorded cases in 2024 to 57, against 68 in 2023. Waterfall also reports that 65% of public incident reports in 2025 lacked the detail to conclude how the attack impaired physical operations, and calls its own dataset a conservative estimate that certainly under-reports activity. Nation-state and hacktivist attacks doubled year on year, with 5 of the 14 clearly linked to the invasion of Ukraine.
Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools.
That is the sentence a quarter of the market will build a campaign on, and it is an assessment rather than a measurement. Both things are true at once, and holding both is the entire craft. A vendor who repeats it without the caveat is one curious journalist away from a bad week. A vendor who dismisses it because the evidence is not public is one incident away from a far worse one.
Dragos tracked 119 ransomware groups aiming at industrial organisations in 2025, up from 80 in 2024, with 3,300 organisations affected. Average ransomware dwell time in OT environments ran to 42 days industry-wide, against an average of 5 days among its own customers with comprehensive OT visibility, which is a customer comparison rather than a market rate. Its blog puts 25% of advisories with no patch or mitigation, 3% of vulnerabilities needing immediate action and 4% actively exploited, while the press release says 26% and 2%, so cite the blog, note the variance, and never pick whichever number flatters the pitch. We wrote about the gap between disclosure and exploitation when the same pattern showed up in IT.
SANS surveyed 330 professionals for its 2025 state of ICS and OT security paper: 22% reported a cybersecurity incident in the past year, 40% of those caused operational disruption, close to 20% took more than a month to remediate, and just 14% felt fully prepared for emerging threats. ENISA examined 4 875 incidents for its 2025 threat landscape and put operational technology threats at 18.2% of them. Different instruments, same direction of travel, and a decent spine for any critical infrastructure security narrative.
| Source | What it measures | Stated sample |
|---|---|---|
| CISA AA26-231A | Assessed threat activity | No sample stated |
| Censys, 30 July 2026 | Internet-exposed hosts | 4,117 Siemens S7-1200 hosts |
| Waterfall 2026 | Incidents with physical impact | 57 public cases in 2025 |
| Dragos 2026 | Ransomware groups hitting industry | 119 groups, 3,300 affected |
| SANS 2025 | Practitioner self-report | 330 professionals |
| ENISA ETL 2025 | Incident share by category | 4 875 incidents |
| Kaspersky Q1 2026 | Malware blocked on Windows ICS hosts | Telemetry, sample not disclosed |
Then there is Kaspersky ICS CERT, which points the other way and deserves quoting anyway. The share of ICS computers on which malicious objects were blocked has fallen for five straight quarters: 21.9%, 20.5%, 20.1%, 19.7%, and 19.6% in the first quarter of 2026. It is vendor telemetry with no disclosed sample size, and it counts commodity malware stopped on Windows machines in industrial estates, not targeted access to a controller. Set it beside the others without that sentence and it reads as a contradiction. Keep the sentence and it becomes the most persuasive slide you own.
One cost anchor, carefully labelled. The Cyber Monitoring Centre estimates the Jaguar Land Rover incident caused a UK financial impact of £1.9 billion and affected over 5,000 UK organisations, with vehicle production suspended for roughly five weeks. The centre calls that scenario-based analysis rather than confirmed operational data, and the compromise was an IT one with manufacturing consequences, not a PLC attack. Our own read on the quarter when nobody touched the turbine found the same shape.
IBM's X-Force index puts manufacturing at 27.7% of observed incidents for a fifth year running, with vulnerability exploitation the leading cause at 40%, while its 2026 breach-cost study found 62% of AI-driven attacks aimed at critical infrastructure sectors and energy breaches averaging $5.2 million, across 602 organisations surveyed between March 2025 and February 2026. Stack those beside the ot cybersecurity story the advisory tells and the shape is consistent, even though not one of them measures the thing the advisory actually describes.
Marketing a security product into a numberless alert#
Monday arrives, the biggest story in your category is an alert with no numbers in it, and three competitors have already published the word unprecedented. Here is the ot cybersecurity move that actually works, and it is not louder: turn up with a measurement where everybody else brought an adjective.
Absence is the opportunity. When a federal document quantifies nothing, the first firm to publish a dated, sourced, reproducible figure becomes the citation everyone else borrows. Not the loudest firm, the most checkable one. That is also how AI answer engines choose now: they lift the passage carrying a number, a date and a link, and leave the adjectives in the undergrowth. Our content marketing work lives on exactly that difference.
Count something yourself. Anyone can bin CISA's published advisory URLs by year, as we did for the chart above, and any vendor with a scanner can count exposed devices across its own customers' address space and publish the total with the date attached. A single honest number a competitor does not hold outperforms a page of fluent scada security prose that any of them could have written, and it costs less than the campaign it replaces.
Watch the failure modes, because every one of them is unforced. Do not let a sales deck turn reconnaissance into an attack. Do not let a designer join two Censys snapshots into a downward slope. Do not quote a preprint without the word preprint, and never quote the DARPA figures without saying the vulnerabilities were synthetic. Each shortcut buys a week of attention and costs a year of trust, and in ot cybersecurity the buyers all talk to each other constantly.
The person you are writing for is an engineering or security lead who has to ask for money on Monday with no incident of their own to point at. Give them a sentence they can repeat in a budget meeting without being asked for a source, and you have done more for the pipeline than any campaign about resilience ever managed. That is cybersecurity marketing done properly, and a sharper brand position is what makes it repeatable rather than lucky. The same discipline saved the story when nobody exploited a single flaw.
The advisory will be superseded, the exposure counts will move, and the AI question will eventually be answered by somebody holding telemetry rather than an assessment. Until then, the ot cybersecurity firms worth hiring are the ones that publish what they measured, name what they did not, and trust the reader to tell the difference. That is a slower prowl than the market wants, and it is the one that still has a den in the morning.
Frequently asked questions#
What is ot security?
OT security, short for operational technology security, protects the hardware and software that run physical processes: programmable logic controllers, sensors, drives and the networks joining them. It differs from IT security because the priority is safety and continuous operation rather than confidentiality, and a patch window can mean stopping production.
Did the advisory say any plants were actually attacked?
No. AA26-231A describes reconnaissance, capability development and pre-positioning, and says operational effects could follow. It reports no successful disruption at any facility, no incident count and no affected-facility count, so any claim that plants were taken offline goes well beyond what the five authoring agencies published.
How many Siemens PLCs are exposed to the internet?
Censys counted 4,117 internet-exposed hosts fingerprinting as Siemens SIMATIC S7-1200 in a snapshot dated 30 July 2026. Censys is explicit that this describes exposure only and does not confirm that any specific host is a victim of the activity CISA describes, which is the caveat every ot cybersecurity brief should carry with the number.
Is there real evidence that AI lowers the barrier to writing exploits?
There is measured evidence in controlled settings. In the DARPA final, teams found 86% of synthetic vulnerabilities, up from 37%, and patched 68%, up from 25%, at an average task cost near $152. That was defensive tooling built by funded expert teams, not a novice with a chatbot, and the advisory itself publishes no evidence of AI authorship.
What is the difference between ot cybersecurity and ics security?
They overlap heavily. The wider term, ot cybersecurity, covers all operational technology, including building systems, safety instrumented systems and industrial networks. The narrower one, ics security, covers industrial control systems specifically: controllers, SCADA servers and the protocols joining them. Most vendors sell to both audiences and should say plainly which one a claim applies to.
How should a security vendor respond to an advisory with no numbers in it?
Publish a number the advisory lacks. Count exposure in your own telemetry, date it, name the method and its limits, then link the advisory for the qualitative claim. An ot cybersecurity buyer forwarding your page to a finance director needs one checkable figure far more than another paragraph about resilience.
Read more on this topic#
Nobody touched the turbine. They took the office.
The quarter's industrial ransomware landed on business systems, not controllers, and the reporting rarely said so.
Read the piecePatch Tuesday, Exploited Wednesday
What happens to a disclosure window when attackers move faster than the patch cycle allows.
Read the pieceNobody Exploited a Single Flaw. They Just Used the Password
A breach with no exploit in it, and the detection story that should have been told instead.
Read the pieceNIST Just Handed Security Teams a Script for Their Own AI Prompts
Published this morning: structured prompts for framework work, and a comment window already running.
Read the piece
Ready to say something measured while the rest say unprecedented?
Security firms hire folkfox to turn advisories, telemetry and hard-won field numbers into ot cybersecurity content a finance director can check and an answer engine can quote.