Table of Contents
CISA’s Internet Exposure Reduction Guidance calls on critical infrastructure operators to find systems needlessly reachable over the internet and take them offline or lock them down.
The agency sharpened the message after observing, in July 2026, malicious activity against more than 100 exposed systems in the Water and Wastewater Systems Sector, often programmable logic controllers wired straight to a cellular modem.
The resource lays out four steps and points to free federal services that help shrink an organization’s attack surface before attackers find the gaps first.
Internet Exposure Reduction Guidance: Key Takeaway
- CISA’s Internet Exposure Reduction Guidance urges operators to inventory exposed systems, remove needless exposure, and secure what must stay online.
This section contains affiliate links; we may earn a commission at no cost to you.
Reducing exposure starts with knowing what you have and fixing what is weak. These tools map that work directly onto CISA’s four steps:
- Tenable (vulnerability management): Continuously scan the systems that face the internet, rank exposures by real risk, and confirm that your fixes hold. Explore Tenable
- Auvik (network monitoring and management): Map every device on the network, surface assets reachable from outside, and watch remote access from one console. Try Auvik
- CyberUpgrade (cybersecurity compliance and management): Run the assess, evaluate, mitigate, and review cycle CISA describes, and keep the evidence auditors ask for. See CyberUpgrade
- Plesk (server and hosting management): Harden the servers you must keep online, manage patches, and lock down remote logins in one place. Check Plesk
The Water Sector Activity Behind the Guidance
CISA published its Internet Exposure Reduction Guidance to help organizations close a gap that is easy to overlook: assets sitting on the public internet that no one meant to leave there, or that no longer need to be there.
The agency warns that misconfigured systems, default credentials, and outdated software are frequently visible through ordinary internet search and discovery tools, which makes them simple for attackers to locate and exploit.
The urgency is not theoretical. CISA states that in July 2026 it observed malicious cyber activity aimed at more than 100 systems exposed to the internet in the Water and Wastewater Systems (WWS) Sector.
In many cases, the exposed device was a programmable logic controller connected directly to a cellular modem. A programmable logic controller, or PLC, is the small industrial computer that opens valves, runs pumps, and controls physical processes at a treatment plant.
CISA says directly connecting PLCs to the internet through cellular modems can create significant security risks.
The controller ends up on the public network with little between it and anyone scanning for it, and the functions it manages are the physical operations of a utility that a community depends on.
Why an Exposed Controller Is Such a Prize
Industrial systems were designed for reliability and long service life, not for defending themselves on the open internet. Terms like SCADA (supervisory control and data acquisition), ICS (industrial control systems), and IIoT (the industrial internet of things) all describe the connected equipment that now runs utilities, factories, and building systems.
CISA notes that the range and number of these assets keeps growing, and that unsecured, they raise both operational and security risk.
Attackers do not need a sophisticated exploit when the front door is open. A threat actor, meaning any individual or group carrying out malicious activity, can find a reachable controller through a search index, test whether it still uses factory logins, and reach control functions.
Attackers have long harvested default router passwords at internet scale to assemble botnets, which are networks of hijacked devices used to launch further attacks. Recent cases, such as exposed Four-Faith router credentials, show how quickly a reachable device with weak logins is discovered and abused.
What CISA’s Internet Exposure Reduction Guidance Recommends
The guidance is built around four steps, as reported by Industrial Cyber. Together they turn a vague worry about exposure into a repeatable process.
Step One: Assess Current Exposure
The first step is to identify which assets are reachable from the internet. CISA recommends mapping that footprint with scanning tools and services, including its own Cyber Hygiene vulnerability scanning and other platforms that run online.
The goal is a clear inventory, because an organization cannot protect a system it does not know is exposed.
Step Two: Evaluate Whether the Exposure Is Necessary
Next, operators decide which systems truly need to remain reachable for operations. For anything that does not, CISA advises removing or restricting connectivity.
The agency adds an important caution: changes should be reviewed against system interdependencies, so that closing one connection does not disrupt an essential service that quietly relied on it.
CISA lists concrete questions for this stage:
- Is the exposed system or service essential? What is the business justification that requires it to be reachable?
- Can access be routed through a safer path such as a VPN or protected with multifactor logins?
- And is the system maintained and patched against known flaws?
Working through those questions turns a judgment call into a documented decision.
Step Three: Mitigate Risk for Assets That Must Stay Online
Some systems have to stay reachable, and for those, CISA says risk mitigation becomes critical.
Its recommendations are practical and familiar: replace default passwords with strong credentials, apply the latest security patches, place remote access behind a virtual private network (VPN), and enable multifactor authentication (MFA), which requires a second proof of identity beyond a password.
None of these are exotic, and that is the point. Many operators pair exposure reduction with zero trust network principles, so that even necessary remote access is tightly scoped and continuously verified rather than trusted by default.
Step Four: Make Assessment Routine
Finally, CISA urges a standing routine of ongoing assessments. Environments change, new devices appear, and yesterday’s clean inventory drifts.
Regular reviews of assets reachable from the internet help catch new exposure early, before an attacker does.
The Discovery Tools CISA Points To
To help organizations see themselves the way an attacker would, CISA references several online discovery platforms. It presents them for informational purposes only and stresses that mention does not imply endorsement by the U.S. government.
Each one indexes IP addresses, parses Transport Layer Security (TLS) certificates, and tracks domains to build a picture of an organization’s footprint on the internet.
Shodan
Shodan scans the internet to detect connected devices and collects information from the banners those devices broadcast.
CISA notes it offers advanced search filters, can flag devices still using default credentials, and can surface known vulnerabilities, which is exactly the reconnaissance a defender wants to run first.
Censys
Censys discovers assets connected to the internet across many categories, including industrial systems.
It supports several output formats, including a web interface, API access, raw data exports, and integration with Google BigQuery, which makes it straightforward to fold into a broader security workflow.
Thingful and Shadowserver
Thingful focuses on categorizing global IoT data and delivers insight across sectors such as energy, telecommunications, and weather, with an API that feeds live IoT data into operational systems. CISA also lists Shadowserver among the platforms that improve visibility into assets exposed on the internet.
Used together, these services let a team find the same weak points an opportunistic scanner would.
Free CISA Services and Who Can Use Them
The guidance leans on services CISA offers at no charge. Chief among them is Cyber Hygiene vulnerability scanning, which probes systems facing the internet and does not require administrative rights on them.
Organizations enroll by emailing [email protected] with the subject line “Requesting Cyber Hygiene Services.”
CISA also puts a number on the benefit. It reports that organizations enrolled in these services typically reduce their risk and exposure by about 40 percent within the first 12 months, with most improvements appearing in the first 90 days.
Regional Cybersecurity Advisors add tailored guidance and assessments on top of the automated scanning.
Eligibility is broad. CISA says U.S. federal, state, local, tribal, and territorial governments, along with public and private critical infrastructure organizations, can enroll.
Organizations based outside the United States are directed to contact [email protected] to discuss what help they may qualify for.
Who Is Affected
CISA frames the guidance as useful for any organization trying to limit its footprint on the internet, but it singles out critical infrastructure operators as facing heightened risk and urges them to prioritize it. The July 2026 activity places water and wastewater utilities squarely in that group.
Federal agencies are affected in a more formal way. Under CISA’s binding operational directive BOD 26-04, agencies are told to follow the Internet Exposure Reduction Guidance when determining whether a vulnerable asset is publicly exposed, a factor that then feeds how urgently they must patch it. A CVE, short for Common Vulnerabilities and Exposures, is the standard identifier assigned to a specific software flaw, and BOD 26-04 ties exposure status to how those flaws are prioritized.
Implications of Reducing Internet Exposure Across Critical Infrastructure
The guidance reads as routine hygiene, yet the July 2026 water sector activity gives it weight. The impact lands differently across several groups.
For Water and Wastewater Utilities
Water systems are a hard case. Many are small, rural, and run by a handful of operators, and a PLC on a cellular modem is often the cheapest way to monitor a remote site.
CISA’s message to these utilities is not to abandon remote monitoring but to justify it, wrap it in a VPN and multifactor logins, and swap default passwords before an attacker does.
The 40 percent risk reduction CISA cites is meaningful precisely because these operators have thin budgets and little margin for a disruption to service.
For OT and ICS Environments Generally
The same logic reaches manufacturing, energy, and building systems, where operational technology (OT), the hardware and software that runs physical processes, increasingly touches the internet. CISA’s warning that exposed and unsecured assets raise operational risk applies wherever a controller has quietly picked up a public address.
The guidance gives these operators a defensible way to decide what stays reachable and what gets pulled back.
For Federal Agencies and Patch Prioritization
By binding exposure status to BOD 26-04, CISA turns exposure reduction from good advice into a compliance input.
An agency that maps its footprint well can prioritize patching more sharply, spending scarce effort on the flaws that sit where attackers can actually reach them.
Agencies that skip the inventory risk both weaker security and a harder time meeting the directive.
For the Attacker Economy
The uncomfortable point CISA makes is that attackers already use the same discovery tools it recommends. Shodan, Censys, Thingful, and Shadowserver make exposed assets cheap to find at scale, which means opportunistic scanning, not targeted skill, is often enough to reach a utility’s controls.
Reducing exposure raises the cost of that reconnaissance and removes the easy wins, which is the most durable form of defense against untargeted, high volume attacks.
This section contains affiliate links; we may earn a commission at no cost to you.
Two of CISA’s core recommendations come down to credentials and recovery. These tools cover both:
- 1Password (password manager): Replace default and reused logins on exposed devices with strong, unique credentials your team will actually use. Get 1Password
- Passpack (password manager): Share and rotate credentials across an operations team without spreadsheets or sticky notes. Try Passpack
- IDrive (cloud backup and ransomware recovery): Keep clean copies so an intrusion through an exposed system does not turn into permanent data loss. See IDrive
Looking Forward
CISA frames internet exposure reduction as basic hygiene rather than a one time project. The agency’s own figures suggest the payoff is real: it reports that organizations enrolled in its Cyber Hygiene services typically cut risk and exposure by about 40 percent within a year, with most gains landing in the first 90 days.
The July 2026 water sector activity shows why the timing matters. Attackers scan constantly, and a controller wired to a cellular modem can surface in a search index within minutes. The guidance does not ask operators to sever remote access, only to justify it, secure it, and revisit it.
For utilities, manufacturers, and public agencies alike, the practical takeaway is the same. Inventory what faces the internet, remove what does not need to be there, and protect the rest with strong credentials, current patches, and multifactor logins. The tools to start are free.
Questions Worth Answering
What is CISA’s Internet Exposure Reduction Guidance?
- A CISA resource that helps organizations find assets reachable over the internet and either remove them or secure them, shrinking their attack surface.
What prompted the renewed warning?
- CISA says it observed malicious cyber activity in July 2026 against more than 100 exposed systems in the Water and Wastewater Systems Sector, often PLCs connected to cellular modems.
Why is connecting a PLC directly to a cellular modem risky?
- It places an industrial controller on the public internet with little protection, where scanners can find it and attackers can reach the physical control functions it manages.
What are the four steps in the guidance?
- Assess current exposure, evaluate whether the exposure is necessary, mitigate risk on assets that must stay online, and repeat the review on a routine basis.
Which discovery tools does CISA reference?
- CISA lists platforms such as Shodan, Censys, Thingful, and Shadowserver for informational purposes only, without endorsing them.
Does reducing exposure mean turning off remote access?
- No. CISA says it means removing remote access when it is unnecessary and securing it, with VPNs and multifactor authentication, when it is necessary.
What free CISA services support this work?
- Cyber Hygiene vulnerability scanning and regional Cybersecurity Advisors, both offered at no cost, plus the discovery tools the guidance references.
Who can enroll in CISA Cyber Hygiene services?
- U.S. federal, state, local, tribal, and territorial governments and public and private critical infrastructure organizations; international organizations can contact CISA international affairs.
How does the guidance relate to federal patching rules?
- Under BOD 26-04, agencies use the guidance to decide whether a vulnerable asset is publicly exposed, which then shapes how urgently they must apply a fix.
What quick wins matter most for exposed systems?
- Replace default passwords, apply current security patches, route remote access through a VPN, and turn on multifactor authentication.
This section contains affiliate links; we may earn a commission at no cost to you.
Also worth a look: EasyDMARC to stop email spoofing, Optery to scrub exposed personal data from broker sites, and Tresorit for encrypted storage of sensitive operational files.