Daily OT Security News: July 27, 2026

Iran-linked OT/ICS targeting keeps internet-exposed industrial systems in focus

Shieldworkz reports that an updated multi-agency U.S. advisory describes ongoing Iran-affiliated activity against U.S. critical infrastructure, naming water, energy, government facilities, healthcare, and manufacturing as affected sectors. Shieldworkz’s analysis says the activity has involved internet-exposed PLCs, HMIs, SCADA systems, and remote field communications, and identifies scanning, default or compromised credentials, and authentication flaws as common access paths. The vendor analysis attributes possible consequences to manipulated HMI or SCADA data displays, altered controller project files, operational disruption, and financial loss, and frames these outcomes as potential impacts observed in the advisory and its technical assessment.

Source: Shieldworkz

Singapore tightens critical-infrastructure assurance amid IT-to-OT risk

FutureCISO reports on remarks from a Singapore Cyber Security Agency OT Cybersecurity Expert Panel Forum that highlighted a late-2025 incident affecting more than 30 wind and solar sites in Poland, including a heat-and-power plant and a manufacturing company. According to FutureCISO’s account of the Singapore CSA remarks, the incident did not affect ongoing electricity generation or Poland’s national power system but illustrated how disruptive activity can be coordinated across multiple sites, including OT environments. The report also says Singapore has mandated Cyber Trust Mark Level 5 certification for critical-information-infrastructure owners by the end of 2027 and for CII auditors by the end of 2026.

Source: FutureCISO

Marathon Petroleum CISO emphasizes resilient OT automation and supplier oversight

In a Help Net Security interview, Marathon Petroleum CISO Mary Rose Martinez says the older concept of air-gapped operational technology has faded. Martinez describes using the Purdue model to apply controls without halting production across refineries, pipelines, and terminals, framing the approach as a way to balance security and continuous operations. She highlights due diligence, contractual safeguards, and close response partnerships with vendors when adding or materially changing products and services, stressing these measures as part of an operational approach described in the practitioner interview rather than as an independently measured industry trend.

Source: Help Net Security

OT resilience remains vulnerable to business-IT dependencies

Sygnia’s OT incident-response analysis says many cyber incidents affecting manufacturers and OT-heavy organizations do not progress into the OT environment, yet still cause operational disruption. The article attributes this partly to the specialized expertise and reconnaissance required to operate in customized, legacy-heavy industrial environments, noting that such operational contexts complicate adversary movement and targeting. Drawing from its incident-response experience, Sygnia argues organizations should plan for resilience across IT dependencies rather than assuming network separation alone will protect production, emphasizing the need to consider cross-domain impacts on operations based on observed response cases.

Source: Sygnia

Share this