Iran-linked OT/ICS targeting keeps internet-exposed industrial systems in focus
Shieldworkz reports that an updated multi-agency U.S. advisory describes ongoing Iran-affiliated activity against U.S. critical infrastructure, naming water, energy, government facilities, healthcare, and manufacturing as affected sectors. Shieldworkz’s analysis says the activity has involved internet-exposed PLCs, HMIs, SCADA systems, and remote field communications, and identifies scanning, default or compromised credentials, and authentication flaws as common access paths. The vendor analysis attributes possible consequences to manipulated HMI or SCADA data displays, altered controller project files, operational disruption, and financial loss, and frames these outcomes as potential impacts observed in the advisory and its technical assessment.
Singapore tightens critical-infrastructure assurance amid IT-to-OT risk
FutureCISO reports on remarks from a Singapore Cyber Security Agency OT Cybersecurity Expert Panel Forum that highlighted a late-2025 incident affecting more than 30 wind and solar sites in Poland, including a heat-and-power plant and a manufacturing company. According to FutureCISO’s account of the Singapore CSA remarks, the incident did not affect ongoing electricity generation or Poland’s national power system but illustrated how disruptive activity can be coordinated across multiple sites, including OT environments. The report also says Singapore has mandated Cyber Trust Mark Level 5 certification for critical-information-infrastructure owners by the end of 2027 and for CII auditors by the end of 2026.
Marathon Petroleum CISO emphasizes resilient OT automation and supplier oversight
In a Help Net Security interview, Marathon Petroleum CISO Mary Rose Martinez says the older concept of air-gapped operational technology has faded. Martinez describes using the Purdue model to apply controls without halting production across refineries, pipelines, and terminals, framing the approach as a way to balance security and continuous operations. She highlights due diligence, contractual safeguards, and close response partnerships with vendors when adding or materially changing products and services, stressing these measures as part of an operational approach described in the practitioner interview rather than as an independently measured industry trend.
OT resilience remains vulnerable to business-IT dependencies
Sygnia’s OT incident-response analysis says many cyber incidents affecting manufacturers and OT-heavy organizations do not progress into the OT environment, yet still cause operational disruption. The article attributes this partly to the specialized expertise and reconnaissance required to operate in customized, legacy-heavy industrial environments, noting that such operational contexts complicate adversary movement and targeting. Drawing from its incident-response experience, Sygnia argues organizations should plan for resilience across IT dependencies rather than assuming network separation alone will protect production, emphasizing the need to consider cross-domain impacts on operations based on observed response cases.