Industrial control systems rarely make headlines, yet they quietly power the essential services that modern life depends on. From electricity and water to transportation and manufacturing, these systems form the backbone of global infrastructure. A recent report from Comparitech highlights a growing and deeply concerning reality: malware targeting industrial control systems is no longer theoretical, it is active, evolving, and increasingly dangerous.
The Expanding Risk of Internet-Exposed Systems
One of the most alarming findings in the report comes from researcher Justin Schamotta, who identified 179 internet-exposed ICS devices. These are not insignificant systems tucked away in isolated labs. Some are tied directly to national infrastructure.
Among the exposed systems were devices connected to railway networks, responsible for routing and signaling trains. Others were linked to national power grid infrastructure in different regions of the world. These systems are critical to public safety and economic stability, and their exposure presents a serious operational risk.
The geographic distribution is equally notable. The United States led with 57 exposed devices, followed by Sweden and Turkey. This highlights that the issue is global in scope, not limited to a single region or regulatory environment.
When Cyber Attacks Become Physical Threats
Unlike traditional cyberattacks that focus on data theft, ICS malware crosses into the physical world.
According to Shujaatali Badami, these threats bridge the gap between digital systems and real-world consequences. A striking example occurred in 2024 in the Ukrainian city of Lviv. Malware known as FrostyGoop exploited industrial protocols to send malicious commands to heating systems, cutting off heat to hundreds of apartment buildings during freezing temperatures.
This type of attack illustrates a key distinction. When attackers compromise IT systems, organizations may lose data. When they compromise operational technology environments, they can disrupt physical processes that people rely on to live and work.
As Michael Bell explains, the consequences can extend far beyond inconvenience. Power plants, water treatment facilities, healthcare systems, traffic networks, and manufacturing operations all depend on ICS environments functioning reliably.
The Domino Effect of Industrial Attacks
The risks do not stop at a single compromised system. Modern industrial environments are deeply interconnected through supply chains and shared infrastructure.
Floris Dankaart emphasizes that a successful attack can trigger cascading failures. A breach in one organization can ripple outward, affecting suppliers, logistics providers, and downstream partners.
This interconnectedness amplifies the “blast radius” of an attack. What begins as a localized compromise can evolve into widespread disruption across entire industries. For attackers seeking maximum impact, this makes ICS environments particularly attractive targets.
Why Vulnerabilities Are Increasing
The report also points to a sharp rise in disclosed vulnerabilities, supported by findings from Cyble Research & Intelligence Labs. Between 2024 and 2025, ICS vulnerability disclosures nearly doubled.
This surge is not surprising when viewed in context.
As Shaila Rana explains, ICS systems were originally designed for isolated environments. Security was not a primary concern because these systems were never intended to be connected to the internet.
That assumption no longer holds.
The shift toward remote monitoring, automation, and Industry 4.0 has connected these systems to broader networks. This convergence of IT and operational technology has dramatically expanded the attack surface.
At the same time, increased attention from the security research community means more vulnerabilities are being discovered and reported. The combination of legacy design limitations and heightened scrutiny is driving the surge in disclosures.
Legacy Protocols and Modern Threats
A major factor in ICS insecurity lies in the protocols many systems still rely on. Technologies such as Modbus, DNP3, and BACnet were built for closed, trusted networks.
They often lack basic security features such as authentication and encryption.
When these protocols are exposed to the internet, they become easy targets. Attackers with relatively modest technical skills can exploit them, especially if additional safeguards like firewalls or network segmentation are not in place.
As industrial systems continue to expand, this challenge is becoming more urgent. The global industrial automation market is growing rapidly, bringing more connected devices online and increasing the number of potential entry points for attackers.
The Challenge of Securing ICS Environments
Securing industrial systems is fundamentally different from securing traditional IT environments.
According to Dale Hoak, standard approaches like aggressive patching are not always feasible. Many ICS environments cannot tolerate downtime, as availability and safety are often more critical than confidentiality.
This creates a difficult balancing act. Organizations must protect systems without disrupting operations that people depend on daily.
Tim Mackey highlights another challenge: longevity. ICS devices often remain in service for decades. Systems designed with the best practices of their time can become vulnerable as new attack techniques emerge.
Attackers are well aware of this. Once inside a network, they may take their time mapping systems and planning highly targeted attacks, knowing that defenders are constrained in how quickly they can respond.
Beyond Malware: The Fundamentals Still Matter
While sophisticated malware grabs attention, many ICS breaches begin with basic security failures.
Rosario Mastrogiacomo points out that weak credentials, poor network segmentation, unsecured remote access, and lack of visibility remain common issues.
Guidance from organizations like NIST and CISA reinforces this reality. Even relatively simple attack methods can succeed against poorly secured environments.
In many cases, the most effective defenses are also the most fundamental:
- Limiting internet exposure
- Segmenting operational networks from IT systems
- Strengthening authentication controls
- Maintaining an accurate inventory of assets
- Preparing for manual or degraded operations during incidents
These measures may lack the appeal of advanced technologies, but they provide the strongest foundation for resilience.
The Era of ICS Malware
According to Will Thomas, we are now in the “era of adoption” for ICS malware. What was once experimental is now routinely deployed by sophisticated threat actors, including nation states.
Attackers are using advanced techniques to hide their origins and evade detection. At the same time, they are exploiting the very characteristics that make ICS environments difficult to secure, legacy systems, long lifespans, and operational constraints.
The implication is clear. ICS security can no longer be treated as a niche concern. It is a central issue for national security, economic stability, and public safety.
Securing the Systems That Sustain Society
The growing threat to industrial control systems reflects a broader transformation in cybersecurity. As more physical systems become connected, the boundary between digital and real world risk continues to blur.
Malware targeting ICS environments is not just about data breaches or financial loss. It is about the potential disruption of services that millions of people rely on every day.
Addressing this challenge requires a shift in mindset. Organizations must move beyond reactive security measures and focus on understanding and controlling their environments. Visibility, segmentation, and disciplined operational practices are essential.
The systems that power modern society were not built with today’s threat landscape in mind. Securing them now is not optional. It is a critical step in ensuring that the infrastructure we depend on remains stable, reliable, and safe in an increasingly connected world.


