OT / ICS · 137 days ago
Direct internet exposure turns remote access into a control-plane problem. The standard response is to treat RDP and VNC as ordinary admin services, but Forescout’s data shows that some of these endpoints sit close enough to industrial systems to become a path into ICS and OT.
Forescout found about 1.8 million RDP servers and 1.6 million VNC servers exposed online. It also mapped 91,000 RDP and 29,000 VNC servers to specific industries, with hundreds that may expose ICS/OT, including 670 VNC servers that provide direct access to OT panels without authentication.
The noise from honeypots, ISPs, and hosting providers hides the real exposure. That makes targeted scanning less reliable, because a small set of genuine OT-facing remote access systems can be buried inside a much larger pool of internet-facing services.
2 sources covering this story
New Forescout research finds 3.4 million RDP and VNC servers exposed, raising risks to OT and enterprise networks.
Hundreds of Internet-Facing VNC Servers Expose ICS/OT
Forescout has identified tens of thousands of exposed RDP and VNC servers that can be mapped to specific industries.
Part of the PlainSec briefing for 2026-05-02