The hard failure here is loss of operator control, not just a noisy intrusion. Once someone can reach a PLC’s management plane, they can change passwords and IP settings, cut operators off, and leave the site running only in manual mode.
CISA says it is seeing a significant increase in attacks on internet-exposed PLCs in water and wastewater systems. The agency says the activity has already caused boil water notices and sustained manual operations, and that the exposed paths can include cellular modems installed by operators, vendors, or system integrators that never made it into routine inventory.
That means perimeter scans that only look for obvious internet-facing devices miss the real trust path. If the control plane is reachable, the attacker can rewrite who is trusted to manage the plant, and the lockout can persist even after the initial access point is found.