Passive Sweep Analysis: Industrial Infrastructure Exposure and Defensive Baselines

Jeff Gray · July 2026 · 5 min read
Original Research · Cyborama OT Intelligence

Key Finding: A passive, non-intrusive scan of a regional US area identified 760 internet-exposed industrial devices utilizing unauthenticated protocols that operate without native security controls. A significant 44% of these exposures originate from devices connected via public cellular networks.

Author Note: This report utilizes public OSINT to establish a defensive baseline, with no active scanning or interaction with systems performed.

The Baseline Sweep & Protocol Exposure

The assessment highlights a breakdown in traditional Purdue Model segmentation, where Level 0–2 industrial systems become directly accessible from the public internet — primarily via unauthenticated, legacy protocols.

Protocol Exposure Breakdown

These exposures represent an inherent, long-standing architectural vulnerability rather than mere misconfiguration.

Key Vulnerability: Public Cellular Infrastructure

A critical finding is that nearly half of the exposed IP addresses reside on public commercial cellular networks. This indicates that cellular gateways and serial-to-IP converters are being deployed directly to the internet, bypassing private APNs or VPN overlays.

Why the Exposure Persists

Defensive Recommendations

Disclaimer: This research supports defensive awareness and does not involve active targeting or vulnerability exploitation.

← Back to Control Systems Security

Threat Radar Pro — Continuous OT Threat Intelligence

Live ICS/SCADA threat monitoring, actor mapping, surge detection, and weekly risk recaps.

View Threat Radar