WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) Forescout Reports Risk to ICS/OT Environments by Exposed Remote Access Services (RDP & VNC)
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Forescout Reports Risk to ICS/OT Environments by Exposed Remote Access Services (RDP & VNC)

TLP:CLEAR

Author: Chase Snow

Created: Thursday, April 30, 2026 - 14:26

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

Summary: On Tuesday, Forescout released a blog post highlighting widespread exposure of remote access services, including Remote Desktop Protocol (RDP) and Virtual Network Computing (VNC), across internet-facing environments. Researchers identified over 1.8 million RDP and 1.6 million VNC servers exposed globally, with tens of thousands mapped to specific industries, including utilities. Notably, hundreds of exposed VNC servers provide direct access to ICS/OT systems, in some cases without authentication, significantly increasing the risk of unauthorized access and operational disruption.

Analyst Note: This reporting reinforces a consistent and well-documented risk to the water sector: insecure remote access pathways into operational environments. The exposure of RDP and VNC services, particularly those lacking authentication or running unsupported systems, creates a direct avenue for threat actors to access and interact with ICS/OT assets. These weaknesses are not theoretical; threat actors, including hacktivists and ransomware actors, are actively scanning for and exploiting exposed systems, and some groups are developing tools specifically designed to identify and access OT environments.

For water utilities, the implications are significant. Remote access technologies are often necessary to support distributed infrastructure, third-party maintenance, and operational continuity. However, when improperly secured or directly exposed to the internet, these same technologies can provide adversaries with a foothold into critical systems. The presence of legacy systems, weak authentication practices, and limited visibility into remote sessions further amplifies this risk.

WaterISAC encourages members to restrict direct internet exposure of RDP and VNC services, implement strong authentication controls, and adopt secure remote access solutions that provide visibility, session control, and least-privilege access. Strengthening these controls remains a critical step in reducing the likelihood of unauthorized access and protecting operational resilience.

Fundamental 2 “Minimize Control System Exposure” from WaterISAC’s 12 Cybersecurity Fundamentals for Water and Wastewater Utilities provides utilities with guidance and resources to help secure this critical risk to the sector.

Original Source: https://www.forescout.com/blog/rdp-security-cps-threats-spark-need-for-secure-remote-access/

Additional Reading:

  • Hundreds of Internet-Facing VNC Servers Expose ICS/OT
  • Guide to Securing Remote Access Software

Related WaterISAC PIRs: 6, 8, 10, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar