CISA Warning Highlights Security Dilemma for Internet-Exposed Industrial Hardware
Operational technology operators face trade-offs between remote access requirements and the heavy computational costs of processing automated connection probes.

Federal cybersecurity officials at the Cybersecurity and Infrastructure Security Agency (CISA) have issued an urgent advisory calling on industrial operators to disconnect exposed operational technology (OT) from the public internet. The agency is urging organizations to remove internet-facing connections, change default credentials immediately, restrict remote access, and strengthen authentication to mitigate growing cyber threats against critical industrial infrastructure. However, as highlighted in technical analysis shared via Hacker News (https://jnior.com/blog/the-cisa-alert-security-beyond-solitary-confinement/), completely severing OT controllers from network connectivity is often impractical for modern facilities that rely on remote management and operational data.
The operational friction stems from the architectural limits of embedded control hardware. When an OT device is reachable online, it encounters automated port scans, connection probes, and credential attacks within minutes. Processing these incoming requests consumes finite system resources. Secure Shell (SSH) login attempts, for instance, force a controller to negotiate cryptographic handshakes before credentials can even be evaluated. Because modern encryption algorithms require significant processing overhead, forcing an embedded controller to execute these handshakes repeatedly can degrade performance, creating an intentional or unintentional denial-of-service condition on hardware tasked with deterministic, real-time industrial operations.
External exposure frequently occurs without direct administrative awareness. While some hardware connects via public Internet Protocol (IP) addresses, many controllers reside on private networks behind firewalls using Network Address Translation (NAT). Exposure commonly occurs when port forwarding is configured to direct external web or management traffic to a specific private device. On platforms like the JNIOR controller running the JANOS operating system, diagnostic tools like the NETSTAT -M command allow engineers to monitor real-time connection attempts from public IP addresses to verify whether unexpected network pathways exist.
Security practitioners draw a sharp distinction between targeted industrial cyberattacks and indiscriminate internet-wide reconnaissance. Highly tailored attacks, such as the Stuxnet worm, require extensive advance knowledge of target systems and specialized payloads. By contrast, the vast majority of malicious traffic consists of automated scanners probing vast address spaces for open ports, recognizable services, or default logins. These automated systems spend minimal resources per probe, yet force receiving controllers to expend processor cycles responding to every request.
Rather than relying entirely on hardware upgrades and heavier cryptographic workloads to absorb background probes, alternative defenses focus on reducing device visibility. Standard cybersecurity guidance emphasizes changing default credentials, eliminating unused accounts, disabling unnecessary services, and enforcing firewall controls—foundational measures reinforced by CISA. However, minimizing the discovery surface of embedded devices provides a complementary layer by preventing automated tools from identifying controllers in the first place.
To mitigate background scanning without draining controller resources, developers of the JANOS operating system implemented a mechanism known as SYN greylisting. The approach adapts a long-standing email filtering concept based on the economic incentives of automated systems versus legitimate clients. Mass network scanners prioritize speed across millions of addresses and quickly move past non-responsive targets. Legitimate network clients, by contrast, assume transient packet loss and automatically retransmit initial connection requests.
Under SYN greylisting, when an incoming TCP SYN packet arrives at an open port, the controller intentionally ignores the initial request without returning a SYN-ACK response. To an automated scanner conducting rapid sweeps, the target appears silent or inactive. A legitimate client retransmits its SYN request in accordance with standard TCP behavior. If the retransmitted packet arrives within a designated time window, the controller accepts the request and establishes the connection normally.
The filtering mechanism operates directly within the TCP driver, introducing negligible latency for legitimate users while consuming minimal memory and CPU resources. By discarding initial unsolicited connection probes, embedded industrial controllers can avoid executing computationally demanding cryptographic handshakes with automated scanners, allowing devices to maintain real-time industrial tasks while remaining invisible to mass reconnaissance.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



