Your Control Network Is Already Exposed, and Attackers Are Just Waiting
About This Session
Your control network is already exposed, and you may be the last to know it. When a water utility, a manufacturer, or a rural co-op gets compromised, the cause is rarely an exotic zero-day. It is a device that should never have been reachable from the public internet: a PLC running default credentials, an HMI indexed by a search engine, a serial-to-IP converter quietly bridging the plant floor to the world.
This session takes the adversary's first move, reconnaissance, and hands it to the defender. Using real, passively-collected exposure data across critical-infrastructure sectors, we will look at what is actually reachable from the open internet right now: the device classes, the protocols, the recurring mistakes, and the recently weaponized examples, from Unitronics PLCs in the water sector to the actively-exploited Lantronix serial-to-IP flaw added to CISA's KEV list this month. No agents, and no scanning of anyone's network. Just what a browser already sees.
Then we get practical. Most of this risk collapses under a short, cheap checklist any operator can run Monday morning: get it off the internet, kill the defaults, segment, and patch the handful of CVEs that adversaries are truly using. You will leave able to find your own exposed assets and close the gaps before someone else finds them first.
This session takes the adversary's first move, reconnaissance, and hands it to the defender. Using real, passively-collected exposure data across critical-infrastructure sectors, we will look at what is actually reachable from the open internet right now: the device classes, the protocols, the recurring mistakes, and the recently weaponized examples, from Unitronics PLCs in the water sector to the actively-exploited Lantronix serial-to-IP flaw added to CISA's KEV list this month. No agents, and no scanning of anyone's network. Just what a browser already sees.
Then we get practical. Most of this risk collapses under a short, cheap checklist any operator can run Monday morning: get it off the internet, kill the defaults, segment, and patch the handful of CVEs that adversaries are truly using. You will leave able to find your own exposed assets and close the gaps before someone else finds them first.
Speaker
Matt Lucas
CEO - RedEye Security
Matt Lucas is the founder of RedEye Security, a Nashville-based firm focused on detection engineering and exposure reduction for operational technology and critical-infrastructure environments. He runs an ongoing ICS exposure research effort that maps internet-facing industrial devices across U.S. sectors, publishes daily OT and ICS threat intelligence, and has brought hands-on "here is your exposure" demonstrations directly to regional operators and county-level events. His work focuses on the unglamorous, high-impact basics: finding what is exposed before an adversary does, and the low-cost fixes that close most of the gap.
