An ICS adversary most commonly establishes an initial foothold before pivoting toward the control network by exploiting:
- A.Direct internet exposure of every PLC's programming port
- B.Phishing of IT/enterprise users, compromised VPN or remote-access services, and similar IT entry points
- C.Brute-forcing the proprietary fieldbus on the plant floor
- D.Physical theft of safety relays from substations
Why B is correct
Most modern OT intrusions begin in the enterprise IT environment via phishing, stolen credentials, or vulnerable VPN/remote-access gateways, then move laterally toward OT. This IT-to-OT pivot underscores why segmentation and monitoring at the IT/OT boundary are critical defenses.
Know someone studying for OT Security Fundamentals? Send them this one.