Key Actions the Advisory Asks For
Straight from AA26-097A. If you run PLCs, these are the moves.
- Remove PLCs from direct internet exposure. Put them behind a secure gateway and firewall, working with your IT/OT team or integrator.
- Install PLCs consistent with the manufacturer's guidelines and security best practices.
- Query your logs for the advisory's indicators of compromise, and watch for suspicious traffic on OT ports
44818,2222,102, and502, especially from foreign hosting providers. - For Rockwell Automation controllers, set the physical mode switch to the
RUNposition. - Inspect reusable code modules (Add-On Instructions and shared routines) in Rockwell programs for unexpected changes, per the new July 22 guidance.
- If you suspect targeting, engage your incident response plan and contact the authoring agencies and your PLC vendor.