Why ICS is vulnerable
Many industrial protocols (Modbus, classic S7, BACnet/IP, IEC 104 without 62351) lack strong mutual authentication. ARP spoofing, rogue gateways, or compromised jump hosts can place an attacker on-path with little protocol-level resistance. Stuxnet famously replayed normal process values to operators while damaging equipment — a classic MitM integrity attack.Observable patterns
- Unexpected ARP/gateway changes on OT VLANs
- Duplicate CIP/Modbus masters
- Latency or sequence anomalies on telecontrol links
- Internet-facing “proxies” that terminate ICS protocols