As operational technology (OT) and industrial control systems (ICS) grow increasingly interconnected with enterprise IT networks, cloud infrastructure, and smart field instrumentation, the attack surface for critical infrastructure has expanded dramatically. Threat actors no longer just target corporate email servers; they actively weaponize industrial protocols, compromise Human-Machine Interfaces (HMIs), and manipulate programmable logic controllers (PLCs).
In an industrial environment, a security breach is rarely loud or obvious. Attackers often dwell quietly for months, mapping physical processes and studying safety loops. Spotting the subtle indicators of a compromise early can mean the difference between minor remediation and a catastrophic physical safety incident. Below are the 20 definitive signs that your OT network has been compromised.
Top 20 Signs Your OT Network Is Compromised
1. Unscheduled PLC Logic Uploads or Modifications
Compilers, engineering workstations, or remote configuration tools record code changes, block downloads, or ladder logic updates outside of authorized maintenance windows. Attackers often alter PLC logic to subtly change physical process thresholds, modify timer values, or plant hidden trapdoors without throwing immediate error codes on the plant floor.
2. Anomalous Polling Rates on Modbus, DNP3, or OPC UA Protocols
A sudden, unexplained spike in read/write requests or unusual polling frequency across industrial control protocols between nodes that rarely communicate. Threat actors use custom scripts or legitimate protocol commands to harvest register values, map out input/output (I/O) maps, and discover vulnerable firmware versions across Purdue Level 1 and Level 2 zones.
3. Ghost Assets and Unregistered IoT/MIoT Endpoints
Passive network monitoring detects new medical IoT (MIoT), industrial IoT (IIoT) sensors, or wireless maintenance gateways appearing on the network without matching inventory records. Threat actors frequently deploy rogue hardware footholds or compromised smart field devices to bypass perimeter firewalls and establish secondary command-and-control channels.
4. Unexpected Firmware Mismatches and Checksum Failures
Periodic file-integrity monitoring (FIM) or cryptographic hash verification reveals that device firmware binaries differ from baseline vendor configurations. Attackers aiming for persistent access will reflash industrial controllers or RTUs with modified firmware to survive cold reboots and maintain control even after temporary network isolation.
5. Out-of-Hours Engineering Workstation Remote Desktop Sessions
Active RDP, VNC, or proprietary engineering software sessions originating from corporate IT subnets or external VPNs into Level 2 HMI stations during non-operational shifts. Engineering workstations hold the master keys to the physical process. Unscheduled, late-night remote access is a classic indicator of credential stuffing or lateral movement from a breached enterprise zone.
6. Unauthorized Modbus Function Codes Executed on the Wire
Deep-packet inspection alerts fire on dangerous or administrative Modbus function codes (such as memory writes, device resets, or program downloads) originating from non-engineering IP addresses. Standard operators read register data, but they rarely execute low-level programming commands. Seeing administrative function codes travel from unexpected client nodes signals active reconnaissance or malicious command injection.
7. Unexplained Inter-Subnet Traffic Crossing Purdue Boundaries
Network traffic flows directly between lower-level safety or control zones (Levels 0/1) and the corporate enterprise network (Level 4) without traversing designated industrial demilitarized zones (DMZs). This indicates that Purdue Reference Model segmentation has been bypassed, either through misconfigured firewalls or unauthorized bridging cables installed by third-party contractors.
8. Sudden Latency Spikes in Real-Time Control Loops
Control loop response times, sensor feedback intervals, or SCADA display refresh rates experience intermittent, unexplainable lag. Packet flooding, ARP poisoning, or unauthorized data exfiltration routines running across shared industrial switches can starve deterministic control traffic of necessary bandwidth.
9. Anomalous DNS Queries from Fixed-Function OT Servers
Industrial data historians, engineering stations, or HMI servers configured exclusively for local operations begin issuing external domain name system (DNS) requests. Fixed-function OT nodes have no business querying external internet domains. Such requests usually point to malware attempting to contact external command-and-control (C2) infrastructure.
10. Unrecognized Scheduled Tasks or Local User Accounts on HMIs
Endpoint monitoring reveals newly created administrator accounts, background service modifications, or hidden batch scripts on Windows-based HMI or engineering servers. Attackers establish persistence by creating backdoor accounts or leveraging native operating system utilities (Living-off-the-Land techniques) to maintain access after initial credential rotation.
11. Modified or Disabled Anti-Malware and Logging Agents
Security event logs stop streaming abruptly, or local host-based security tools on engineering workstations are systematically disabled or uninstalled. Sophisticated threat groups actively blind security operations centers (SOCs) by terminating telemetry daemons before launching disruptive payloads against physical processes.
12. Unexpected ARP Table Flurries and MAC Spoofing Indicators
Network switches log rapid changes in MAC-to-IP address mappings or detect duplicate IP addresses on critical control subnets. Attackers employ ARP spoofing or man-in-the-middle techniques to intercept unencrypted industrial traffic, capture engineering credentials, or manipulate sensor feedback loops.
13. Unauthorized Changes to HMI Graphic Screens and Alarm Thresholds
Plant operators report subtle modifications to graphical mimic displays, missing alarm indicators, or altered safety threshold setpoints on local screens. By blinding operators or altering visual feedback, attackers prevent human supervisors from noticing that physical processes are being driven into hazardous or unstable operating states.
14. Abnormal Outbound Data Transfers During Scheduled Downtime
Network telemetry registers high-volume data egress moving outside the facility perimeter during scheduled plant maintenance or overnight shutdown windows. Attackers often mask data exfiltration-such as stealing proprietary industrial recipes, CAD files, or network topologies-during periods when heavy network traffic is expected.
15. Serial-to-Ethernet Gateway Configuration Alterations
Unauthorized setting changes occur on legacy protocol converters translating traditional RS-485/RS-232 serial traffic into modern TCP/IP packets. Legacy serial devices lack native security features. Compromising the conversion gateways allows attackers to inject malicious commands straight into older PLCs that cannot validate packet authenticity.
16. Unverified USB Mass Storage Mount Events on Air-Gapped Stations
Endpoint logs record unauthorized USB flash drive attachments, file transfers, or peripheral mount events on isolated engineering workstations. Despite air-gap policies, physical media remains a primary vector for introducing malware bypasses into isolated industrial networks.
17. Stale or Orphaned VPN Credential Reuse from Third-Party Vendors
Active VPN authentication tunnels originate from vendor accounts that belong to personnel who no longer service the facility or outside agreed maintenance windows. Dormant third-party credentials are a prime target for credential-stuffing campaigns, offering a trusted path directly into the heart of the OT network.
18. Safety Instrumented System (SIS) Communication Disruptions
Intermittent heartbeat failures, diagnostic alarms, or communication timeouts logged between the primary control system and independent safety PLCs. Advanced cyber-physical attacks often target safety systems first, attempting to disable emergency shutdown (ESD) mechanisms before initiating physical process disruption.
19. Unusual Execution of Native Administrative Binaries
Standard system utilities like PowerShell, WMIC, or command prompt execute unusual strings, script blocks, or encoded commands on engineering servers. Threat actors use built-in administrative tools to perform internal reconnaissance, discover network shares, and move laterally without downloading noisy external malware files.
20. Baseline Configuration Drift Across Plant Network Switches
Automated configuration management tools flag unexpected VLAN modifications, port mirroring adjustments, or spanning-tree protocol changes on industrial switches. Attackers alter network switch configurations to mirror traffic to compromised listening ports, enabling them to harvest raw packet data and industrial credentials across the plant floor.
Integrating Advanced OT Visibility Solutions for Early Detection
To catch these subtle indicators before they escalate into physical emergencies, modern industrial enterprises deploy specialized continuous threat monitoring platforms. While established asset discovery and monitoring tools from legacy vendors like Nozomi Networks, Dragos, Claroty, Shieldworkz, and TXOne provide essential network telemetry and behavioral analysis, advanced platforms bridge the critical gap between raw packet data and real-time incident detection. By unifying visibility across Purdue levels zero through four, industrial organizations can instantly surface anomalous network behavior and protect their critical infrastructure.
Conclusion
Recognizing that an OT network is compromised requires shifting focus from traditional IT indicators-like encrypted files or database exfiltration-to the subtle digital footprints left by attackers manipulating physical control loops. Monitoring for unauthorized PLC logic changes, anomalous protocol polling, and segmentation drift ensures that security teams can intercept threats early. Implementing these 20 warning signs into your continuous monitoring strategy transforms industrial cybersecurity from a reactive posture into an active defense, safeguarding plant availability, regulatory compliance, and human safety.