When Water Systems Are Under Attack: How Aeris IoT Watchtower® Protects Cellular-Connected OT Devices

A response to CISA Advisory AA26-097A

The Threat Is Real — and It’s Escalating

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, EPA, DOE, and U.S. Cyber Command have issued an urgent joint advisory (AA26-097A) warning of ongoing Iranian-affiliated advanced persistent threat (APT) actors actively targeting internet-connected Programmable Logic Controllers (PLCs) and Operational Technology (OT) devices across U.S. critical infrastructure — including water and wastewater systems, energy facilities, and government facilities.

This isn’t a hypothetical. Since at least March 2026, these actors — linked to Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC CEC) — have successfully disrupted PLC operations, manipulated SCADA and HMI displays, exfiltrated device project files, and in some cases, disabled critical shutdown and alarm logic, allowing systems to enter unsafe operating conditions without alerting operators. The result: operational disruption and financial loss.

The targeted devices span major industrial OT vendors — Rockwell Automation®/Allen-Bradley®, Schneider Electric®, and Siemens® — and the attack vector is straightforward: these PLCs were directly internet-exposed and inadequately secured.

The Cellular Blind Spot in OT Security

Here’s the question that should be top of mind for every critical infrastructure operator: Are your OT devices connected to the internet via cellular?

Cellular connectivity has become the go-to choice for remote OT deployments — water treatment pumping stations, remote energy substations, municipal control systems, and field sensors. Cellular offers operational flexibility, avoids the cost and complexity of fixed-line infrastructure, and enables remote monitoring and management of assets in geographically dispersed environments.

But cellular connectivity also means these devices have a direct path to and from the internet — exactly the attack surface that Iranian-affiliated APT actors are exploiting. The CISA advisory specifically calls out that:

“Cellular modems, used for remote field connectivity and access, [must] be secured with strong authentication and updated.”

And further:

“To mitigate unauthorized access to OT via cellular modems, organizations should consider implementing isolated architectures, such as private APN, 5G PNI-NPN, cellular SD-WAN, Zero Trust Network Access (ZTNA), or a site-to-site VPN.” This is precisely where Aeris IoT Watchtower changes the game.

Aeris IoT Watchtower®: Security That Lives at the Network Layer

Aeris IoT Watchtower® is an operational visibility and security solution natively integrated into the Aeris IoT Platform. Because it operates at the cellular network layer — not at the device level — it requires no agents, no hardware changes, and no modifications to deployed OT equipment. You simply turn it on.

This architecture is uniquely powerful in the context of the CISA advisory: the very cellular modems and connections that threat actors can exploit become the enforcement point for your security posture.

Here’s how Aeris IoT Watchtower directly addresses the TTPs and mitigations outlined in AA26-097A:

1. Implement CISA’s IOCs as Blocking Policies — Immediately

CISA’s advisory provides a specific list of IP addresses (Indicators of Compromise, or IOCs) observed in use by Iranian-affiliated APT actors between September 2025 and July 2026. These include addresses associated with foreign hosting providers used to reach PLCs on OT ports 44818, 2222, 102, 502, and modem SSH port 22.

With Aeris IoT Watchtower’s IP & Port-Based Blocking, operators can directly translate CISA’s published IOCs into active blocking policies within the Aeris Management Console — no device-side changes required:

  • Block inbound/outbound traffic to and from the specific threat actor IP addresses listed in the advisory
  • Restrict traffic on OT-specific ports (44818, 2222, 102, 502, 22) to only authorized IP ranges
  • Deny access from unauthorized foreign hosting providers at the network level

This is actionable, operationally immediate, and doesn’t require touching a single PLC in the field.

2. A Meaningful Step on the Path to Zero Trust for Cellular IoT

The CISA advisory explicitly recommends Zero Trust Network Access (ZTNA) as a mitigation for cellular-connected OT devices. Aeris IoT Watchtower is built on a Zero Trust architecture for cellular IoT — and implementing IOC-based blocking policies is a concrete, meaningful step on that journey.

At its core, Zero Trust means: nothing is trusted by default; every connection must be verified and authorized. Aeris IoT Watchtower enforces this principle at the network level:

  • Allowlist-based policies ensure that only known, authorized endpoints can communicate with your PLCs — aligning directly with CISA’s recommendation to “allow only authorized communications between expected control system devices”
  • Device-level enforcement enables granular policy application per IMSI (device identity), so even within a fleet, individual compromised or anomalous devices can be isolated
  • Full traffic blocking by default with selective allowlisting creates a true Zero Trust posture for cellular-connected OT assets
  • FQDN-based policies add an additional control layer for cloud-connected OT management platforms

Implementing IOC blocks is not the end state — it’s a step in the right direction. Aeris IoT Watchtower provides the architecture to progress from reactive blocking to proactive, policy-driven Zero Trust access control across your cellular IoT estate.

3. Visibility Into the Threat Before It Becomes an Incident

The CISA advisory notes that Iranian-affiliated actors were able to operate undetected long enough to exfiltrate project files, modify PLC logic, and disable safety systems. Early detection is critical.

Aeris IoT Watchtower’s Awareness capabilities provide continuous visibility into cellular IoT device behavior:

  • Port, protocol, and endpoint monitoring — immediately surfaces unexpected communications to unauthorized IPs or OT protocol ports
  • Data volume and behavioral baselines — flags anomalous spikes or patterns in device data consumption that may indicate exfiltration or command-and-control (C2) activity
  • Security event identification — detects and surfaces malicious, suspicious, and anomalous behavior based on cellular network traffic patterns and threat intelligence. When a security event is identified, it doesn’t just generate an alert — it becomes the trigger for immediate enforcement action. This direct bridge between visibility and blocking is what sets Aeris IoT Watchtower apart: the moment a threat pattern is recognized at the network layer, operators can convert that finding into an active blocking policy, containing the threat before it advances further into your OT environment. That connection between awareness and action is the foundation of what follows in Section 4.
  • Blocked Traffic Reports — dedicated reporting on traffic blocked by active Watchtower enforcement rules, creating an audit trail for incident response

This level of visibility means that when a PLC starts communicating to a foreign-hosted IP on port 44818 — you know about it before the project file is gone.

4. Threat Intelligence-Backed Malware and C2 Protection — and Immediate Containment

Visibility without action is just awareness. What makes Aeris IoT Watchtower uniquely powerful in a threat scenario like the one described in CISA AA26-097A is that the same network layer that surfaces the threat is also the enforcement point that stops it.

Beyond manually configured IOC blocks, Aeris IoT Watchtower continuously applies threat intelligence to automatically block connections to internet destinations associated with:

  • Ransomware infrastructure
  • Phishing endpoints
  • Command and control (C2) servers
  • Known malware distribution sites

This is particularly relevant given the CISA advisory’s documentation of threat actors using leased, third-party hosted infrastructure as C2 channels. Aeris IoT Watchtower’s threat intelligence layer provides a persistent, automatically updated defense against these evolving C2 networks — without requiring operators to manually track and update every new threat actor IP.

But protection goes beyond blocking known-bad destinations. When Watchtower’s continuous visibility identifies a security event — an anomalous communication pattern, an unexpected port, a spike in outbound data — that detection directly enables containment. At the cellular network layer, blocking is immediate. A device attempting to reach a C2 server is stopped at the network core, not after the connection is established. A PLC exhibiting signs of malware-driven exfiltration can have its data path severed — without anyone setting foot on site. This is malware containment at the point of connectivity: fast, surgical, and operationally non-disruptive to the rest of your fleet.

5. Quarantine and Containment When You Need It Most

If a cellular-connected PLC is suspected of being compromised, operators need the ability to act fast. Aeris IoT Watchtower provides:

  • Device-level suspension and quarantine — immediately cut off a compromised device’s cellular data connectivity without physically accessing the site
  • Manual block controls — administrators can block any individual device or group of devices behaving abnormally

When malware is active or suspected, containment speed is everything. Because Aeris IoT Watchtower operates at the cellular network layer, a compromised device can be isolated the moment suspicious behavior is detected — its connection severed before lateral movement or further exfiltration can occur. The device stays physically in place; only its network path is cut. This lets your team investigate safely, reimage if necessary, and restore operations on your terms — not the attacker’s.

This directly supports the CISA advisory’s guidance to “reimage devices” and “review logs and configurations on all connected devices” — because you can isolate the device first, then investigate safely.

6. Extending Protection to IT Traffic: Where Watchtower Meets SASE

Aeris IoT Watchtower is purpose-built for the cellular IoT and OT domain — the field devices, remote PLCs, and cellular-connected sensors that traditional enterprise security tools were never designed to reach. But critical infrastructure organizations don’t operate in a vacuum. The same networks that carry OT traffic also carry IT traffic — operator workstations, remote access tools, cloud management platforms, and enterprise applications.

For organizations that have already invested in a Secure Access Service Edge (SASE) framework to protect their IT traffic — whether through leading providers such as Palo Alto Networks Prisma SASE®, or others — Aeris IoT Watchtower complements and extends that posture into the cellular IoT layer that SASE alone cannot reach.

Here’s how they work together:

  • SASE secures IT traffic — users, endpoints, cloud applications, and enterprise branch connectivity — applying Zero Trust policies, threat inspection, and secure web gateway controls across the enterprise perimeter
  • Aeris IoT Watchtower secures cellular IoT and OT traffic — field devices, PLCs, sensors, and cellular-connected OT infrastructure — applying Zero Trust policies, IOC blocking, and malware containment at the cellular network core

Together, they create a unified security posture that spans both IT and OT — closing the gap that exists when SASE is deployed without a companion solution for cellular-connected field assets. For security architects evaluating how to extend Zero Trust principles from enterprise IT into the OT environment, Aeris IoT Watchtower is the cellular IoT-native layer that bridges the two worlds. Your SASE investment protects what’s inside the enterprise; Aeris IoT Watchtower protects what’s out in the field.

Mapping Aeris IoT Watchtower to CISA AA26-097A Mitigations

CISA Mitigation (AA26-097A)Aeris IoT Watchtower Capability
Remove PLCs from direct internet exposurePrivate APN / isolated network architecture via Aeris IoT Platform
Block access from unauthorized or threat actor IPsIP & Port-based Allow/Block policies
Implement ZTNA for cellular-connected OTZero Trust application access control via cellular network enforcement
Monitor network traffic for unusual logins and unexpected protocolsContinuous behavioral monitoring — ports, protocols, endpoints, data volume
Query logs for IOCsSecurity event reporting and Blocked Traffic Reports
Quarantine compromised devicesDevice-level suspension, block, and quarantine controls
Implement secure private APN / ZTNA / SD-WANNatively supported via Aeris IoT Platform and Watchtower enforcement
Ensure cellular modems are securedAeris-managed connectivity with policy enforcement at the network core

The Bottom Line: Don’t Let Your Cellular Connection Be the Attack Vector

Iranian-affiliated APT actors are scanning the internet for exposed OT devices. Water systems, energy facilities, and municipal infrastructure are confirmed targets. And where cellular connectivity is the link between the field and the operator — it is also a potential entry point for adversaries.

Aeris IoT Watchtower closes that gap. By operating natively within the cellular network — with no device-side agents required — it gives critical infrastructure operators the ability to:

Translate CISA IOCs directly into blocking policies

Enforce Zero Trust access control at the cellular network layer

Detect anomalous OT device behavior before it escalates

Quarantine and contain compromised devices without an on-site visit

Progress toward a comprehensive Zero Trust posture for cellular IoT

Complement your existing SASE investment with cellular IoT-native security

The threat is active. The IOCs are published. The path to protection for your cellular-connected OT assets starts with Aeris IoT Watchtower®.


To learn more about how Aeris IoT Watchtower® can protect your cellular-connected operational technology assets, contact us or visit aeris.com.

Reference: CISA Advisory AA26-097A — “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure” (Updated July 22, 2026)