
Field Notes
Grid Intrusions as Geopolitical Signal: What State-Linked OT Cyberattacks Reveal Before the Headlines Do
TL;DR: State-linked intrusions into US and allied grid and OT systems, from Volt Typhoon's multi-year US foothold to the April 2026 Iranian PLC campaign that intensified six weeks into open Iran-Israel-US conflict, track geopolitical escalation calendars rather than opportunistic criminal timing. The industry's 42-day average detection dwell time, against a 5-day best case at OT-visibility leaders, decides whether that signal reaches a risk committee before an escalation or only after it.
Key takeaways:
- President Trump threatened to bomb Iranian power infrastructure directly in the weeks before CISA's April 7, 2026 advisory, which stated that targeting had "recently escalated, likely in response to hostilities."
- NERC has said it is coordinating with the Department of Energy and the Electricity Subsector Coordinating Council to monitor the grid in step with active conflict windows, rather than waiting for incident reports.
- Bitsight tracked 170,000 to 180,000 monthly internet-facing ICS/OT exposures in 2025 and concluded flatly that "awareness does not equate to meaningful remediation."
CISA's April 7, 2026 advisory on Iranian-affiliated actors exploiting programmable logic controllers across US water, energy, and government facilities landed in the sixth week of open Iran-Israel-US hostilities, days after President Trump threatened to bomb Iranian power infrastructure directly.¹ The advisory itself said targeting had "recently escalated, likely in response to hostilities." Most companies routed it to the SOC.

The Geostrategic Record Energy Risk Teams Keep Filing Under IT
Grid and OT intrusion activity clusters around geopolitical escalation, not opportunistic criminal timing.
- Volt Typhoon, disclosed February 2024. CISA, NSA, and FBI found the Chinese state-linked group held footholds in US energy, water, and transportation IT for at least five years, including four years extracting domain controller credentials, using only legitimate system tools. Agencies assessed with high confidence it was pre-positioning for disruption "in the event of a major crisis or conflict."²
- Sandworm-attributed attack on Polish energy sites, December 29, 2025. Attackers entered through internet-facing edge devices, then damaged remote terminal units and wiped human-machine interface data across 30-plus wind, solar, and heat sites. CISA's February 10 alert did not name the actor; ESET research it cited attributed the campaign to Russia-aligned Sandworm.³
- Iranian PLC campaign, April 7, 2026. CISA assessed IRGC Cyber Electronic Command-affiliated actors, potentially including CyberAv3ngers, were exploiting Rockwell Automation and Siemens PLCs across energy, water, and government-facility networks, six weeks into direct Iran-Israel-US conflict.¹
- CSIS-documented volume growth. Energy accounted for roughly 40 percent of critical infrastructure cyberattacks in CSIS's 2023 baseline study; US energy and utility organizations logged more than 1,160 weekly attack attempts per organization in 2024, up 70 percent over 2023.⁴

What Volt Typhoon, Sandworm, and the Iranian Campaigns Have in Common: The Geostrategic Read
Dragos tracked 26 threat groups active against industrial targets worldwide, 11 active in 2025, with naming conventions that map onto state cyber commands rather than criminal syndicates: PYROXENE and BAUXITE overlap with IRGC-CEC and CyberAv3ngers, VOLTZITE with Volt Typhoon, and ELECTRUM with Sandworm.⁵
- Pre-positioning precedes disruption by months or years, tied to named state cyber commands. Volt Typhoon sat inside IT environments for up to five years before disruptive intent was assessed. The Iranian PLC campaign intensified in week six of conflict, and Sandworm's Polish attack came as the Ukraine war entered its fourth year, each tied by US or allied CERT assessment to a specific state cyber command.
- Detection speed determines whether the signal reaches decision-makers in time. Dragos found average OT dwell time industry-wide at 42 days, against 5 days for organizations with full OT visibility.⁵ That 37-day gap separates a geopolitical risk read that arrives before an escalation from one that arrives after.

Building the Geostrategic Watch Function OT Risk Data Actually Supports
Bitsight's 2026 Global State of ICS/OT Exposure report counted 170,000 to 180,000 monthly internet-facing ICS/OT exposures in 2025, noting that "awareness does not equate to meaningful remediation."⁶ NERC says it is monitoring the grid with active conflict windows, coordinating with the Department of Energy and the Electricity Subsector Coordinating Council.¹
- Route named-actor advisories to the risk committee, not only the SOC. A CISA advisory naming an IRGC-CEC or Sandworm-linked group is a state-intent data point that should trigger the same escalation review as a sanctions action, the same day, not after incident response closes the ticket.
- Track dwell time as a geopolitical indicator, not just a security metric. A 42-day average against a 5-day best case is a measurable gap between what the network knows and what the risk function is told, a geopolitical risk capability to close.
- Map PLC and vendor exposure to the state actors active against that vendor class. Rockwell/Allen-Bradley and Siemens S7 exposure has a named adversary attached; inventories that cannot answer "which PLCs match this week's advisory" cannot support this.
- Treat OT intrusion volume shifts as leading indicators of state posture, not lagging incident counts. A campaign that escalates before a public conflict declaration is functioning as intelligence.
Fortius Intel note: The SOC will keep asking whether a PLC was patched. The risk function's job is to ask why a state-linked actor decided this was the week to try. Both questions deserve an answer, and only one of them is currently getting routed to the board.
Methodology: Analysis draws on CISA Advisory AA26-097A (April 7, 2026), CISA Advisory AA24-038A on Volt Typhoon (February 7, 2024), CISA's alert on the Poland energy sector incident (February 10, 2026), the Dragos 2026 OT Cybersecurity Year in Review (February 17, 2026), CSIS's April 2, 2026 analysis of Iran-linked energy sector threats, and Bitsight's 2026 Global State of ICS/OT Exposure report (referenced June 30, 2026). All cited sources are publicly available.
Footnotes
1 Cybersecurity and Infrastructure Security Agency (CISA), Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure, Advisory AA26-097A, April 7, 2026. Assessed IRGC-CEC-affiliated actors exploiting Rockwell Automation/Allen-Bradley and Siemens S7 PLCs across energy, water/wastewater, and government-facility sectors; advisory states targeting "recently escalated, likely in response to hostilities." Available at https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a. NERC monitoring context and PLC exposure figures (600,000 to 2 million PLCs across US critical infrastructure) via Utility Dive, "NERC is 'actively monitoring the grid' following Iran-linked cyber threat," April 8, 2026. Available at https://www.utilitydive.com/news/nerc-cisa-iran-war-cyber-hacking/816914/.
2 CISA, NSA, FBI, and partner agencies, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure, Advisory AA24-038A, February 7, 2024 (updated March 7, 2024). Volt Typhoon dwell time of at least five years, four-year credential extraction from domain controllers in one case, living-off-the-land technique assessment, and pre-positioning for disruption during "potential geopolitical conflicts." Available at https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a.
3 CISA, Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps, February 10, 2026. December 29, 2025 attack via internet-facing edge devices; damaged RTUs, corrupted OT firmware, wiped HMI data; disrupted monitoring at 30-plus wind, solar, and heat generation sites; default-credential exploitation. Available at https://www.cisa.gov/news-events/alerts/2026/02/10/poland-energy-sector-cyber-incident-highlights-ot-and-ics-security-gaps. Sandworm attribution via Industrial Cyber, "CISA alerts on OT vulnerabilities after Poland energy attack damaged RTUs and wiped HMI data," citing ESET research. Available at https://industrialcyber.co/industrial-cyber-attacks/cisa-alerts-on-ot-vulnerabilities-after-poland-energy-attack-damaged-rtus-and-wiped-hmi-data/.
4 Center for Strategic and International Studies (CSIS), Leslie Abrahams and Lauryn Williams, Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure, April 2, 2026. Energy sector share of critical infrastructure cyberattacks (approximately 40 percent, 2023 study cited); more than 1,160 weekly attack attempts per US energy/utility organization in 2024, a 70 percent year-over-year increase; early March 2026 Iran-linked attack on Stryker as part of a multidomain response to US-Israeli airstrikes. Available at https://www.csis.org/analysis/iran-conflict-heightens-cyber-threats-us-energy-infrastructure.
5 Dragos, 2026 OT Cybersecurity Year in Review, February 17, 2026. 26 threat groups tracked worldwide, 11 active in 2025; PYROXENE and BAUXITE overlaps with IRGC-CEC/CyberAv3ngers activity, VOLTZITE overlap with Volt Typhoon, ELECTRUM overlap with Sandworm; industry-wide average OT dwell time of 42 days versus 5 days for organizations with full OT visibility; 119 ransomware groups affecting 3,300 industrial organizations in 2025, a 64 percent year-over-year increase. Available at https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware.
6 Bitsight, 2026 Global State of ICS/OT Exposure, referenced in "Power Grid Cyber Security Risk," Bitsight blog, June 30, 2026. 170,000 to 180,000 monthly internet-facing exposures observed across monitored ICS/OT protocols in 2025. Available at https://www.bitsight.com/blog/power-grid-cyber-security-risk.
About the author
Jay Bimbrah, Co-Founder & COO. A former Scotland Yard counter-terrorism investigator, Jay has advised EMEA tier-1 banks and Lloyd's market firms on distinguishing real exposure from theoretical risk.