| 01 | Internet-exposed PLC or HMI; unnecessary remote/vendor path | Direct access collapses the boundary around the physical process. | Remove exposure; controlled gateway; MFA; allowlists; monitor remote sessions. |
| 02 | Default, shared, stale or weak credentials; no MFA | Recent water incidents repeatedly leverage poor identity controls. | Unique accounts; vaulting; MFA; revoke departures; just-in-time vendor access. |
| 03 | Unknown or incomplete OT inventory | An owner cannot patch, isolate, monitor or recover an asset it cannot name. | Field-verified inventory; owners; firmware; network paths; criticality; evidence. |
| 04 | Flat IT/OT network or permissive firewall path | One compromised endpoint can reach process control. | Zones and conduits; OT DMZ; deny by default; separate identities; bastion. |
| 05 | Outdated firmware and known exploited vulnerabilities | Publicly known weaknesses shorten attacker effort. | CISA KEV/advisory matching; vendor-approved remediation; compensating control. |
| 06 | Unauthorized controller or configuration change without a trusted baseline | Operators can be locked out or process logic altered. | Gold project/config; hashes; change windows; write monitoring; restore tests. |
| 07 | Weak logging and no ICS-aware monitoring | Writes, failed logins and path violations may be invisible. | Central logs; passive OT telemetry; config drift; maintenance-window correlation. |
| 08 | Untested or online-only backups; no manual procedure | Recovery fails exactly when operations depend on it. | Offline known-good copies; restore drill; local and manual operating plan. |
| 09 | Alarm or telemetry manipulation and loss of view | A trusted-looking screen can drive the wrong physical action. | Independent sensing; plausibility checks; field verification; alarm integrity. |
| 10 | Vendor governance and human-factor gaps | Former staff, informal remote help and undocumented SOPs create persistent paths. | Owner, authorization, expiry, competency, SOP and attestation obligations. |