Walk the footprint of an oilfield services company, a water district or a small utility and you will find plenty of small boxes: a cellular modem on a tank battery, a remote terminal unit at a wellhead, a monitor on a lift station or a gateway bolted inside a cabinet at a remote pump site. They were installed to save a truck roll, and they work quietly for years. They are also frequently missing from asset lists, running default settings and exposed to the public internet.
These devices bridge the field to the control room. If an attacker reaches them, they may reach whatever they talk to.
Why these devices get forgotten
- They were installed by a vendor, an integrator or a field technician, not by IT.
- The cellular plan may be on a separate account that finance pays without question.
- Nobody logs into them after commissioning.
- They are not on the corporate network, so standard tools never see them.
- Replacing them feels risky and expensive, so they stay.
Forgotten does not mean harmless.
What can go wrong
Several common problems appear in field gateways.
- Default or shared passwords. Many devices ship with well-known credentials, and the same password may be used across dozens of sites.
- Public addresses. Some cellular plans assign addresses reachable from the internet, so a device may be visible to scanners all day.
- Open management services. Web interfaces, remote login services and unneeded protocols left enabled.
- Old firmware. Updates are rarely applied because the devices are remote.
- Weak or no logging. Nobody would notice an unauthorized change.
- Trusted paths into the control network. A gateway might connect directly to controllers with no filtering.
Government agencies, including CISA, have repeatedly warned that internet-exposed operational technology with default credentials is a practical target. That guidance is worth reading in its general form.
Step one: find them
You will need several sources.
- Carrier invoices and portals. Every active line is a device.
- Vendor and integrator records and purchase history.
- Field staff knowledge. Ask technicians and operators where the boxes are.
- Site walks, photographing each cabinet with device labels and serial numbers.
- Network scans of the address ranges your carrier plan uses, performed with appropriate authorization.
Build a register with location, make, model, firmware, purpose, owner, connected equipment and cellular account details.
Step two: remove public exposure
Work with the carrier to move devices to private network arrangements where available, so they are not reachable from the open internet. Where that is not possible, restrict inbound access to specific addresses, disable unused services and require strong authentication. Ask your vendor what the supported secure configuration looks like.
Step three: fix credentials
Change default passwords, and avoid reusing the same password across sites. Store credentials in a controlled password vault, not in a spreadsheet or on the cabinet door. Remove accounts that are no longer needed, including vendor accounts for people who have left.
Step four: control updates
Establish a process for reviewing vendor security advisories and applying firmware updates in planned windows. Test updates on a spare unit if the process depends on it. Where a device is no longer supported, plan its replacement and place compensating controls around it in the meantime.
Step five: limit what the gateway can reach
Treat the gateway as an untrusted boundary. Allow it to communicate only with the specific systems and ports required. If it must reach controllers, filter that path. Keep it away from business systems and general internet use.
Step six: add visibility
Where feasible, collect basic logs and alerts: configuration changes, failed logins and unexpected reboots. Track data usage on the cellular plan, since a sudden spike can signal misuse. Set up a simple check for devices that go silent.
Step seven: write down the rules
Add field gateways to your OT security policy and change process. Require approval before installing new ones, record them in the register and review the list yearly.
What about regulated environments
If you operate pipeline or electric assets, your regulatory frameworks may bring these devices into scope depending on function and connectivity. Even outside of regulation, ISA/IEC 62443 concepts such as zones and conduits offer a useful way to think about them.
Getting started
Begin with the carrier invoice: list the lines, and ask who owns each one. Ironfield Cyber helps operators discover and secure remote field devices and fold them into a practical OT security program. If you suspect you have more boxes in the field than your records show, we can help find them.