Skip to content
DnsLister Forum

Where domain hunters compare notes

427 or 4 Devices?: Measuring Internet-Exposed Industrial Infrastructure in the UK

This is a classic example of the gap between theoretical attack surface and real-world risk. Flare’s team ran a scan on UK-based industrial infrastructure and found a massive discrepancy between the number of devices Shodan reports (427) and the number of unique, identifiable industrial assets (4).

Technical Breakdown

  • The Core Issue: The "427" figure is inflated by virtual hosts, load balancers, and CDN nodes that share IPs with industrial systems. The "4" represents actual, discrete PLCs, RTUs, or HMIs with direct internet exposure.
  • Protocols Found: The scan focused on common ICS protocols (Modbus, S7, BACnet, etc.) exposed on the open internet. The low count suggests most UK critical infrastructure is behind proper OT network segmentation or VPNs.
  • Attribution: The research highlights that Shodan-style surface scanning is a poor indicator of true exposure for targeted threat actors. An APT would use passive DNS, certificate transparency logs, and lateral movement from compromised IT networks to find the real 4 devices.

Defense

Don't rely solely on internet-facing scans for your OT asset inventory. The real risk is not the 4 exposed devices (which are likely honeypots or misconfigured test benches), but the 423 IPs that appear to be industrial but are actually IT infrastructure. Ensure your OT network is air-gapped or uses a properly configured PAM/ZTNA solution, not just a firewall rule.

Source: https://flare.io/learn/resources/blog/internet-exposed-industrial-infrastructure-uk

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *