
70% of Internet-Exposed ICS Hosts Are on Consumer and Mobile Networks
Approximately 70% of the roughly 134,000 Internet-exposed ICS hosts Censys observes globally sit on consumer and mobile networks.
This creates a security problem that goes beyond exposure. When industrial control systems (ICS) are connected through mobile networks, registration data often points to the telecommunications provider rather than the organization operating the equipment. Researchers can see the exposed device, but may have no reliable way to identify and notify its owner.
The result is an exposure notification gap: some of the Internet-connected systems that are most important to critical infrastructure can be visible to attackers while remaining difficult for defenders to trace back to the organizations responsible for securing them.
The 2026 Censys State of the Internet Report, which will be public on October 6, examines this exposure notification gap and the broader shifts taking place across Internet-exposed ICS infrastructure.
Pre-Register for the 2026 State of the Internet Report
Each year, Censys’ State of the Internet Report analyzes Internet-wide trends to identify meaningful shifts in the technologies, infrastructure, threats, and behaviors shaping the public Internet. Sign up to receive your copy as soon as it publishes on October 6.
Why the Exposure Notification Gap Matters
Exposure notification can significantly reduce Internet-facing risk. Threat researchers (like Censys ARC), CERTs, and vendors find an exposed device, identify who runs it, and notify them so it can be remediated before it is exploited. It’s an effective means of intervention, so long as all the pieces are there.
But for many ICS devices, they aren’t. These devices often sit in substations, pump houses, remote well sites, and unstaffed automation environments where cellular connectivity may be the best (or only) option. While that connectivity makes the equipment manageable, it can also sever the link between the exposed IP address and the organization responsible for it.
The result is that a researcher who finds an exposed PLC on a mobile carrier’s address space may only be able to identify and notify the carrier, which has no operational relationship with the device or authority over its configuration. The utility or manufacturer that operates it may never hear about the exposure.
Recent attacks against water and wastewater systems demonstrate why this gap matters. On July 30, 2026, CISA issued an alert warning that threat actors were targeting Internet-exposed PLCs. According to CISA, attackers accessed exposed controllers, changed passwords to lock operators out, and altered device IP addresses to disconnect them, resulting in boil-water notices and extended periods of manual operation.
CISA specifically warned that cellular modems installed by operators, vendors, or system integrators may not be documented or included in routine attack surface scans. A joint FBI/EPA public service announcement issued the same day identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers as targeted equipment and reported incidents across at least seven states.
Read Censys ARC’s Analysis of the CISA Advisory
Global ICS Exposure Is Growing and Shifting
Censys observes an average of 134,000 distinct hosts running ICS services and tooling exposed on the Internet in early 2026, up roughly 4% from about 129,000 in 2024.
North America Accounts for 38% of Global ICS Exposure

North America has more ICS exposures than any other region, accounting for more than 38% of all global ICS exposures.
The United States Has Roughly as Many ICS Exposures as All of Europe

The United States accounts for 32% of global ICS exposure on its own, with over 40,000 exposed hosts, which is roughly the same share now held by the entire European region combined.
Turkey ranks second globally with fewer than 10,000 exposed hosts. The US total is more than four times larger.
Europe’s Share of Global ICS Exposure Is Declining
Europe fell from 36.5% of the global total in 2024 to 32% in early 2026, with France, Italy, and Belgium together accounting for approximately 85% of that decline.
Europe’s regulatory and commercial environment differs from other regions, including evolving cybersecurity requirements such as NIS2, which may be one factor contributing to this shift. The data alone, however, does not establish causation. Europe’s declining ICS exposure is a bright spot and raises interesting questions about what may be driving this progress and whether it can be replicated elsewhere in Europe and around the world.
Get the Full 2026 State of the Internet Report
The State of the Internet Report is Censys’ annual analysis of Internet-wide trends across the technologies, infrastructure, threats, and behaviors shaping the public Internet. This year’s edition covers:
- The Internet at Large: An examination of emerging trends across hosts, services, networks, and geographies.
- The Internet’s Response to Emerging Vulnerabilities: A study of how quickly software ecosystems respond to vulnerability disclosures.
- Industrial Control Systems and Critical Infrastructure: An assessment of how global ICS exposures shift across geographic regions and network types over time.
- Threat Infrastructure Trends: Where threat infrastructure runs, how it clusters, and which direction it’s moving.
- AI Infrastructure: An analysis of adoption and exposure trends for various internet-exposed AI-related technologies.
Pre-register to receive the report when it publishes on October 6, 2026.

