Internet exposure of Operational Technology (OT) and Industrial Control Systems (ICS) continues to be a critical
infrastructure security issue despite decades of raising awareness, new regulations and periodic CISA advisories]. Moreover, opportunistic attackers are increasingly abusing this exposure at scale — sometimes with a very lax targeting rationale driven by trends, such as current events, copycat behavior or the emergencies found in new, off-the-shelf capabilities or hacking guides.