What are the most common security mistakes in industrial networks (OT/ICS)?

The most frequent (and most dangerous) OT security mistakes in Poland

#MistakeReal-world consequence seen in audits
1No network segmentation between IT and OTRansomware from office network encrypts PLCs in <4 h
2Default or no passwords on PLCs, HMI, SCADAAttacker gains full control in minutes
3Outdated, unpatched systems (Windows XP, Siemens S7-300 without updates)Exploits from 2010 still work
4Direct internet exposure of OT devicesSystems visible in Shodan → instant compromise
5No logging or monitoring in OTAttack goes undetected for months
6Shared accounts & no MFA for critical systemsOne compromised engineer credential = full plant access
7USB devices without control90 % of OT infections in Poland start from an infected pendrive

Correct approach (mandatory for NIS2 and ISO/IEC 62443)

Fixing these seven mistakes eliminates ~95 % of real-world OT attacks I investigate.