Polish power plant OT network breach

Attackers shut down a steam turbine and process-water treatment system at a Polish combined heat and power plant this month. The plant supplies heat to roughly 50,000 residents. Recovery was still in progress while the intruders remained active inside the network.
The entry point was the private cellular network the grid operator uses to reach remote industrial equipment. Not a phishing email, not a compromised VPN credential, not a vulnerability in a public-facing application. The operational technology comms layer itself was the way in.
This matters because OT networks and the radio or cellular links that connect them to field devices are routinely treated as inherently separate from the threat surface that gets tested and monitored. In practice, that separation is often more assumed than enforced. Private cellular links, SCADA comms channels, and remote access paths to industrial control systems need to be assessed with the same rigour applied to anything else.
If your organisation operates infrastructure with remote OT connectivity and hasn't had that attack surface formally assessed, this is a reasonable prompt to start that conversation.
Concerned this affects you?
We can assess your exposure and tell you plainly where you stand.