What MITRE ATT&CK ICS T0883: Internet Accessible Device (Initial Access) requires
MITRE ATT&CK ICS T0883 covers adversary access to industrial control devices directly exposed to the internet without proper authentication, firewall, or VPN protection. Shodan, Censys, and ZoomEye continuously index thousands of exposed PLCs, HMIs, SCADA endpoints, building automation panels, and energy management systems globally. Compliance obligations include NERC CIP-005 (Electronic Security Perimeters), NERC CIP-007 (Systems Security Management), IEC 62443-3-3 SR 5.1 (Network Segmentation), NIST SP 800-82 Rev 3, ENISA OT Security Guidance, CISA Cross-Sector Cybersecurity Performance Goals, and NIS2 Article 21(2)(c) for critical infrastructure.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0883/
SHA-256 integrity: b9bac4b7d9a6772da2adece21f0ff868c038de187520ca48014bdb21b95efc82
Primary Citations — 8 traced to source
- MITRE ATT&CK ICS Technique T0883: Internet Accessible Device (https://attack.mitre.org/techniques/T0883/)
- NERC CIP-005-7: Electronic Security Perimeters
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access