A shop-floor controls engineer at a High Point furniture plant will read the August headlines about the VMware and Windows bugs, patch the servers his managed IT provider flags, and never once think about the fire-alarm management console in the electrical room or the Nastran box the mechanical team uses to run stress models. Both showed up in CISA advisories the same week. Neither will get touched for months.
That gap is the whole problem with operational technology security, and the week of August 18 to 20, 2026 is a clean example of it. CISA published three industrial control system advisories that week. None of them is a screaming internet-wormable zero-day. None sits on CISA's Known Exploited Vulnerabilities list. And that is precisely why, on most North Carolina plant floors, nobody will do anything about them.
The bottom line for a 20 to 250 person manufacturer: the industrial-control flaw that eventually costs you a shift is almost never the one on the news. It is the boring advisory that sat unpatched because it never felt urgent. Preferred Data Corporation has watched that pattern play out in Piedmont Triad plants since 1987. Below is what these three advisories mean for your building, and what to fix first.
Worried your plant floor and building systems are on the same flat network as your office PCs? Preferred Data Corporation maps OT and IT exposure for North Carolina manufacturers, and the assessment is passive: we watch and map, we do not poke your running controls or reboot anything on the floor. Call (336) 886-3282 or request an OT security assessment.
What did CISA flag for industrial systems the week of August 18, 2026?
CISA released three ICS advisories between August 18 and 20, 2026, as tracked for critical-infrastructure operators by WaterISAC, covering a building fire-and-life-safety management app, engineering simulation software, and a network-analysis tool. Two touch equipment that sits inside North Carolina factories and commercial facilities right now. Here is the plain-English version.
| Advisory (date) | Product | Flaw and CVE | Who runs it |
|---|---|---|---|
| ICSA-26-232-01 (Aug 20) | Johnson Controls Simplex Incident Manager | Credentials stored unencrypted in memory (CVE-2026-27875); a low-privilege local user can pull passwords and tokens | Facilities, life-safety, larger plants |
| ICSA-26-230-02 (Aug 18) | Siemens Simcenter Nastran / Femap | Stack overflow to remote code execution when a booby-trapped file is opened (CVE-2026-59086) | Mechanical and structural engineering teams |
| ICSA-26-230-01 (Aug 18) | CISA Malcolm | Network traffic-analysis tool; relevant mainly to teams already running it | Security and OT monitoring teams |
The Johnson Controls advisory lists Critical Manufacturing and Commercial Facilities among the affected sectors, and Johnson Controls has shipped a fixed version. The Siemens flaw hits Simcenter Nastran and Femap builds before version 2606, and it fires only when someone opens a malicious model file, which is a phishing problem wearing an engineering hat.
Key takeaway: None of these three sits on CISA's Known Exploited Vulnerabilities list. That is the difference between a CISA ICS advisory and the KEV catalog, and it is exactly why these will age quietly on your network. No confirmed exploitation is not the same as safe; it usually just means nobody has looked.
Why is an advisory with no known exploitation the dangerous one on a plant floor?
Because OT gear does not get patched on IT's schedule, and attackers know it. A flaw with no confirmed exploitation today is a quiet foothold the day someone does get on your network, and on a plant floor they can sit on that foothold for weeks before anyone notices.
Put a number on "weeks." In its 2026 OT/ICS Year in Review, the OT security firm Dragos found the average dwell time for ransomware inside operational-technology environments was 42 days. That is six weeks an intruder can spend mapping your controls network before doing anything you would notice. Dragos tracked 119 ransomware groups hitting industrial organizations in 2025, up from 80 the year prior, and found manufacturing made up more than two-thirds of the victims.
The part that should change how you budget: Dragos also found that 26% of the ICS advisories it reviewed shipped with no vendor patch or mitigation at all. When a fix does exist, as it does for the Johnson Controls and Siemens flaws this week, applying it is the easy scenario. A quarter of the time you are managing exposure you cannot patch, which means segmentation and monitoring are the actual controls, not a software update.
Chasing the KEV catalog is a fine IT patch strategy and a lousy OT one, and most of your vendors will not tell you that because their tooling is built around the KEV list. Systems that get exploited fast land on that list because they are easy to reach and worth reaching. Your fire-panel console and your engineer's simulation box are worth reaching too. They are just slower and quieter, so they never make the urgent list and never get scheduled.
Why does the Johnson Controls Simplex flaw matter more than it looks?
Because building and life-safety systems are almost always on the same flat network as everything else, and almost never in anyone's patch plan. The Simplex Incident Manager flaw (CVE-2026-27875) lets a local user with low privileges read credentials straight out of memory. On paper that sounds minor. In a real facility it is a pivot.
Walk a typical Piedmont Triad plant with us and the pattern repeats. The fire-alarm and incident-management console, the HVAC and building-automation controllers, the badge system, and the plant-floor HMIs all trace back through unmanaged switches to the same address space as the front-office PCs. Nobody designed it that way on purpose. It grew, one contractor install at a time, and the integrator who wired the fire panel was never asked to segment it. So a credential lifted from a building-systems box is a credential that may work somewhere that matters.
The other reason these systems lag is real and worth stating plainly: you often cannot patch them on your own timeline. A fire-and-life-safety system is a regulated, inspected asset, and the OEM or the integrator has to sign off on firmware changes. A controls PC certified by the machine builder on a specific software version voids its support if you patch it without approval. That is why "just update it" is not an answer on a plant floor, and why the work is scheduling, validation, and isolation rather than a Patch Tuesday reboot.
Not sure what is actually on your OT network? Preferred Data Corporation builds the OT asset inventory a plant floor usually lacks. Call (336) 886-3282 or ask about our network and infrastructure services.
What should a North Carolina manufacturer do about these advisories?
Do not scramble to patch three specific products. Use this week as the trigger to fix the conditions that make every future advisory dangerous. None of this depends on whether you run Johnson Controls or Siemens gear, which is the point: the exposure is the conditions, not the three products.
1. Inventory what is actually on the OT network
You cannot defend equipment you have not listed. Start with a walk-down of the plant floor and the mechanical and electrical rooms: every HMI, PLC, controls PC, building-automation controller, fire and security panel, and the switches connecting them. A complete OT inventory is the exception on a plant floor, not the rule, which is exactly why an advisory like this often maps to nothing anyone can point at in Greensboro or Charlotte.
2. Segment OT from IT, and life-safety from both
The single highest-value control is a real boundary between the office network and the plant floor, and another around building and life-safety systems. A flaw that leaks a credential is far less useful when that credential cannot route anywhere. Segmentation also contains ransomware, which is the threat actually hitting manufacturers per Dragos.
3. Schedule OT patch windows instead of reacting
For the flaws you can fix, like this week's Johnson Controls and Siemens issues, get vendor or integrator sign-off and put the update into a planned maintenance window. Reactive patching during an incident, on a machine whose downtime runs into the thousands of dollars per hour, is the worst-case version of this work.
4. Lock down engineering workstations
The Siemens Simcenter Nastran flaw needs a user to open a malicious file, which puts the target on your engineers, not your servers. The box running Nastran usually gets treated like a workstation nobody has to think about, when it is really a five-figure engineering license with a direct line to your product files. It needs multi-factor authentication, attachment filtering that catches a hostile model file before someone double-clicks it, and a spot on the managed list, not the "IT never logs into that one" list.
5. Monitor the boundary you cannot patch
Where no fix exists, or where the OEM has not blessed one, monitoring is the control. Watching the traffic that crosses between your office network and your plant floor is how you close that six-week window, turning a silent foothold into an alert instead of a shutdown.
Reactive patching vs. managed OT discipline
The difference between the two approaches shows up as a budgeted line item on one side and an emergency purchase order on the other.
| Factor | Wait for the KEV list | Managed OT discipline |
|---|---|---|
| What triggers action | A headline or active exploitation | A scheduled review of every advisory |
| OT asset visibility | Partial, tribal knowledge | Complete inventory, owned |
| Network design | Flat, office and plant shared | Segmented, life-safety isolated |
| Patch timing | During an incident, at peak cost | Planned maintenance window, vendor-approved |
| Unpatchable gear | Ignored until it fails | Monitored and contained |
| First sign of trouble | A production stoppage | A boundary alert |
What Preferred Data Corporation does about OT exposure
Preferred Data Corporation has served North Carolina manufacturers from High Point since 1987. We know the plant floor because we have spent decades walking them here, and we run the IT side too, so we are not the vendor who maps your OT network and then hands you a PDF to go solve it yourself. For the gaps these advisories point at, our work includes:
- OT asset inventory and IT/OT mapping: the complete list of what is on the plant floor and how it connects, the piece most often missing before an incident
- Network segmentation: real boundaries between office, plant floor, and life-safety systems; see our network and infrastructure services
- Managed patching and vendor coordination: scheduled OT patch windows with OEM and integrator sign-off, part of our managed IT services
- Monitoring and incident response: watching the IT/OT boundary and responding when something crosses it, through our cybersecurity services
- Manufacturing-specific planning: controls, HMI, and building-system risk tied to production reality, not generic checklists; see our manufacturing solutions
Key takeaway: The three advisories from this week will be forgotten by next Monday. The flat network, the unlisted fire panel, and the unmanaged engineering workstation will still be there. Fix the conditions, not the headlines.
About Preferred Data Corporation
Preferred Data Corporation provides managed IT, cybersecurity, and network infrastructure for manufacturers and industrial firms across the Piedmont Triad, the Research Triangle, and the broader North Carolina market. Headquartered in High Point, NC since 1987, 39 years serving the region, with a 20-plus year average client retention, a BBB A+ rating, and on-site coverage within 200 miles, we are the OT and IT partner NC plant owners call when the plant floor and the office network stop being two separate things.
Get ahead of the next advisory instead of reacting to it:
- Call (336) 886-3282
- Visit preferreddata.com/contact
- Email [email protected]
- Address: 1208 Eastchester Drive, Suite 131, High Point, NC 27265
Questions NC plant managers are asking this week
Do these CISA advisories mean my plant is under attack?
No. Unlike the KEV catalog, which lists flaws with confirmed active exploitation, a standard CISA ICS advisory is a heads-up that a vulnerability exists and, usually, that a fix is available. The Johnson Controls and Siemens advisories this week were not published on the basis of in-the-wild attacks. The risk is that unpatched OT gear stays vulnerable for a long time, which is where the real exposure builds.
We are a 40-person shop. Is OT security really our problem?
Yes, more than most owners assume. Dragos found manufacturing was more than two-thirds of industrial ransomware victims in its 2026 year in review, and smaller manufacturers are targeted precisely because their plant floors are so often flat and unmonitored. Size does not exempt you; it often makes you the easier target.
Why can we not simply patch the affected systems and move on?
For some, you can and should, with vendor sign-off. But building fire-and-life-safety systems and machine-certified controls PCs often cannot be patched without OEM or integrator approval, or without voiding support. That is why the durable fixes are inventory, segmentation, and monitoring rather than a single update.
What is the fastest thing we can do this week?
Confirm whether your plant floor and building systems share a network with your office PCs. If they do, that flat design is a bigger risk than any of these three CVEs, and segmenting it is the highest-value move you can make. An OT-aware managed IT partner can map it quickly.
Does Preferred Data Corporation service equipment across North Carolina?
Yes. We are based in High Point and provide on-site OT and IT coverage within 200 miles, reaching manufacturers across Greensboro, Winston-Salem, Charlotte, Raleigh, and the wider Piedmont Triad and Research Triangle.
Related Resources
- Managed IT Services for NC Manufacturers
- Cybersecurity Services
- Network and Infrastructure Services
- Manufacturing IT Solutions
- SCADA Security for NC Manufacturers
- OT Security in the AI Age: Protecting NC Factory Networks
- Iranian APT and Rockwell PLCs: NC Manufacturer OT Defense
- IT Services in Greensboro
- IT Services in Charlotte