Internet-Exposed Tank Gauges Reveal a Persistent Critical Infrastructure Risk


Automatic tank gauge systems may appear to be relatively simple monitoring devices. They measure the contents of storage tanks and provide operators with information needed to manage fuel, chemicals, water-treatment materials, and other liquids.

But when these systems are exposed to the public internet, protected by default credentials, or connected to broader business networks without adequate safeguards, they can become an entry point into operational environments—and a potential source of dangerously unreliable data.

Listen to this article

In June 2026, the Cybersecurity and Infrastructure Security Agency, National Security Agency, Federal Bureau of Investigation, Department of Energy, and other federal partners warned that cyber threat actors were compromising internet-exposed automatic tank gauge systems used across U.S. critical infrastructure. The agencies urged owners and operators to harden the systems and reduce unnecessary external exposure. (CISA)

The warning highlights a problem that extends well beyond tank gauges. Industrial organizations continue to connect operational technology to modern networks for legitimate business reasons, but many of the devices involved were designed for a more isolated—and less hostile—environment.

What Automatic Tank Gauge Systems Measure—and Why It Matters

An automatic tank gauge, commonly referred to as an ATG, remotely measures conditions inside a storage tank. Depending on the installation, the system may report liquid volume, level, pressure, temperature, and potential leaks.

Those readings help personnel manage inventory, schedule deliveries, detect abnormal conditions, and operate facilities safely. Federal guidance notes that ATGs are used in critical infrastructure sectors including energy, chemical, food and agriculture, and transportation. (National Security Agency)

“At a very basic level, [automatic tank gauge systems] measure the volume of something that is in a tank,” explained Damon Small of Xcape, Inc., in an interview with Brilliance Security Magazine. “More importantly, they can also measure the pressure and the temperature of those products that are in the tank.”

The device may not directly open a valve or start a pump, but the information it produces influences the people and systems responsible for those actions. Its importance therefore lies not only in what it controls, but in the operational decisions made from its data.

From Physical Isolation to IT/OT Convergence

The exposure of ATG systems reflects the broader convergence of information technology and operational technology.

Historically, many industrial systems operated on networks that were largely separated from corporate IT and the public internet. An attacker seeking access might have needed to enter the facility physically or interact directly with local equipment.

That arrangement changed as organizations recognized the value of sharing operational data with business systems. Remote telemetry can improve inventory management, maintenance, logistics, regulatory reporting, and executive decision-making. Remote access may also allow specialists to monitor distributed facilities without being present at every site.

Those benefits, however, altered the threat model.

“In the before time, go back a couple of decades, and these operational technology systems were completely segregated from the business or IT systems,” Small said. “To attack these OT networks, you would have to gain physical access to the facility.”

With IT/OT convergence, an adversary may no longer need to “jump over the fence.” An internet-facing system, remote-access service, compromised credential, or poorly controlled connection between network environments can create a route toward technology that was never designed to withstand continuous external probing.

Connectivity does not automatically make an industrial system insecure. It does, however, remove assumptions of isolation on which many older architectures and operating practices depended.

Why OT Security Priorities Are Different

One reason apparently basic security measures remain difficult to deploy is that operational technology has a different mission from conventional enterprise IT.

In many IT environments, cybersecurity professionals describe their priorities through the CIA triad: confidentiality, integrity, and availability. Sensitive information must remain private, accurate, and accessible.

Operational environments often reverse that emphasis. Availability and safe operation may come first, followed by integrity and then confidentiality.

A corporate email interruption is disruptive. An unplanned outage in a refinery, chemical facility, water-treatment plant, or manufacturing line may affect physical processes, damage equipment, create hazardous conditions, or result in substantial financial loss.

That difference matters when security teams propose new authentication systems, network controls, patches, or configuration changes. Even a well-intentioned control may face resistance if it could interrupt production or interfere with equipment that must operate continuously.

As Small emphasized, weak controls do not necessarily mean that operators are careless or indifferent to cybersecurity. Their priorities are shaped by production and safety requirements.

“Anything—any technical control that you try to implement—that has the potential to interrupt production equates to a potentially large loss in revenue,” he said. “It’s not that OT is bad for doing this. It is that their priorities are necessarily different because of the goals that they have.”

The Real Threat: Manipulated or Unavailable Telemetry

Much of the discussion surrounding cyber risk in industrial environments focuses on direct control: opening valves, stopping machinery, changing chemical processes, or disabling safety equipment.

Automatic tank gauges illustrate a more subtle risk. An attacker may not need to control the physical process directly if they can manipulate the information on which an operator relies.

A false reading could indicate that a tank has more or less product than it actually contains. Incorrect pressure or temperature data could conceal a developing hazard. Unavailable telemetry could leave remote operators unable to determine whether conditions remain within safe limits.

This distinction is important. A device can influence physical operations even when it does not issue commands to physical equipment.

“If the operator is making decisions based on bad data, then they might fail to recognize a safety situation that exists because the telemetry is bad,” Small said.

He noted that the issue is not limited to fuel storage. Similar monitoring technologies are used in municipal water and wastewater operations, where the volume of treatment chemicals may affect both process reliability and public safety.

An operator who receives no data knows there is a visibility problem. Manipulated data may be more dangerous because it can still appear normal. The operator may continue making decisions without realizing that the underlying information has been compromised.

Expert Perspective: Damon Small of Xcape

To provide additional context on the operational and safety implications of internet-exposed automatic tank gauge systems, Brilliance Security Magazine spoke with Damon Small of Xcape, Inc.

Xcape’s staff brings expertise from several areas of industrial technology, including biomedical engineering, oil and gas, and manufacturing. That diversity of experience allows the firm to examine complex life- and safety-critical systems with a practical understanding of the cyber risks that can compromise them.

In the following interview, Small explains why ATG telemetry matters, how IT/OT convergence has expanded the attack surface, and what operators should consider when system readings become unavailable or can no longer be trusted.

Beyond Fuel Systems

Automatic tank gauges are often associated with gas stations, fuel terminals, pipelines, and oil and gas facilities. The federal warning, however, points to possible exposure across several critical infrastructure sectors.

Storage tanks are used wherever organizations must monitor liquids or other materials whose volume and condition affect operations. Depending on the facility, those materials could include:

  • Fuel and petroleum products
  • Industrial chemicals
  • Water-treatment chemicals
  • Agricultural products
  • Food-processing materials
  • Manufacturing inputs
  • Wastewater and sewage-treatment substances

The underlying security problem is therefore not confined to a specific industry, manufacturer, or type of tank. It is the growing dependence on remote operational telemetry combined with systems that may retain outdated credentials, insecure services, or direct internet connectivity.

A compromise does not need to produce a dramatic physical effect to be consequential. It may delay operations, force a facility into manual procedures, disrupt deliveries, undermine confidence in reporting, or require personnel to verify conditions physically.

Planning for a “Denial of View”

Organizations often prepare for denial-of-service attacks that make a system unavailable. Operational environments must also prepare for a related condition: denial of view.

A denial-of-view incident occurs when personnel can no longer see or trust the information needed to understand the physical process. The screen may go blank, communications may fail, or the readings may continue to appear even though their integrity is uncertain.

An effective response plan should address both loss of telemetry and loss of confidence in telemetry.

That planning should begin with clear procedures for recognizing unusual behavior. Organizations need to understand the normal communication patterns, login activity, data ranges, and operational rhythms associated with their systems. As Small put it, defenders must “understand what good looks like.”

Monitoring should focus particularly on the internet-facing perimeter and on the points where information passes between IT and OT security boundaries. Those junctions act as choke points where organizations may be able to detect anomalous access or unexpected data movement.

Response plans should also define how readings will be verified independently. Depending on the facility, that could involve on-site inspection, secondary instruments, manual measurements, comparison with known inventory movement, or confirmation by local operating personnel.

At minimum, organizations should determine:

  • Who has authority to declare telemetry unreliable
  • How remote operators will contact on-site personnel
  • Which measurements can be verified manually
  • How frequently manual checks must occur
  • What operating limits apply while digital visibility is degraded
  • Which processes should be slowed or stopped if safe conditions cannot be confirmed
  • How evidence will be preserved for cybersecurity investigation

The appropriate response will vary by sector and facility. What matters is that the organization makes those decisions before an incident rather than improvising after trusted visibility has been lost.

Why Basic Security Guidance Still Matters

The principal recommendations for securing exposed ATG systems are familiar: remove unnecessary internet exposure, replace default credentials, restrict remote access, strengthen authentication, monitor network activity, and segment operational environments from business networks. Federal guidance also urges organizations to inventory affected devices and evaluate how they are connected.

The simplicity of those recommendations should not be mistaken for ease of implementation.

Some operational devices may be old, distributed across many locations, or supported by vendors with limited update mechanisms. Organizations may not have a complete inventory of every connected asset. Remote access may have been enabled years earlier for maintenance and then left in place. Credentials may be shared among technicians or embedded in legacy workflows.

Security leaders also cannot assume that controls commonly deployed in IT can be transferred to OT without testing. A patch, authentication change, or network restriction that behaves predictably in an office environment may have unexpected effects on specialized industrial equipment.

The priority should therefore be risk-informed hardening rather than indiscriminate change.

Organizations should first identify which systems are exposed, determine whether that exposure is operationally necessary, and remove it wherever possible. Remote access that must remain should be placed behind controlled gateways, protected with strong authentication, restricted to authorized users, and continuously logged.

Network segmentation should limit the ability of an intruder to move from an internet-facing or business system into the operational environment. Changes should be tested in coordination with engineers, operators, vendors, and safety personnel.

IT and OT Teams Must Support One Another

The ATG warning also demonstrates why cybersecurity cannot remain exclusively an IT responsibility.

IT security professionals understand identity, network defense, monitoring, vulnerability management, and incident investigation. OT personnel understand the physical process, safety requirements, equipment limitations, and consequences of downtime.

Neither perspective is sufficient by itself.

Applying security controls without operational context can create unacceptable risk. Maintaining operational availability without adapting to remote cyber threats can leave critical systems exposed. Protecting converged environments requires both groups to understand the constraints and priorities of the other.

Small described that process as a learning exercise for professionals from both disciplines.

“I came from the IT world and had to learn the OT world, and OT folks are doing the same thing,” he said. “The challenges we face in each of our worlds are very much related, but it is also very important to support one another.”

A Warning Larger Than the Device

Automatic tank gauges are not necessarily the most complex components in critical infrastructure. That is precisely why the federal warning deserves attention.

The risk arises from ordinary technology performing an essential function, connected in ways its original designers may not have anticipated. The same pattern can be found across industrial environments: a monitoring device, remote maintenance interface, legacy controller, or field system becomes reachable from networks where adversaries can discover and target it.

Securing those systems begins with reducing unnecessary exposure and improving access control. But it also requires a more mature understanding of operational consequence.

Organizations must prepare not only for the possibility that an attacker could take control of equipment. They must also prepare for something less visible but equally disruptive: the moment operators can no longer rely on what their systems are telling them.


Steven Bowcut is the Editor-in-Chief of Brilliance Security Magazine and host of the BSM Podcast. He has spent years covering cybersecurity and physical security, focusing on the technologies, strategies, and leadership insights that matter most to security practitioners and decision-makers. Through the magazine and podcast, Steven brings readers and listeners practical content with industry leaders, innovators, and experts shaping the future of security. Follow and connect with Steve on Instagram and LinkedIn.

Additional Resources

Video Overview

Infographic