No authentication on industrial protocols (Modbus has no native authentication) - Default credentials on HMIs and engineering workstations - Flat networks with no segmentation between IT and OT - Legacy operating systems (Windows XP, Windows 7) without patches - Remote access without multi-factor au