Help Net Security reported on August 7, 2026 that U.S. internet exposure for automatic tank gauges fell by more than half over three months, based on Bitsight research. That sounds like a win, and it probably is. The catch is that automatic tank gauges are not just obscure fuel-station hardware. They monitor fuel level, temperature, moisture, and leaks, and similar equipment can sit behind backup generators at hospitals, data centers, manufacturing sites, schools, municipal facilities, and other businesses.
Bitsight's August 6 research found that the largest drop happened on port 10001, a common default exposure path for older tank gauge setups. The company also warned that other exposure remained, that some web-facing gauges were still confirmed vulnerable, and that moving a device behind a firewall does not automatically fix the device itself.
The Business Risk Is Inventory, Not Just Exposure
For many owners, the practical issue is not whether they operate a fuel business. It is whether anyone can answer a simple question: what operational technology is connected to the company network, who manages it, and how is remote access controlled?
Automatic tank gauges are a useful example because they often live between facilities, vendors, compliance, and IT. A service company may install the equipment. A facilities manager may depend on it. An IT provider may never have been asked to include it in the asset list. That handoff gap is where small business risk can hide in plain sight.
CISA and several federal partners warned in June that cyber actors had compromised internet-exposed ATG systems and modified them through command execution. The agencies recommended removing direct internet exposure, strengthening credentials, and limiting access. Those are not exotic controls. They are basic network ownership controls, applied to equipment that often gets left outside the normal IT review.
What Owners Should Ask
If your business uses generator fuel monitoring, environmental sensors, building controls, industrial equipment, or vendor-managed facility systems, ask your IT provider or internal team to verify a few things:
- Which operational devices are connected to the network, including fuel, generator, HVAC, building, production, or monitoring systems?
- Are any of those devices reachable from the public internet on any port or protocol?
- Who owns password changes, firmware updates, vendor access, and emergency support for each device?
- Is remote access protected by a VPN, firewall rules, strong unique credentials, and logging?
- Can the business prove segmentation between office systems and operational equipment?
- Are vendor support accounts reviewed after installation, staff changes, and contract renewals?
A Better Next Step Than Panic
The lesson is not to treat every fuel gauge like a crisis. The lesson is to stop treating facilities technology as invisible. Owners should ask for a short operational technology inventory and exposure review, especially if the business has backup generators, fuel storage, environmental compliance equipment, warehouse systems, or vendor-managed devices.
A good review should produce evidence, not just reassurance: device names, locations, responsible vendors, access paths, firewall rules, credential status, and a plan for anything that should not be internet-facing. If a vendor says remote access is needed, the next question is how that access is limited, monitored, and removed when it is no longer required.
The public exposure numbers appear to be moving in the right direction. For a business owner, the useful move is to make sure the same kind of cleanup has happened inside your own network. The gauge may read safer now, but someone still has to check the tank.
Sources and further reading