Yes, but plants and sub-stations don't need to shop on e-Bay or check their Facebook status now do they?
If they need to be connected to a network, make it a private network and most of these issues go away.
There is no sane reason that these networks and these facilities should not be air-gapped from the internet at large. There are ways around the air-gap (stuxnet), but even these are trivial to prevent by not allowing random USB keys from outside by gluing the port closed and/or securing the hardware properly, and/or beating anyone stupid enough to do this with a stick.
It's not nuclear science or anything, it's just common sense.