Persistent OT Vulnerabilities Revealed by Cyberattacks on Water Infrastructure

0
2

Key Takeaways

  • A wave of cyberattacks since late July has targeted internet‑facing programmable logic controllers (PLCs) at water utilities in at least seven states.
  • CISA has urged owners to remove publicly exposed PLCs and other operational technology (OT) from the internet immediately.
  • Many compromised devices were installed years ago, use factory‑default or no passwords, and lack basic network segmentation.
  • Smaller, publicly owned water systems often lack the funding, staff, and expertise to modernize OT environments.
  • Legislative proposals such as the Water Cyber Shield Act aim to boost funding and EPA authority, while existing grant programs help but are stretched thin across multiple priorities.
  • Continuous cybersecurity education and adoption of secure‑by‑design practices are essential for long‑term resilience.

Overview of Recent Attacks
Since the end of July, cybercriminals have launched a series of intrusions against water utility companies in at least seven states, focusing on devices that should never be reachable from the public internet. The attackers gained entry through programmable logic controllers (PLCs) that monitor and automate treatment processes, pumping stations, and other critical functions. Although the incidents did not cause widespread service disruption, they exposed a persistent weakness in how many water systems manage their operational technology. Federal agencies, including CISA, the FBI, and the EPA, have issued joint warnings urging immediate remedial action. The pattern mirrors earlier OT‑focused campaigns, indicating that threat actors continue to exploit low‑hanging fruit rather than relying on sophisticated zero‑day exploits.

CISA Advisory and Recommendations
CISA Acting Director Nick Andersen publicly urged critical infrastructure owners to “remove publicly exposed PLCs and other operational technology from the internet as soon as possible.” The agency’s directive emphasizes that PLCs are industrial computers designed for isolated, tightly controlled environments; exposing them to the internet defeats fundamental security principles. CISA recommends conducting asset inventories to identify any internet‑facing OT, disabling unnecessary remote access, enforcing strong authentication, and segmenting OT networks from corporate IT and the public internet. The advisory also stresses the importance of applying vendor patches, changing default credentials, and monitoring for anomalous traffic that could signal compromise.

Nature of PLCs and Exposure
PLCs are the workhorses of modern water treatment, regulating chemical dosing, flow rates, and equipment cycles. Because they are often legacy devices, many were installed with minimal security considerations and later connected to corporate networks for convenience or remote maintenance. In the July attacks, the FBI and EPA noted that the targeted PLCs were likely the result of third‑party installations that never underwent proper network hardening. These devices frequently retain factory‑default usernames and passwords—or no authentication at all—making them trivial targets for automated scanners. Once inside, attackers can manipulate process variables, potentially contaminating water supplies or causing equipment damage.

Historical Context of OT Attacks
The recent water‑sector intrusions echo earlier OT campaigns, such as a 2023 incident that also hit water systems and a March 2026 breach that hit water, energy, and government facilities simultaneously. Michael Garcia, former associate chief of policy at CISA and now policy director at the Operational Technology Cybersecurity Coalition, described the exposed PLCs as “low‑hanging fruit for these bad actors.” He noted that the attackers did not need advanced exploits; they simply scanned for devices openly reachable on the internet and logged in with default credentials. This recurrence underscores a chronic gap between OT security best practices and real‑world implementation, especially in utilities that lack dedicated cybersecurity staff.

Expert Insights on Vulnerabilities
James Turgal, former assistant director of the FBI IT Branch, highlighted that many of the compromised PLCs were installed years ago, leaving current owners with limited visibility into their configurations and patch levels. He observed that age, rather than sophistication, often drives vulnerability in smaller municipalities and rural districts. “It’s not even like the threat actors need a zero‑day vulnerability or code gap to get in,” Turgal said. “It’s just wide open.” Both Garcia and Turgal stressed that the root cause is frequently a lack of resources: publicly owned utilities operate on tight budgets, making it difficult to fund OT upgrades, hire specialized personnel, or conduct regular security assessments.

Resource Constraints in Smaller Utilities
Garcia pointed out that a majority of water systems are publicly owned with “pretty minimal resources,” which hampers their ability to prioritize cybersecurity amid competing demands like infrastructure maintenance and regulatory compliance. Smaller utilities may not employ dedicated OT security engineers, leaving network hygiene to general IT staff who lack OT‑specific training. Consequently, critical security steps—such as changing default passwords, disabling unnecessary services, or implementing network segmentation—are often overlooked. The financial barrier extends to purchasing modern firewalls, intrusion detection systems, or securing remote‑access solutions that meet OT safety requirements.

Legislative Response: Water Cyber Shield Act
In response to the rising threat, Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, which would allocate additional funding for cybersecurity improvements in water infrastructure and expand the EPA’s authority to enforce corrective actions during cybersecurity assessments. The bill seeks to create a dedicated grant stream that utilities can use to modernize OT environments, purchase security tools, and hire qualified personnel. By elevating the EPA’s role, the legislation aims to ensure that cybersecurity considerations are integrated into routine water‑system inspections, similar to how safety and environmental standards are currently enforced.

CISA’s Role and Industry Responsibility
As the national coordinator for critical infrastructure security, CISA continues to issue guidance, conduct outreach, and encourage manufacturers to adopt secure‑by‑design principles. The agency advises software and hardware vendors to build products that minimize exposure, support strong authentication, and provide timely patches. However, CISA acknowledges that ultimate responsibility lies with the operators and vendors who deploy and maintain the systems. Garcia emphasized that even a modest investment in firewalls, network monitoring, and staff training can dramatically reduce risk, but only if utility leaders recognize cybersecurity as a core component of operational reliability rather than an optional add‑on.

Grant Programs and Funding Challenges
Existing federal grant mechanisms, such as the EPA’s cybersecurity grant for mid‑size to large utilities and the State and Local Cybersecurity Grant Program (set to expire in September), help owners budget for cyber resiliency. Garcia warned, however, that spreading limited funds across multiple priorities—forces utilities to “slice and dice an already small grant” to cover both cybersecurity and other needs like disaster preparedness. He advocated for a separate, dedicated cybersecurity grant program that would not siphon money from essential water‑infrastructure projects but would enable smaller systems to acquire baseline protections such as firewalls, multi‑factor authentication, and regular penetration testing.

Education and Best Practices as Mitigation
Beyond technology and funding, Garcia stressed the importance of continuous cybersecurity education for all personnel, from executives to front‑line operators. He framed security as a preventive mindset: “knowing an ounce of prevention is worth a pound of cure.” Regular tabletop exercises, awareness phishing simulations, and clear incident‑response plans can help staff recognize and react to threats before they cause harm. Encouraging a culture where security concerns are reported without fear of reprisal, combined with technical controls, creates a layered defense that is far more resilient than reliance on any single solution.

By combining immediate remediation of exposed PLCs, sustained investment in modern OT security, targeted legislative support, and ongoing workforce education, water utilities can close the longstanding security gaps that have left them vulnerable to cyberattacks for years.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here