Key Takeaways
- Cyberattacks on water and wastewater systems are increasing, with a July 22 federal advisory highlighting Iranian‑affiliated actors targeting internet‑connected PLCs.
- PLCs (programmable logic controllers) and SCADA systems control pumps, valves, and chemical feeds; exploiting them can disrupt pressure and risk contamination.
- Riverhead Water District uses Allen‑Bradley PLCs and Rockwell’s FactoryTalk software, the same models named in the advisory.
- Over the past two years the district has upgraded firewalls, instituted coordinated patching, added control‑system redundancy, and maintained 24‑hour staffing in its control room.
- Operators can detect abnormal pump or tank behavior and switch to manual hand‑control operation if needed.
- Seasonal summer demand (up to ~20 million gallons per day) shortens the time before pressure drops to unsafe levels, heightening the impact of a potential attack.
- The district emphasizes coordination among water‑operations staff, town IT, and outside controls contractor Lexington Controls, supplemented by regular phishing‑test training for employees.
- New York State has introduced mandatory cybersecurity requirements, grant funding, and reporting rules for water utilities, and Riverhead recently secured $278,285 in state grants for IT improvements.
- While defenses have markedly improved, officials warn that threats are evolving and continuous vigilance is essential.
Rising Cyber‑Threat Landscape for Water Utilities
Recent reports of cyber intrusions on water and wastewater systems in Minnesota and other states have prompted federal agencies to issue a July 22 advisory warning that Iranian‑affiliated threat actors are actively probing internet‑connected operational technology devices. The advisory, co‑signed by the FBI, CISA, NSA, EPA, Department of Energy, U.S. Cyber Command, and the Treasury Department, stresses that attackers are not exploiting a novel software flaw but rather leveraging common weaknesses such as exposed PLCs, default credentials, and insufficient network segmentation.
Understanding the Target: PLCs and SCADA
The advisory identifies programmable logic controllers (PLCs) as the primary objective. PLCs are industrial computers that regulate equipment like pumps, valves, and chemical feed mechanisms, and they are typically overseen through supervisory control and data acquisition (SCADA) systems that provide real‑time visibility and control. Attackers can use legitimate programming software to access misconfigured PLCs, download or alter project files, manipulate SCADA displays, and even disable alarm or shutdown logic, thereby threatening the physical operation of water facilities.
Riverhead’s Specific Infrastructure and Vendor Partnership
Riverhead Water District Superintendent Frank Mancini confirmed that the town’s water system employs Allen‑Bradley PLCs and Rockwell’s FactoryTalk software—both models explicitly cited in the federal warning. The district works closely with Lexington Controls, its external controls contractor, and the town’s IT department to maintain, patch, and monitor the system. This partnership is essential because any update to firewalls or PLC firmware must be coordinated to avoid unintended interference with industrial control processes.
Hardening Defenses: Firewalls, Patching, and Redundancy
Over the last two years, Mancini said the district has installed new firewalls, established a disciplined schedule for updating firewall software and PLC‑related patches, and introduced redundancy into its control‑system architecture. Updates are carefully timed—never performed indiscriminately on a Sunday night—because an uncoordinated patch could disable a well pump or cause erratic behavior during peak summer demand. This methodical approach seeks to balance cybersecurity resilience with uninterrupted water delivery.
Operational Vigilance: 24‑Hour Monitoring and Manual Override
The water district staffs its control room around the clock, enabling operators to watch tank levels, pump activity, and other critical parameters in real time. If a pump unexpectedly stops or a tank level deviates from the norm, staff can notice immediately. Mancini emphasized that the most immediate danger from a cyberattack is not water poisoning but loss of system pressure; should pressure fall below 20 PSI, a boil‑water advisory becomes mandatory. In the event of a compromised automated system, the district can switch to manual hand‑control operation at the flip of a switch, allowing operators to run pumps and valves locally from each station.
Seasonal Demand Amplifies Risk
Riverhead’s water usage varies dramatically between seasons. Winter consumption averages 2–3 million gallons per day, providing a larger buffer before tanks reach critical lows. In summer, demand spikes to 17–18 million gallons daily, with occasional days approaching 20 million gallons. Mancini warned that if pumps were shut down under such high demand, tanks would empty rapidly, accelerating pressure loss and increasing the likelihood of contamination. Consequently, the summer period heightens the stakes for any disruption to the control system.
Progress Through Coordination and Training
Mancini noted that the district’s current security posture is far stronger than it was five years ago, when the SCADA system was more limited and cybersecurity measures were rudimentary. Improvements stem from tight collaboration among water‑operations staff, the town’s IT deputy director John West, and Lexington Controls. West has been instrumental in configuring defenses, identifying weaknesses, and ensuring cybersecurity is not siloed within the water department. Additionally, the town conducts regular phishing‑tests; although recent tests showed only a few employees clicking malicious links, the exercise underscores the persistent need for user‑awareness training.
State‑Level Initiatives and Grant Support
New York State has moved to bolster water‑sector cybersecurity. In March, Governor Kathy Hochul announced mandatory training for certified operators, incident‑reporting requirements, risk‑based standards, and designated cybersecurity leads for larger drinking‑water systems. The state also launched grant funding to help utilities evaluate and improve their defenses. Riverhead recently secured two grants totaling $278,285 through the New York State Environmental Facilities Corporation’s SECURE Cybersecurity Grant Program for IT infrastructure upgrades in the Riverhead Sewer District—separate from the water‑district measures but indicative of the growing emphasis on cyber resilience across water‑related infrastructure.
Conclusion: Preparedness Amid an Evolving Threat
While Mancini expressed confidence that Riverhead is “as prepared as we could be,” he cautioned against overstating security or assuming any system is immune. He anticipates that threat actors will become more knowledgeable about water‑system operations, potentially increasing their capacity to cause serious disruption. For now, the district’s layered defenses—technical upgrades, vigilant monitoring, manual fallback options, inter‑agency coordination, and ongoing staff training—provide a robust foundation, but continuous adaptation remains essential as the cyber threat landscape evolves.

