Cyberattacks on Water Sector Expose Persistent OT Security Gaps
Cyberattacks targeting water systems highlight longstanding security gaps in internet-facing operational technology.
Federal cybersecurity officials’ warnings to water utilities show how critical infrastructure operators are still fighting the same operational technology security problem that government has been warning about for years.
The latest directive from the Cybersecurity and Infrastructure Security Agency (CISA) advised water utility providers to remove internet-facing programmable logic controllers after a series of cyberattacks against water utility companies in at least seven states since the end of July.
“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” CISA Acting Director Nick Andersen said in a statement to GovCIO Media & Research.
PLCs are industrial computers that monitor and automate equipment and processes at many facilities — whether they are water treatment plants, energy substations, traffic control centers, public transit hubs and more.
Critical Infrastructure Operator Challenges
The PLC components have been targets for various hacks to critical infrastructure over the years, such as a 2023 incident also targeting water systems and a March 2026 incident targeting multiple sectors, including water, energy and government facilities.
Michael Garcia, former associate chief of policy at CISA and currently policy director at the Operational Technology Cybersecurity Coalition, called internet-exposed PLCs in the July attacks “low-hanging fruit for these bad actors.”
“They identified PLCs that are connected to the internet, which they’re not supposed to be,” he told GovCIO Media & Research in an interview. OT systems never connect to the internet to ensure mediated, monitored and controlled access by system owners. The FBI, EPA and CISA said that the targeted PLCs were likely a result of third-party installation.
James Turgal, former assistant director of the FBI IT Branch, said that the targeted PLCs were also likely installed years ago, limiting the amount of visibility systems owners may have over devices. He added that other internet-facing or exposed devices often use the factory-default password — or no password at all — which increases their vulnerability.
“A lot of these systems, especially in the smaller municipalities and rural areas, it’s literally an indication of age,” said Turgal. “It’s not even like the threat actors need a zero-day vulnerability or code gap to get in. It’s just wide open.”
Garcia said it’s typical for publicly owned systems to lack resources and funding to modernize their IT and OT environments, or even know what to prioritize.
“I think we have to remind ourselves that a majority of these systems are publicly owned with pretty minimal resources,” he said.
The Path Forward
Congress is working on new policy to protect water systems after the recent attacks. Sens. Adam Schiff and Amy Klobuchar’s Water Cyber Shield Act introduced Monday would provide more funding for cybersecurity improvements and give the EPA more authority over corrective actions in cybersecurity assessments of water infrastructure.
As the national coordinator for critical infrastructure security, CISA provides guidance for critical infrastructure organizations to mitigate risks. The agency also has been advising software manufacturers to make product lines secure by design for their customers.
However, it’s ultimately the responsibility of the operators and manufacturers to ensure their environments are modernized.
“If you’re talking about a super small water utility company that may not have cybersecurity experts, they may not be aware of what they need to invest in [to prevent these attacks],” Garcia said. “That’s why we need a separate cybersecurity grant program so governments can invest in firewalls or other strong cybersecurity measures and try to quantify those results.”
One cybersecurity grant program from the EPA helps mid-size to large water utilities proactively mitigate cyberattacks. But Garcia said a more localized approach would help smaller localities dedicate adequate cybersecurity resources.
He added that the State and Local Cybersecurity Grant Program, which is set to expire in September, helps owners and operators at smaller systems specifically budget for cyber resiliency and security responses. Garcia said that system owners may apply for other grants to help boost resiliency, but they may need that funding to strengthen other parts of the water system like preparing for natural disasters.
“You end up slicing and dicing an already small grant for the water sector to also include this very important provision of cybersecurity,” said Garcia. “We need a separate cybersecurity grant program because it’s not going to take away from other important grants, but it can lead to ensuring that smaller systems can invest in firewalls or other strong cybersecurity measures.
Garcia said everyone in an organization must learn cybersecurity education and best practices to prevent attacks and mitigate them.
“The ability to continually inform and educate folks as to the importance of cybersecurity, that knowing an ounce of prevention is worth a pound of cure, goes a long way,” said Garcia.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Public-Private Threat Sharing Could Give Defenders an Edge
Industry and government professionals say they will ultimately have the tactical advantage around threats as long as they work together.
4m read -
Streamlining the ATO Process Makes Software Deployments More Efficient, Secure
NIST’s Victoria Yan Pillitteri discusses common ATO stumbling blocks and how agencies can streamline authorization for secure software deployment.
7m watch -
ASPR Signals New Quantum Guidance Amid Health Cyber Threats
The health agency is the latest to provide guidance on post-quantum cryptography amid a government-wide focus to get ahead of quantum threats.
3m read -
NIST Explores AI’s Role in DevSecOps
Michael Ogata discusses NIST’s latest DevSecOps research, the growing role of AI agents and the need for new approaches to identity and authorization.
4m watch