Skip to Main Content Subscribe

Cyberattacks on Water Sector Expose Persistent OT Security Gaps

Share

Cyberattacks targeting water systems highlight longstanding security gaps in internet-facing operational technology.

4m read
Aerial view of wastewater treatment plant.
Aerial view of wastewater treatment plant. Photo Credit: Shutterstock/Martin Mecnarowski

Federal cybersecurity officials’ warnings to water utilities show how critical infrastructure operators are still fighting the same operational technology security problem that government has been warning about for years.

The latest directive from the Cybersecurity and Infrastructure Security Agency (CISA) advised water utility providers to remove internet-facing programmable logic controllers after a series of cyberattacks against water utility companies in at least seven states since the end of July.

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” CISA Acting Director Nick Andersen said in a statement to GovCIO Media & Research.  

PLCs are industrial computers that monitor and automate equipment and processes at many facilities — whether they are water treatment plants, energy substations, traffic control centers, public transit hubs and more.

Critical Infrastructure Operator Challenges

The PLC components have been targets for various hacks to critical infrastructure over the years, such as a 2023 incident also targeting water systems and a March 2026 incident targeting multiple sectors, including water, energy and government facilities.

Michael Garcia, former associate chief of policy at CISA and currently policy director at the Operational Technology Cybersecurity Coalition, called internet-exposed PLCs in the July attacks “low-hanging fruit for these bad actors.”

“They identified PLCs that are connected to the internet, which they’re not supposed to be,” he told GovCIO Media & Research in an interview. OT systems never connect to the internet to ensure mediated, monitored and controlled access by system owners. The FBI, EPA and CISA said that the targeted PLCs were likely a result of third-party installation. 

James Turgal, former assistant director of the FBI IT Branch, said that the targeted PLCs were also likely installed years ago, limiting the amount of visibility systems owners may have over devices. He added that other internet-facing or exposed devices often use the factory-default password — or no password at all — which increases their vulnerability. 

“A lot of these systems, especially in the smaller municipalities and rural areas, it’s literally an indication of age,” said Turgal. “It’s not even like the threat actors need a zero-day vulnerability or code gap to get in. It’s just wide open.”

Garcia said it’s typical for publicly owned systems to lack resources and funding to modernize their IT and OT environments, or even know what to prioritize.

“I think we have to remind ourselves that a majority of these systems are publicly owned with pretty minimal resources,” he said.

The Path Forward

Congress is working on new policy to protect water systems after the recent attacks. Sens. Adam Schiff and Amy Klobuchar’s Water Cyber Shield Act introduced Monday would provide more funding for cybersecurity improvements and give the EPA more authority over corrective actions in cybersecurity assessments of water infrastructure.

As the national coordinator for critical infrastructure security, CISA provides guidance for critical infrastructure organizations to mitigate risks. The agency also has been advising software manufacturers to make product lines secure by design for their customers.

However, it’s ultimately the responsibility of the operators and manufacturers to ensure their environments are modernized.

“If you’re talking about a super small water utility company that may not have cybersecurity experts, they may not be aware of what they need to invest in [to prevent these attacks],” Garcia said. “That’s why we need a separate cybersecurity grant program so governments can invest in firewalls or other strong cybersecurity measures and try to quantify those results.”

One cybersecurity grant program from the EPA helps mid-size to large water utilities proactively mitigate cyberattacks. But Garcia said a more localized approach would help smaller localities dedicate adequate cybersecurity resources. 

He added that the State and Local Cybersecurity Grant Program, which is set to expire in September, helps owners and operators at smaller systems specifically budget for cyber resiliency and security responses. Garcia said that system owners may apply for other grants to help boost resiliency, but they may need that funding to strengthen other parts of the water system like preparing for natural disasters.

“You end up slicing and dicing an already small grant for the water sector to also include this very important provision of cybersecurity,” said Garcia. “We need a separate cybersecurity grant program because it’s not going to take away from other important grants, but it can lead to ensuring that smaller systems can invest in firewalls or other strong cybersecurity measures.

Garcia said everyone in an organization must learn cybersecurity education and best practices to prevent attacks and mitigate them. 

“The ability to continually inform and educate folks as to the importance of cybersecurity, that knowing an ounce of prevention is worth a pound of cure, goes a long way,” said Garcia.

Related Content