Alienum phaedrum torquatos nec eu, vis detraxit periculis ex, nihil expetendis in mei. Mei an pericula euripidis, hinc partem.

Call Us (321) 972-1375

 

 

Blog

RB Advisory LLC / Cyber Security  / Recent Water-Sector Cyber Incidents Show Why OT Cybersecurity Cannot Wait

Recent Water-Sector Cyber Incidents Show Why OT Cybersecurity Cannot Wait

Recent cyber incidents affecting community water systems have delivered another urgent warning for critical infrastructure operators: operational technology connected to the public internet can create a direct path from a cyber intrusion to a physical disruption.

Reports indicated that multiple utilities experienced disruptions involving internet-connected operational technology. Some operators shifted equipment to manual control while affected systems were investigated. Officials reported no evidence that drinking water quality was compromised.

In response, the Cybersecurity and Infrastructure Security Agency urged utilities nationwide to remove exposed industrial-control equipment from the internet. CISA also recommended replacing default passwords and limiting remote access to trusted devices.

Investigations into cyber incidents often remain ongoing, and early speculation about responsible actors can outpace verified information. For critical infrastructure organizations, the immediate priority is not assigning blame; it is identifying exposure, containing risk, and strengthening resilience.

Cybersecurity Becomes a Public-Safety Issue

Water and wastewater systems are part of the nation’s critical infrastructure. Their operational environments control pumps, valves, treatment processes, storage systems, and other equipment that communities depend on every day.

When those environments are disrupted, the consequences can extend well beyond lost data or unavailable email. Operators may lose visibility into essential processes, facilities may need to shift to manual operations, and communities may experience service interruptions or public-health precautions.

For Regine Bonneau, founder and chief executive officer of RB Advisory LLC and professionally known as The Cyber Queen™, incidents affecting operational environments demonstrate why operational technology cybersecurity must be treated as an enterprise risk and public-safety priority.

“When a cyberattack can interrupt pumps, valves, and treatment operations, cybersecurity is no longer simply an IT issue, it is an operational resilience and public-safety issue,” says Bonneau. “Organizations must know which assets are connected, remove unnecessary internet exposure, secure every form of remote access, and prepare their teams to continue operating safely when technology is disrupted.”

Internet Exposure Creates Avoidable Risk

Programmable logic controllers and other industrial-control devices were designed to manage physical processes reliably. Many were not designed for direct exposure to today’s internet-based threats.

CISA and other federal partners have repeatedly warned that internet-accessible programmable logic controllers can be targeted by threat actors seeking to disrupt water systems and other critical infrastructure organizations. Recommended actions include addressing insecurely connected operational technology, implementing multifactor authentication, using strong and unique passwords, and checking devices for default or missing passwords.

These are foundational controls, but they remain essential:

  • Remove operational technology from the public internet unless connectivity is operationally necessary.
  • Eliminate default and shared credentials.
  • Require multifactor authentication for remote access.
  • Restrict access to approved users and trusted devices.
  • Segment operational technology from business and public-facing networks.
  • Maintain an accurate inventory of connected assets.
  • Monitor for unauthorized configuration and access changes.
  • Test incident-response and manual operating procedures.

Aging Systems Require Lifecycle Security

Water utilities often operate a complex mix of legacy equipment, modern technology, vendor-supported systems, and components installed over many years. That complexity makes visibility, ownership, patching, and secure modernization more difficult.

It also means cybersecurity cannot be treated as a one-time technology purchase. Security requirements must be integrated throughout the asset lifecycle, from planning and design through deployment, operations, maintenance, modernization, and eventual replacement. 

Organizations should also review every third party with access to their operational environment. Vendors, integrators, contractors, and remote maintenance providers may each introduce credentials, connections, software, or devices that must be governed and monitored.

Resilience Requires Preparation Before an Attack

Preventing an intrusion is important, but no organization can assume every attack will be stopped.

Resilient utilities prepare to detect suspicious activity quickly, isolate affected systems, maintain essential operations, communicate with government partners, and recover safely. Recurring cybersecurity assessments reinforce the importance of continuous evaluation rather than one-time compliance.

“Cyber resilience is not measured only by whether an attacker gets in,” Bonneau adds. “It is measured by how quickly the organization recognizes the threat, contains the impact, protects the public, and restores operations with confidence.”

These incidents should prompt every critical infrastructure organization, not only water utilities, to ask a direct question:

Which operational assets are exposed today, and what would happen if access to them were lost tomorrow?

The time to answer that question is before an attacker does.

_____

RB Advisory offers executive OT cybersecurity briefings that help leadership teams identify critical operational risks, reduce exposure, and strengthen incident response and resilience. Schedule an Executive OT Cyber Risk Briefing today at (321) 972-1375.