Water and wastewater systems are among the most essential components of modern society. They support public health, manufacturing, agriculture, healthcare, businesses, and communities every day.
But many of these systems also depend on operational technology, industrial control systems, programmable logic controllers, remote access solutions, and connected monitoring platforms.
Recent warnings from the Cybersecurity and Infrastructure Security Agency highlight how attractive these environments have become to threat actors.
Reports indicate that more than 100 internet-exposed water systems were targeted during July cyberattacks. The activity has raised concerns about the security of operational technology used to control critical water infrastructure.
The broader campaign follows attacks against water utilities in multiple US states, including incidents where automated control functions were disrupted. CISA subsequently urged water and wastewater operators to remove publicly exposed PLCs and other operational technology from direct internet exposure.
Why Water Infrastructure Is Becoming a Cybersecurity Priority
Unlike traditional IT systems, operational technology directly interacts with physical processes.
A compromised system can potentially affect:
• Water pumping
• Treatment processes
• Pressure management
• Chemical dosing
• Wastewater operations
• Remote monitoring
• Industrial control systems
• Facility automation
This means a cybersecurity incident can potentially move beyond data theft and affect physical operations.
For critical infrastructure organizations, cybersecurity must therefore address both digital assets and the physical processes those assets control.
Internet Exposure Creates an Unnecessary Attack Surface
One of the most important lessons from the recent incidents is the danger of exposing industrial control equipment directly to the public internet.
Internet accessible PLCs, HMIs, remote management interfaces, cellular-connected equipment, and other OT components can provide attackers with an entry point into environments that were historically protected by physical isolation.
CISA has specifically encouraged water and wastewater operators to remove publicly exposed PLCs and OT systems from the internet. Where remote access is necessary, organizations should use secure access mechanisms such as VPNs or controlled gateway systems rather than exposing controllers directly.
This is a fundamental security principle:
Critical operational systems should not be unnecessarily reachable from the public internet.
Default Credentials Remain a Serious Risk
Another important concern for OT environments is weak authentication.
Legacy industrial systems may continue operating for years with default passwords, shared credentials, outdated accounts, or insufficient access controls.
Attackers can take advantage of these weaknesses to gain unauthorized access and potentially change system configurations.
Organizations operating industrial environments should:
• Change default passwords immediately
• Use strong and unique credentials
• Implement privileged access management
• Disable unnecessary accounts
• Enforce multi-factor authentication where technically feasible
• Review vendor and third-party access
• Monitor privileged activity
• Regularly audit remote access
Security controls must account for the operational requirements of industrial environments while still preventing unauthorized access.
OT Security Requires a Different Approach
Traditional IT security tools are important, but they cannot provide complete protection for operational technology.
OT environments have unique characteristics.
Systems may:
• Operate continuously
• Depend on legacy technology
• Have limited patching windows
• Require specialized protocols
• Control physical processes
• Depend on vendor-specific equipment
• Have strict availability requirements
A security control that works well for a corporate workstation may not be appropriate for a PLC controlling a critical industrial process.
This is why OT security programs need specialized assessments that understand both cybersecurity and industrial operations.
Remote Access Is a Critical Security Concern
Remote connectivity has become increasingly important for utilities and industrial organizations.
Vendors, system integrators, engineers, maintenance teams, and operators may need remote access to critical systems.
However, every remote connection creates potential security exposure.
Organizations should maintain a complete inventory of:
• VPN connections
• Remote desktop services
• Cellular modems
• Vendor connections
• Engineering workstations
• Cloud-connected OT platforms
• Remote monitoring systems
• Internet-facing HMIs
• External management interfaces
Undocumented remote access can become an invisible pathway into critical infrastructure.
CISA has also highlighted the importance of identifying connections that may not be captured during routine attack surface assessments.
The Importance of Network Segmentation
Critical infrastructure should not operate as a flat network.
Strong segmentation can help prevent an attacker who compromises one system from easily reaching more sensitive operational assets.
A well-designed architecture can separate:
• Corporate IT networks
• OT networks
• Engineering workstations
• Control systems
• Safety systems
• Vendor access
• Internet-facing services
• Monitoring infrastructure
Additional controls such as firewalls, access control lists, jump servers, secure gateways, and network monitoring can further reduce lateral movement opportunities.
Backup and Recovery Are Essential
Cybersecurity is not only about preventing an attack.
Organizations must also be prepared to recover if an attacker compromises a controller or disrupts an operational system.
For critical OT environments, organizations should maintain:
• Known-clean system backups
• PLC configuration backups
• Tested recovery procedures
• Offline copies of critical configurations
• Incident response plans
• Manual operating procedures
• Emergency communication procedures
• Regular recovery exercises
CISA has emphasized the importance of maintaining known-clean PLC backups when responding to incidents involving compromised controllers.
Recovery planning can be particularly important for smaller utilities that may have limited cybersecurity personnel and resources.
Cybersecurity Is Also a Public Safety Issue
A cyberattack against a water utility is fundamentally different from a conventional data breach.
A stolen database is serious.
But an attack against systems responsible for physical processes can potentially affect service availability, operational continuity, and public confidence.
This makes water infrastructure cybersecurity a public safety and resilience issue, not simply an IT security problem.
The recent incidents demonstrate why cybersecurity teams, plant operators, engineering teams, management, government agencies, and third-party technology providers need to work together.
Compliance and Critical Infrastructure Security
Cybersecurity requirements for critical infrastructure are becoming increasingly important.
Organizations need to demonstrate that they have appropriate controls for:
• Risk management
• Access control
• Vulnerability management
• Incident response
• Network security
• Data protection
• Security monitoring
• Business continuity
• Third-party risk
• Disaster recovery
Compliance should not be treated as the final objective.
The objective should be to build security controls that actually reduce operational risk while also helping organizations meet applicable regulatory and contractual requirements.
What Water and Critical Infrastructure Operators Should Do
Organizations responsible for water, wastewater, and other critical infrastructure should consider the following actions:
• Identify every internet-facing OT asset
• Remove unnecessary direct internet exposure
• Replace default credentials
• Restrict remote access
• Use secure VPN or gateway architectures
• Implement network segmentation
• Monitor OT network traffic
• Maintain current asset inventories
• Review vendor access
• Conduct OT vulnerability assessments
• Perform penetration testing where appropriate
• Maintain known-clean backups
• Test incident response procedures
• Establish manual operating procedures
• Train operational and cybersecurity personnel
• Continuously review external exposure
Security assessments should also include third-party connections and legacy systems because these can create significant blind spots.
The Risk Extends Beyond Water Utilities
The same cybersecurity lessons apply to other critical infrastructure sectors.
Electric utilities, manufacturing facilities, transportation networks, oil and gas operations, telecommunications providers, healthcare facilities, and government infrastructure increasingly depend on connected operational systems.
Attackers do not necessarily need a sophisticated zero-day vulnerability when an exposed controller, weak credential, outdated system, or poorly secured remote connection provides an easier path.
The fundamental security principle is simple:
If a critical system does not need to be exposed, it should not be exposed.
Conclusion
The targeting of more than 100 internet-exposed water systems is another reminder that critical infrastructure has become an increasingly important cybersecurity target.
The greatest risk is not always a highly sophisticated attack. In many cases, unnecessary internet exposure, weak authentication, poor network segmentation, undocumented remote access, and inadequate monitoring can create opportunities for attackers.
Organizations operating critical infrastructure should move beyond reactive security and adopt continuous exposure management, specialized OT security assessments, strong identity controls, network segmentation, threat monitoring, tested recovery procedures, and regular security validation.
Protecting critical infrastructure requires protecting both the technology and the physical processes that technology controls.
As digital connectivity continues expanding across industrial environments, cybersecurity must become an integral part of operational resilience.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
In addition, COE Security helps organizations strengthen critical infrastructure and operational technology security through OT security assessments, network security reviews, vulnerability assessments, penetration testing, attack surface assessments, remote access security reviews, cloud security assessments, incident response planning, security monitoring, and compliance-focused cybersecurity programs.
For water and wastewater organizations, we can help identify internet-exposed OT assets, assess PLC and HMI security, review remote access pathways, evaluate network segmentation, validate security controls, and develop cybersecurity and incident response strategies.
For manufacturing organizations, we help assess connected industrial environments, OT networks, PLCs, engineering workstations, remote access infrastructure, and third-party connections to reduce the risk of operational disruption.
For energy and utilities organizations, we can support OT security assessments, vulnerability management, penetration testing, threat monitoring, network segmentation reviews, and security control validation.
For healthcare organizations, we help protect connected medical environments, enterprise networks, applications, cloud infrastructure, and sensitive data while supporting security and compliance requirements.
For financial services and government organizations, we provide penetration testing, vulnerability assessments, cloud and network security reviews, threat detection, compliance support, and risk management services.
COE Security also helps organizations develop stronger security programs by combining cybersecurity testing, continuous monitoring, secure development practices, compliance support, and proactive risk management.
The goal is to help organizations identify weaknesses before attackers do, protect critical systems, reduce operational risk, and build stronger cyber resilience.
Follow COE Security on LinkedIn for ongoing insights into cybersecurity, OT security, critical infrastructure protection, AI security, compliance, vulnerability management, and emerging cyber threats to stay updated and cyber safe.
Click to read our LinkedIn feature article