
Water Utilities Have a Cybersecurity Problem, and It’s Not a Lack of Frameworks
A few weeks ago, I wrote that AWIA was never enough to address the cybersecurity risks facing U.S. water utilities. Since then, we’ve gotten another reminder of why.
In late July, the FBI and EPA warned that attackers had targeted internet-facing PLCs at water and wastewater utilities across multiple states, in some cases causing operational disruptions including loss of pressure, flooding, and loss of monitoring or control.
More recently, federal agencies have issued a joint cybersecurity advisory warning of active threats targeting Siemens S7 Series programmable logic controllers (PLCs), technology used throughout water and wastewater systems and other critical infrastructure.
At the same time, lawmakers have introduced the Water Cyber Shield Act, legislation intended to strengthen cybersecurity oversight and provide additional resources to water utilities.
Together, these developments reinforce the same issue: systems that control physical processes remain active targets, while regulators are looking for stronger ways to address the vulnerabilities putting those systems at risk.
Attackers Don’t Need to Reinvent the Wheel
We have known for years that exposed industrial control systems present a risk. What’s changing is how quickly attackers can take advantage of it.
That risk also extends beyond the utility itself. The recently disclosed breach of Micro-Comm, a provider of PLC and SCADA technology used by water and wastewater facilities, is another reminder that vendors and third-party systems are part of the OT attack surface.
Recent water utility incidents show what that exposure can lead to. Attackers reached internet-facing PLCs and altered device configurations, disrupting operators’ ability to monitor or control systems. They didn’t need a new attack path; they exploited one that was already there.
AI may make that easier. According to the advisory, threat actors are using publicly available information about Siemens S7 PLCs and AI to help generate exploitation scripts, reducing the time and technical expertise required to target poorly secured OT environments.
An Internet-Exposed PLC Is Still an Internet-Exposed PLC
There’s a tendency in our industry to focus on the newest part of an attack. Right now, that’s AI. AI may be a new part of the attack chain, but the underlying security problems aren’t new. If a PLC controlling a physical process is directly accessible from the internet, weakly segmented, protected by default credentials or reachable through an insecure remote access path, the exposure already exists.
Start with the architecture.
- Can an attacker reach the PLC?
- Should they be able to?
- What sits between an external connection and the control system?
- Do you know which industrial devices are exposed?
- Can you identify unauthorized changes to controller logic or process configurations?
- Can you distinguish legitimate engineering activity from malicious activity?
- And if an attacker reaches an operational system, do you have the visibility and procedures necessary to respond without creating a larger operational problem?
Those are the questions that determine whether an attacker can turn a vulnerability into an operational incident.
Regulation Is Starting to Catch Up
The Water Cyber Shield Act, introduced in the Senate earlier this month, is another important development. The proposed legislation would give the EPA greater cybersecurity oversight of water systems, including authority to conduct assessments, require corrective action for significant vulnerabilities, expand incident reporting and provide additional funding to help utilities strengthen cyber resilience.
This begins to address a longstanding gap in water utility cybersecurity. For years, utilities have largely been asked to assess and document risk without a consistent mechanism requiring them to address the vulnerabilities those assessments uncover. That was one of my biggest criticisms of relying on AWIA as a cybersecurity framework.
Assessing risk is necessary, but risk doesn’t decrease until vulnerabilities are addressed. Stronger accountability around remediation would be progress. Utilities, however, shouldn’t wait for regulation to address exposures and weaknesses they already know exist.
Get Back to the Fundamentals
Water utilities don’t need another framework telling them cybersecurity matters. They need to prioritize what actually reduces operational risk. That starts with the fundamentals:
- Remove unnecessary internet exposure from PLCs, HMIs and other industrial systems.
- Secure remote access and segment IT and OT environments.
- Eliminate default and shared credentials wherever possible.
- Maintain an accurate OT asset inventory and understand what’s communicating.
- Monitor critical systems for unauthorized changes.
- Test incident response against scenarios involving loss of visibility or control.
None of this is revolutionary, and that’s the point. Reducing the risk of these attacks starts with identifying and closing the pathways attackers are already exploiting.
The Goal Isn’t Compliance. It’s Resilience.
More federal attention, funding and stronger cybersecurity requirements could help water utilities address longstanding security challenges, but regulation should establish a floor, not a finish line.
A strong cybersecurity program comes down to operational resilience: limiting access to critical systems, detecting malicious activity quickly, and keeping water operations safe and reliable when something goes wrong.
The latest attacks and federal warnings aren’t introducing a new problem. They’re showing us how much easier an old one is becoming to exploit and why it’s time to fix it.
Back

