Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Recent Water Utility Attacks Offer a Blueprint for Resilience

    August 14, 2026

    Everything is about to “go dark”

    August 14, 2026

    Behind the Blog: Endless Scam Parade

    August 14, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Recent Water Utility Attacks Offer a Blueprint for Resilience
    News

    Recent Water Utility Attacks Offer a Blueprint for Resilience

    adminBy adminAugust 14, 2026No Comments10 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Building Stronger Utilities Through Shared Lessons

    Water and wastewater utilities have quietly become one of the most targeted sectors in critical infrastructure, and recent incidents across multiple states are making that reality impossible to ignore. These systems process over 32 billion gallons of wastewater every day. An additional 27 billion gallons are withdrawn and delivered from surface water and groundwater sources per day specifically for residential use like providing drinking water, doing laundry, and watering lawns. The public servants operating these critical utilities are keeping our communities safe and functional with little fanfare and, often, with extremely limited resources.

    Aging infrastructure, expanding internet connectivity, and a rapidly evolving threat landscape are colliding in ways that demand attention. Rather than dissect any single incident, the pattern of attacks offers something more useful: a set of hard-won lessons about what resilience truly requires in operational environments where a misconfigured control device can have consequences that go well beyond a data breach. Perhaps more than ever, our adversaries are showing us that cyber resilience and operational resilience are no longer separable.

    Visibility iconLesson 1: Visibility Remains a Foundational Challenge

    Organizations cannot protect systems they don’t know about. This is one of the key reasons the CIS Critical Security Controls (CIS Controls) begin with inventorying everything you own, software and hardware.

    Attackers scan for, build inventories of, and specifically target internet-accessible operational technology (OT). Unfortunately, many of the owners, operators, and security teams responsible for configuring and monitoring those same OT assets are not fully aware of what they own or what is internet-facing. There are many reasons why, but none of them matter during an incident. What matters is that we know, or can know very quickly, everything we need to know about our systems in a crisis.

    Visibility is critical to incident response. On the one hand, many of the impacted entities were able to respond extremely quickly and restore authorized access to affected systems before any public safety impacts occurred. On the other, the discovery of these attacks was due to operational impact, even if minor, and not from security alerts, alarms, or other visibility-related detections on the cybersecurity side. Had the adversary been more advanced, the lack of visibility could have caused much greater impacts, including public health concerns.

    Takeaway: Essential OT security practices require that we establish and maintain complete asset visibility across both IT and OT environments.

    Reference: CIS Control 1 (Inventory and Control of Enterprise Assets)

    Connectivity iconLesson 2: Connectivity Creates Both Opportunity and Risk

    Many critical infrastructure attacks begin with systems that were never intended to be publicly accessible. For years prior to COVID, the utility community had been on a path of IT/OT convergence. The pandemic simply drove a rapid and unplanned expansion of remote access to OT environments in a very short period. Unfortunately, adequate security didn’t keep pace.

    The same remote access tools that let an operator efficiently monitor and manage plants from anywhere without rolling a truck are the capabilities that threat actors exploit. The operational efficiency gained is valuable, especially in a sector with chronically strained resources. The flip side is that many Programmable Logic Controllers (PLCs) and other OT devices are accessible from the open internet, despite basic security controls being widely available and cost-effective.

    Every utility must understand which OT assets can be reached from the internet and whether that exposure is truly necessary. PLCs are designed for reliability: they run industrial protocols that were never intended to be exposed to the internet. Whether by design, misconfiguration, or gradual network sprawl, internet-accessible OT becomes visible to anyone running a basic scan. A quick scan for a single network port used by one specific type of PLC revealed nearly 3,000 exposed devices with over 1,800 being in the United States.

    Takeaway: Every remote access path into an OT environment increases the attack surface. Connectivity decisions require security review, and existing remote access should be inventoried and validated alongside the assets themselves.

    Reference: CIS Control 12 (Network Infrastructure Management), NIST SP 800-82

    Operational Resilience iconLesson 3: Operational Resilience Matters as Much as Prevention

    Even strong security programs must prepare for disruption. Preventing every cyber attack is not a realistic goal. What is realistic is that proactively building operational resilience can dramatically limit the blast radius when there is an incident. Emergency protocols, including isolating key systems and switching to manual control in near real time, preserve public safety even as a full investigation begins.

    Response to the current wave of attacks on water systems across multiple states reinforced the fact that the ability to switch to manual operation is a key feature of industrial systems. Utilities that maintain documented manual procedures, keep operators trained, and regularly test their emergency response plans fare significantly better than those that wait to figure it out in the middle of a crisis. The EPA recommends regular tabletop exercises to test Emergency Response Plans and train staff on response protocols.

    Operational resilience is often heavily influenced by resourcing. An incident that would be easily contained in a highly resourced utility can cause prolonged operational impacts in organizations with limited monitoring, limited segmentation, and no dedicated cybersecurity personnel. To boost resilience, organizations large and small can take advantage of community resources through the MS-ISAC, WaterISAC, and OT-CERT as well as federal resources.

    Takeaway: Business continuity, emergency response, and crisis management plans aren’t nice to have items; they are operational requirements. And they require regular updates and regular exercise. Every operator must know their manual fallback procedures before a crisis.

    Reference: CIS Control 17 (Incident Response Management); AWIA Emergency Response Plan requirements; CISA Water Sector Incident Response Guide

    Risk iconLesson 4: Third-Party Risk Extends Into OT Environments

    The water sector runs on vendor relationships. Instrumentation vendors, supervisory control and data acquisition (SCADA) integrators, chemical suppliers, managed service providers, and equipment manufacturers all have varying degrees of access to utility systems. And as we learned above, that access is not always well-governed. From underlying operating systems lacking reliable patch management to unsafe connection protocols to an overall misunderstanding of security best practices, the risk provided by third parties creates a complex and challenging web of interdependency.

    Third-party risk in OT is different from third-party risk in IT. A vendor remoting into a billing system is a governance and data protection concern. But a vendor remoting into an industrial system is an operational safety concern. The security expectations need to reflect that distinction but often don’t. In recent weeks, we’ve learned that many PLCs are not tucked behind VPNs, rogue wireless access points are common in water districts nationwide, and sometimes vendor security advisories give adversaries the very information they need to remotely reset your devices. While security advisories contain valuable patch information for defenders, they can often act as a tutorial for those with ill intent.

    To truly build the operational resilience described above, utilities must be able to both trust their third-party vendors to bake security into their products and processes and hold them accountable when they don’t. This isn’t an overnight solution, but it is required to reduce community-wide risk.

    Takeaway: Third-party access to OT systems requires, at a minimum, the same rigor as direct operator access. Every vendor connection to OT should be inventoried, time-limited, monitored, and tied to a specific authorization.

    Reference: CIS Control 15 (Service Provider Management); Joint Guidance on OT Remote Access

    Public Service iconLesson 5: Cybersecurity is Not Just a Business Issue, It’s a Public Service Issue

    Water utilities don’t make headlines when they work. They make headlines when they don’t. A pressure loss, a contamination scare, a boil-water notice, and other downstream consequences of a successful cyber attack on water infrastructure aren’t abstract to the public. The impacts are felt in hospitals, schools, restaurants, businesses, and homes, and it reframes the issue of cybersecurity investment from a business cost to a public service obligation.

    For water utilities, and many other public services, the responsibility for reasonable security can’t rest solely on the IT department. Technology managers in water districts large and small are asked to solve a problem that Fortune 500 companies struggle with, on a fraction of the budget, with a fraction of the staff, and with infrastructure that often predates the internet. Yet in our rapidly evolving technology environment, cyber and physical security decisions increasingly affect service reliability, community trust, regulatory obligations, and operational continuity.

    From incident protection to real-time detection, from proactive emergency planning to clear communication pathways in a crisis, and from preventative maintenance to manual operation during an incident or outage, these are public safety decisions supported by and supporting the technical staff that make it all possible. Anticipating emergencies, careful planning, and conducting drills before an incident reduces confusion, builds confidence, and supports faster decision-making to ensure public health and safety is not at risk.

    Takeaway: Cybersecurity in the water sector is a resource and prioritization challenge as much as a technical one. Leadership at every level, from lawmakers and regulators down to the local district, has a role in closing it.

    Reference: CIS Controls; EPA Cybersecurity Grant Program; WaterISAC Resource Center; Security Strategy for Critical Infrastructure

    Utilities iconWhere Utilities Go From Here

    The past several weeks have been a stress test the sector didn’t ask for. But it reminds us of an idiom that has long been attributed to Churchill: we should never let a good crisis go to waste. We can learn from this event since the pattern is clear: exposed devices, remote reset weaknesses, flat networks, and limited visibility. None of those are unsolvable problems nor do they require a seven-figure budget to address. Some security prioritization and leadership focus today gets us closer to operational readiness tomorrow.

    Run through the basics. Complete your AWIA Risk and Resilience Assessment if you haven’t already. Segment your OT network from your IT network. Establish visibility into what you own and disconnect anything openly internet-facing or put it behind proper security tools. Placing internet-facing OT assets behind a VPN is one of the highest-impact, lowest-cost steps you can take almost immediately. Build and exercise your incident response plan. Seek out the free resources that exist specifically for this sector.

    Even sophisticated threat actors will go after low-hanging fruit first, so your focus should be to put as many obstacles in the way as possible.

    One thing you can do today: Search your organization on Shodan. It’s free, it takes five minutes, and it will show you exactly what your utility looks like to an adversary scanning the internet. If you find OT exposed that shouldn’t be, then you know where to start!

    Need help getting started? Join the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) and take advantage of cybersecurity resources, threat intelligence, and incident response support specifically designed to help state, local, tribal, and territorial organizations strengthen resilience.


    About the Author

    Randy Rose
    Senior Vice President, Security Operations and Intelligence

    Randy has over two decades of experience across state, local, and federal government. He currently leads Security Operations at the Center for Internet Security where he is privileged to oversee the execution of the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Multidimensional Threat Intelligence (MDT), Cyber Incident Response Team (CIRT), and Red Team missions in direct support of the Multi-State ISAC. Previously, he led the largest Joint Military Security Operations Center in Europe and the Intelligence Department for the Navy’s Global Cyber Operations Task Force.

    Early in his career, he served in the U.S. Air Force and later was New York State’s first local government-focused penetration tester. He moonlights as an adjunct instructor at Siena University and the State University of NY at Albany. He sits on the Board of Directors for two local non-profits helping those in need of housing, food, and trauma services. He loves rock music and is willing to have deep conversations with anyone over his favorite bands.

     



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleEverything is about to “go dark”
    admin
    • Website

    Related Posts

    News

    Everything is about to “go dark”

    August 14, 2026
    News

    Behind the Blog: Endless Scam Parade

    August 14, 2026
    News

    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    August 14, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Recent Water Utility Attacks Offer a Blueprint for Resilience

    August 14, 2026

    Everything is about to “go dark”

    August 14, 2026

    Behind the Blog: Endless Scam Parade

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.