What recent cyberattacks reveal about securing water utility OT
Key Highlights
- Many water utilities still rely on legacy PLCs and remote access methods that are vulnerable to cyberattacks, highlighting the need for better security configurations.
- Smaller utilities often lack dedicated cybersecurity expertise and depend on third-party support, increasing their exposure to cyber threats, especially via publicly accessible cellular networks.
- Basic security practices, such as changing default passwords and limiting remote access modes, can significantly reduce vulnerabilities in operational technology environments.
A wave of recent cyberattacks targeting U.S. water systems has highlighted persistent vulnerabilities in operational technology (OT) environments, prompting renewed discussion about how utilities – particularly smaller systems – can strengthen cybersecurity without sacrificing operational efficiency.
During a recent WaterWorld roundtable discussion, automation expert Jeremy Pollard, retired industrial automation specialist and columnist for Control Design, and Gabriel Collins, Baker Botts Fellow in Energy and Environmental Regulatory Affairs at Rice University's Center for Energy Studies, discussed what the attacks reveal about the current state of water utility cybersecurity and what utilities can do to reduce their risk.
While investigations into the attacks remain ongoing, both experts agreed the incidents should serve as a wake-up call for the industry.
Legacy OT remains a primary concern
According to Pollard, many water and wastewater utilities continue to rely on legacy programmable logic controllers (PLCs) and remote access methods that were designed long before cybersecurity became a central concern.
Pollard said many PLCs are internet-accessible because operators and integrators need remote access to monitor and maintain facilities. If attackers discover exposed devices or compromise remote communication methods, they may be able to gain access to control systems.
"If you use a tool like Shodan... PLCs show up all over the place," Pollard said, noting that internet-facing devices often exist because utilities require remote access for maintenance and operations.
Once inside, attackers may be able to change passwords, lock legitimate users out of controllers or manipulate operating parameters if sufficient protections are not in place. Pollard noted that some reporting suggests the attackers demonstrated familiarity with PLC programming and industrial control systems.
He added that the widespread use of major automation platforms – including Schneider Electric, Siemens and Rockwell Automation – likely makes them attractive targets simply because of their prevalence throughout the water sector.
Smaller utilities face unique challenges
The discussion also focused on why smaller utilities frequently appear among publicly identified cyberattack victims.
Collins suggested that highly capable nation-state actors are likely probing many more systems than those ultimately reported.
"My suspicion is... these Iranian linked groups are probably attacking a lot more water systems," Collins said, adding that the publicly known incidents may simply represent systems where attackers successfully gained access or caused noticeable disruptions.
Pollard agreed, noting that smaller utilities often depend on third-party contractors for automation support and may lack dedicated OT cybersecurity expertise.
Many also rely on publicly accessible cellular networks for remote communications rather than private industrial networks, potentially increasing exposure if communication devices are compromised.
Simple security practices still matter
Although sophisticated nation-state attacks dominate headlines, both experts stressed that many vulnerabilities remain surprisingly basic.
Pollard recalled working with a municipality that used the password "password" across multiple devices, including cellular modems.
"It's easier to do that than to have different passwords," he said, acknowledging that operational convenience has often taken precedence over security in smaller organizations.
He also pointed to a recent report describing attackers targeting hotel Wi-Fi networks to steal credentials from traveling personnel who remotely access industrial systems.
Because many operators and contractors connect to facilities while traveling, compromised credentials can potentially provide attackers with legitimate access into operational networks.
Older equipment can still be secured
Replacing legacy PLCs is not always feasible, but Pollard said utilities can immediately improve security by reviewing how controllers are configured.
One recommendation is leaving controllers in "run mode" rather than remote programming mode whenever possible, preventing unauthorized online logic changes while still allowing systems to operate normally.
"It doesn't stop data changes," Pollard cautioned, noting attackers could still modify setpoints or timer values if they gain sufficient access.
He also referenced the industry's "Top 20 PLC Security" guidance, which outlines software and configuration practices intended to prevent unsafe parameter changes and establish operating boundaries for industrial control systems.
Why manual operations mattered
Most utilities affected by the recent attacks reported that drinking water remained safe because operators shifted facilities into manual operation after automated controls were disrupted.
While Pollard acknowledged those responses prevented more serious consequences, he argued the attacks were still successful in another sense.
"We're talking about it," he said. "The fact that it's got everybody on edge, I believe it's been very successful in that regard."
Collins added that cyberattacks do not necessarily need to cause catastrophic failures to achieve strategic objectives.
From his perspective, simply demonstrating the ability to access critical infrastructure can serve as a form of deterrence by reminding governments and utilities that vulnerabilities exist. He suggested that different nation-state actors may pursue different goals, ranging from signaling capability to causing operational disruption during future geopolitical conflicts.
Proactive testing over reactive response
Looking ahead, both experts advocated for greater use of proactive cybersecurity assessments.
Collins suggested federal agencies could conduct or fund penetration testing of utility systems to identify vulnerabilities before adversaries do.
"You can either adversarially test ourselves and find problems and fix them, or we can be tested by our adversaries," Collins said. "That's the fundamental security choice we're facing here."
Pollard agreed, saying the water sector should revisit remote access architectures that have become increasingly complex over time.
In his experience, some utilities now require numerous authentication steps involving jump servers, firewalls and demilitarized zones (DMZs), creating systems that are difficult to manage while not necessarily improving security.
"Anybody that's using remote access, you have to revisit that and make sure that it's as simple as it can be and have security as a focus," Pollard said.
As cyber threats against critical infrastructure continue to evolve, both experts emphasized that improving operational technology security will require a combination of modernized equipment, stronger cybersecurity practices and a proactive approach to identifying weaknesses before attackers do.
About the Author
Alex Cossin
Associate Editor
Alex Cossin is the associate editor for Waterworld Magazine, Wastewater Digest and Stormwater Solutions, which compose the Endeavor Business Media Water Group. Cossin graduated from Kent State University in 2018 with a Bachelor of Science in Journalism. Cossin can be reached at [email protected].




