The prescient threat: Why CISA's water advisory demands process-level visibility

Why grounding cybersecurity in physical ground truth is essential for safeguarding public health and maintaining operational integrity.

Key Highlights

  • Cyberattacks on water utilities are increasingly sophisticated, enabling remote manipulation of physical processes without detection.
  • Legacy infrastructure and open protocols expose critical control systems to exploitation, often without adequate cybersecurity protections.
  • The 'Blind Operator Scenario' occurs when falsified digital data prevents operators from accurately assessing physical equipment status, risking public safety.

In November 2025, I wrote an article for WaterWorld examining a cyberattack on the Risevatnet dam in Bremanger, Norway. In that incident, threat actors logged into a remote-control panel, opened a discharge valve for four hours, and posted footage on Telegram, all while upper-level monitoring systems registered normal conditions.

At the time, I described that breach as a precautionary warning shot. It demonstrated that adversaries no longer need to physically compromise infrastructure onsite or damage equipment directly. Instead, they can alter physical processes remotely while keeping control room displays green and serene.

What began as an isolated incident abroad has now escalated into direct operational disruptions across American communities, with a widely reported wave of cyber intrusions targeting municipal water utilities across at least seven U.S. states (including facilities in Minnesota and Michigan). In a joint cybersecurity advisory issued by CISA, the FBI, NSA, EPA, DOE, CNMF, and the Department of the Treasury, federal agencies confirmed that threat actors maliciously altered controller logic, warning that " the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies."

This article will explore how these cyber attacks occur at a technical level, the operational risks posed by the "Blind Operator Scenario," and how Process-Oriented OT Cybersecurity provides independent physical visibility at Level 0. Beyond simply ensuring critical decisions are based on physical ground truth, this approach delivers real-time anomaly detection, unparalleled operational intelligence, and continuous process integrity to safeguard mission-critical assets.

An asymmetrical battlefield: Understanding water sector vulnerabilities

To understand why U.S. water infrastructure has become a prime target, one must recognize the profound imbalance defining this threat landscape. On one side are well-funded, state-sponsored actors operating with advanced offensive capabilities. On the other are local municipal utilities operating with lean public works crews and tight budgets.

While adversaries frequently exploit three core structural vulnerabilities (representing the lowest-hanging fruit) it is critical to stress that these well-funded, state-sponsored actors are systematically targeting all forms of critical infrastructure and dedicating immense resources to compromise these systems.

These foundational vulnerabilities include:

Legacy infrastructure retrofitted for remote access: Most water plants rely on legacy Programmable Logic Controllers (PLCs) built decades ago without basic encryption or password protections. To enable remote vendor maintenance and centralized control, utilities retrofitted these older devices with cellular modems and network gateways, inadvertently exposing them to the public internet.

Protocol openness: Attackers do not need complex zero-day exploits. By targeting exposed management ports or brute-forcing remote field modems via Dropbear SSH, intruders connect directly to PLCs using standard, commercially available vendor engineering software.

The regulatory alignment gap: While water utilities face strict, mandatory compliance for water quality and public health, cybersecurity standards have historically remained voluntary or unfunded. Consequently, digital security investments are routinely deferred in favor of physical plant maintenance.

In recent campaigns targeting U.S. facilities, state-sponsored groups actively weaponized this gap. Attackers used foreign servers to connect to exposed controllers, downloaded the plants' software project files, and uploaded tampered programs back onto the devices.

Specifically, investigators observed that attackers modified pre-written logic modules across PLCs manufactured by major vendors including Rockwell Automation, Schneider Electric, and Siemens. They inserted malicious code that overrode safe operating rules and disabled emergency shut-off commands and alarms. Meanwhile, they altered the data sent to operator screens so chemical levels, pressures, and equipment status appeared completely normal.

Because control screens continue to display normal operating conditions while physical equipment enters unsafe states, plant staff are left without accurate visibility into what is actually happening in the facility. This disconnect forces operators into a dangerous dilemma: what should be called The Blind Operator Scenario.

The "Blind Operator" Scenario: High-stakes decisions under uncertainty

The moment automated controls fail, present falsified data, or force a complete network quarantine, utility leadership enters the Blind Operator Scenario — a condition where operators lose trusted digital telemetry and must manage physical plant processes in the dark.

Corporate IT can isolate a hacked server in seconds by pulling the cable. Water utilities don't have that choice: shutting off the water causes an immediate public emergency.

Depressurizing a municipal water distribution system creates severe public health hazards. A sudden loss of pressure can create conditions that allow back-siphonage, drawing groundwater contaminants and bacterial pathogens into clean water mains, while simultaneously leaving fire hydrants dry.

In the immediate fog of war following a cyber intrusion, plant decision-makers may be forced to navigate three high-stakes operational choices without trusted SCADA data:

  1. Issue a community-wide boil water advisory? Issuing an advisory triggers immediate public panic and severe commercial disruption for local businesses. If the cyber intrusion was merely an isolated network probe or a benign false positive, the advisory inflicts massive, unnecessary economic damage.
  2. Halt treatment production entirely? Shutting down high-service pumps and isolating chemical treatment skids protects physical machinery from damage. However, it can reduce or eventually eliminate distribution pressure, depending on system configuration and available storage, risking widespread pipe contamination.
  3. Switch to manual operation and continue with caution? Switching wells and pumps to manual control keeps water flowing through the system. However, if chemical feed skids are secretly over-dosing or under-dosing behind falsified supervisory screens, running manually without independent verification risks delivering improperly treated water to the public.

Making these critical choices based on software that may be tampered with creates an unacceptable risk profile. Utilities require an unmanipulated, physical source of ground truth to guide their response.

Process oriented OT cybersecurity: Grounding defence at Level 0

Over the past decade, cybersecurity in the water sector has focused almost entirely on software networks, firewalls, and Intrusion Detection Systems (IDS). While these tools are necessary for network perimeter security, they have a major shortfall: they monitor digital network packets, not physical machinery.

When an adversary modifies controller code, network firewalls process the activity as legitimate industrial protocol traffic. When the SCADA system receives status updates from the compromised controller, it displays whichever falsified values the device transmits. Network security tools merely monitor software-level communication, but they cannot independently verify actual physical operations.

Process-Oriented OT Cybersecurity bridges this gap by moving visibility down to Level 0 of the Purdue Model — the physical process layer where raw electrical signals drive field machinery. Level 0 includes physical pumps, valves, and chemical dosing skids, along with hardwired electrical loops (such as 4–20 mA current signals, 0–10V control lines, or motor current transformers) that power them.

By capturing these electrical signals passively and out-of-band — completely separate from PLCs, SCADA servers, and network firewalls — utilities establish an unmanipulated physical ground truth. When implemented as a genuinely isolated, out-of-band monitoring architecture, the monitoring system has no direct control pathway into the PLC or SCADA network, substantially reducing the ways an attacker could manipulate or disable those measurements through the compromised control system.

Resolving the dilemma: Physical signals vs. software claims

During a cyber incident, operators face severe operational uncertainty because supervisory displays can no longer be trusted. When screens freeze, go dark, or present falsified "normal" readings, operators cannot verify whether physical equipment is operating safely or being manipulated behind the scenes.

By cross-checking software-layer telemetry against independent Level 0 electrical signals in real time, plant leadership can eliminate operational guesswork and categorize an incident into one of three distinct realities:

1. Active physical sabotage (Real process threat)

If hardwired Level 0 electrical signals reveal that pump motors are drawing abnormal current, chemical dosing skids are drifting out of safe parameters, or valves are opening without authorization, physical signals confirm that the process is behaving abnormally, giving operators evidence that the event has crossed from a digital anomaly into a physical operational problem. This objective evidence provides plant leadership with the immediate certainty required to halt the affected process, switch to backup water storage, and issue public health advisories.

2. Digital interface failure only (Safe physical operations)

Conversely, if control displays disconnect or freeze due to ransomware, IT network isolation, or software crashes, independent Level 0 electrical signals eliminate operational guesswork by indicate that pumps and other monitored equipment remain within their expected operating ranges. This provides evidence the incident is confined entirely to the digital network, allowing operators to confidently maintain manual water production without issuing unnecessary, panic-driven boil-water notices.

3. Benign IT anomaly (False alarm)

Finally, when an upper-level network security tool fires an urgent alert regarding suspicious IP traffic or a potential intrusion, Level 0 electrical signals show zero deviation in physical equipment behavior, confirming the machinery is operating exactly as intended. This supports the conclusion that the network event has caused no physical impact, allowing IT and security teams to investigate and remediate the alert without interrupting plant operations.

Conclusion: Decisions based on physical reality

The recent wave of cyber intrusions across U.S. water utilities marks a permanent shift in critical infrastructure risk. It should be a wake-up call: defensive strategies built exclusively around IT-based cyber strategies leave critical operations dangerously exposed when sophisticated adversaries bypass control logic.

There is a path to resilience. While manual fail-safes are an essential operational fallback, decision-makers still require uncompromised, real-time ground truth to navigate a crisis without risking public safety or economic disruption.

Software control interfaces can be spoofed, altered, or severed. Raw electrical physics cannot.

By embedding out-of-band Level 0 process monitoring into their cybersecurity architecture, water utility leaders can eliminate the Blind Operator Scenario. However, the value extends far beyond simply cross-referencing data. A comprehensive Level 0 approach provides autonomous operational resilience, enabling early anomaly detection, predictive maintenance insights, and continuous process integrity. This ensures that no matter how complex digital threats become, every critical operational decision remains firmly grounded in the physical truth of their machinery.

About the Author

Amir Samoiloff

Amir Samoiloff is CEO of Siga.

Sign up for our eNewsletters
Get the latest news and updates