RFDELTA Signals
Signal 019Free

Water Utility Cybersecurity: Why Internet-Exposed PLCs Create Physical Infrastructure Risk

CISA warned about increased targeting of internet-exposed programmable logic controllers in water and wastewater systems. The risk reaches pumps, pressure, monitoring and manual operations.

RFDELTA Signal 019: Water OT CybersecurityRFDELTA SIGNAL 019
When software touches pumps, valves, pressure and chemistry, cybersecurity becomes part of the utility itself.Critical infrastructure / OT cybersecurity

Why it matters

Operational technology connects software to the physical process. In a water utility, a small programmable logic controller can sit in the control path for pumps, pressure, treatment or monitoring. That makes internet exposure materially different from an ordinary website vulnerability.

CISA warned about internet-exposed PLCs

CISA reported increased activity targeting internet-exposed programmable logic controllers used by water and wastewater operators. The agency's guidance emphasizes removing PLCs from direct public-internet exposure and securing every remote-access path.

The central issue is reachability. A controller that can be found and authenticated to remotely can become an operational target rather than only an IT asset.

More than 30 Minnesota systems were targeted in one cluster

Associated Press reported that more than 30 Minnesota water systems were targeted in a late-July cluster. Investigators had not publicly identified the culprit at the time of that reporting, so attribution should remain separate from the observed operational activity.

Cyber effects can become physical effects

Recent incidents have included changes to controller settings, passwords or network addresses and, depending on the affected utility, loss of remote monitoring or control, pressure changes, flooding, boil-water notices or a switch to manual operations.

Those effects varied by system; targeting does not mean every community lost service or water quality.

Resilience requires an OT operating model

The mitigation stack is straightforward in concept but operationally demanding: inventory every exposed connection, remove controllers from the public internet, harden remote access and credentials, segment networks, monitor changes and preserve a tested manual operating mode.

The RFDELTA takeaway

Critical-infrastructure cybersecurity is a systems discipline. The relevant outcome is not simply whether malware runs; it is whether operators can continue controlling a physical process safely when digital access is degraded or hostile.

Watch the original Signal

The concise video version is designed for discovery; this page preserves the sourcing, caveats and deeper context.

Memorable path: https://rfdelta.com/019

Video transcript

A municipal pump can depend on a small industrial controller reachable from miles away. CISA says attackers are increasingly targeting internet-exposed programmable logic controllers used by water and wastewater operators. Recent incidents have disrupted utilities across multiple states, while more than thirty Minnesota water systems were targeted in one cluster. Investigators had not publicly named the culprit. The failure mode is physical: attackers can change controller settings, passwords, or network addresses. That can knock operators out of remote monitoring and control. Federal guidance is direct: take PLCs off the public internet and secure every remote path. Inventory every connection, use strong access controls, and preserve manual operation. The lesson is bigger than water. When software touches pumps, valves, pressure, and chemistry, cybersecurity becomes part of the utility itself.

Frequently asked questions

What is a PLC?

A programmable logic controller is an industrial computer used to monitor and control physical equipment and processes.

Did investigators publicly attribute the Minnesota cluster to a specific actor?

Not in the Associated Press reporting used for this Signal. The operational facts and actor attribution should therefore be treated separately.

What is CISA’s core mitigation message?

Reduce direct internet exposure, secure remote access and credentials, understand every connection, and maintain operational resilience including manual control where appropriate.

Primary sources

Continue exploring RFDELTA

RFDELTA Signals map the hidden systems, technology transitions and operational dependencies underneath fast-moving headlines.