top of page
bb9e2e_4f8caeebaf524be18dc0b438da38b83a~mv2_edited.png

Five Steps Toward Safer, More Resilient Water Operations

  • 2 days ago
  • 8 min read

How Water Utilities Can Prepare SCADA for an Active Cyber Threat



Overview: After attacks affected water systems across multiple states, the priority is no longer general cyber awareness. It's protecting control, maintaining safe operations, and recovering with confidence.


Cyber Threats to Water Systems are Dramatically Increasing

The cyber threat facing water utilities changed significantly in 2026.


On April 7, the EPA, FBI, CISA, and NSA issued an urgent joint advisory warning that Iranian-affiliated actors were targeting internet-connected operational technology across U.S. critical infrastructure, including drinking water and wastewater systems.

The reported activity went beyond stolen credentials. Attackers erased configurations, tampered with mechanical sensor functions through software, disrupted human-machine interfaces (HMI), manipulated information displayed through SCADA systems, and caused operational downtime and financial loss.


On July 22, federal agencies expanded the advisory. The update added guidance for detecting tampered Rockwell Automation PLC code and warned that attackers were also targeting Schneider Electric, Siemens, and other systems.


Within days, the warning became even more immediate. A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27. On July 30, the FBI and EPA reported that water and wastewater utilities in at least seven states had experienced incidents since July 27, with some attacks degrading water operations. Reported effects included lost monitoring and control, pressure loss, flooding, changed network settings, modified passwords, and altered PLC project files.[2]


The significance of these events is not simply that attackers reached water-sector technology. It's that familiar weaknesses could be repeated across multiple sites. The FBI noted that similarities in network configurations provided by third parties may allow attackers to reproduce a successful method across different customers.


For utilities, that changes the preparation question. The objective is no longer only to stop someone from logging into a system. Utilities must be able to verify that operational information is trustworthy, limit the physical consequences of a compromise, continue providing safe service during disruption, and restore systems from a known-good state.


The following five steps turn that objective into a practical SCADA modernization roadmap.


Step 1: Protect the Ability to Verify the Physical Process

Cybersecurity planning often begins with technology. Water utilities should begin with the physical process the technology controls. A compromised control environment can affect water pressure, chemical dosing, tank levels, treatment processes, pumps, valves, alarms, and continuity of service. The severity of an attack depends on what that device controls and whether operators can independently determine what is happening in the field.


That distinction became especially important after federal investigators examined a malicious PLC project file during the 2026 campaign. The altered file retained portions of the original ladder logic while adding instructions that overrode functions responsible for maintaining safe operating parameters.[1] The system could therefore appear partially familiar while no longer operating entirely as intended.


This is why a modern SCADA environment must provide more than visibility. The screen cannot be the utility’s only source of truth. Operators need a way to confirm that the digital representation still matches the physical process.


Step 2: Remove Direct Exposure Without Giving Up Remote Operations

Remote access is essential for many water utilities. It allows operators and specialists to monitor wells, tanks, reservoirs, pump stations, treatment plants, and chemical-feed systems without continuously staffing every location.


The problem is not remote access itself.

The problem is direct and unmanaged access to operational equipment.


In December 2024, EPA and CISA warned that attackers could use public search tools to find exposed HMIs. The agencies cited incidents in which pro-Russia hacktivists changed operating settings, pushed pumps and blowers beyond normal parameters, disabled alarms, changed administrative passwords, and forced utilities to return to manual operations.[3]


The July 2026 attacks reinforced the same underlying weakness. Actors remotely accessed internet-facing PLCs and changed passwords and IP addresses, leaving some operators unable to monitor or control connected equipment.[2] Removing a PLC or HMI from direct internet exposure does not require abandoning remote operations. It requires placing remote access behind an intentionally designed security layer.


The National Institute of Standards and Technology(NIST) provides three reference architectures for securing water and wastewater operational technology with commercially available tools. The designs emphasize controlled access, secure communication, managed identities, endpoint protection, change control, and third-party requirements established before a vendor connects to the environment.[4]


Lastly, a remote connection should always have a defined operational purpose, an accountable owner, limited privileges, monitored activity, and a reliable way to revoke access. Recent CISA warnings about undocumented cellular modems makes this especially urgent. An architecture diagram may show a segmented environment while a field-installed modem quietly creates a second path around it. Utilities therefore need to validate their actual external connections, not only the connections leadership believes are present.


Step 3: Turn Asset Inventory Into an Operational Record of Truth

Utilities cannot protect equipment they do not know they have. Yet a conventional equipment list is not enough to support cyber resilience.


A useful operational technology inventory should connect each device to its function. Leaders need to know what physical process it controls, how it communicates, who can access it, who maintains it, whether the manufacturer still supports it, where its approved configuration is stored, and what happens if it becomes unavailable.

That context changes how vulnerabilities are prioritized.


A publicly exposed modem associated with a noncritical monitoring function presents one type of risk. An exposed controller connected to pressure, chemical dosing, or treatment equipment presents another. Without process context, both may appear as equivalent rows in a spreadsheet even though their potential consequences are very different.


The scale of the challenge is substantial. In November 2024, the EPA Office of Inspector General reported the results of a passive assessment covering 1,062 drinking water systems serving more than 193 million people. The assessment identified 97 systems serving approximately 26.6 million people with critical or high-risk vulnerabilities. Another 211 systems serving approximately 82.7 million people had externally visible open portals associated with medium- or lower-risk concerns.[5]


The lesson is not simply that more inventories are needed. It's that inventories must remain current enough to support decisions during an active threat. When CISA or a manufacturer releases an advisory, a utility should be able to determine quickly whether the affected product is installed, where it is located, what it controls, whether it is exposed, and who is responsible for the response.


Inventory must become an ongoing operational discipline, not a spreadsheet assembled once for an assessment and forgotten until the next audit.


Step 4: Prepare the System to Degrade Predictably

The July attacks showed that cyber resilience is partly determined by what happens after operators lose digital control. According to the FBI, the operational consequences of the recent incidents varied according to the function of the compromised PLC, the equipment it supported, and the utility’s ability to switch to manual operations. CISA reported that some activity resulted in boil-water notices and sustained manual operations.[2]


Those outcomes closely resemble the scenario EPA tested earlier in the month.

On July 8, EPA’s National Cyber Drill challenged water and wastewater utilities to maintain critical functions while telecommunications and internet services were unavailable or unreliable. Participants operated in a simulated environment with limited or no access to remote SCADA connectivity, cloud services, email, Voice over IP, and other digital communication tools.[7]


EPA has not published a formal after-action report or sector-wide findings from the drill. However, the exercise design identifies the underlying resilience standard clearly. A utility should be able to transition from connected operations to degraded or manual operations without creating a second emergency. That requires more than a binder labeled “incident response.”


When normal communications fail, operators still need a clear way to run the system, confirm that critical readings are accurate, and know who has the authority to make decisions. They also need protected backups of the configurations and applications required to restore operations safely.


Recovery order matters as much as backup availability. Restoring a compromised configuration quickly can recreate the incident. Utilities need to know which systems must return first, how the approved configuration will be validated, which vendors will be required, and what evidence is necessary before remote operations resume.


A resilient SCADA environment does not promise that nothing will fail. It ensures that failure occurs within understood boundaries and that the utility retains control over the response.


Step 5: Make Cyber Resilience Part of the Modernization Roadmap

Cybersecurity cannot sit off to the side while SCADA modernization moves forward. It needs to be built into the same roadmap, alongside decisions about aging equipment, unsupported systems, operational priorities, etc.


Network segmentation is a good example. Separating business IT from operational technology can make it harder for an attacker to move between environments, but a firewall alone is not enough. Utilities first need to understand how control centers, remote sites, engineering workstations, vendors, and production systems actually connect and depend on one another. Without that context, adding another layer of security may create more complexity without meaningfully reducing risk.


The same principle applies to patching. A security team may identify an update as urgent, while operators know that applying it requires testing, vendor support, or a carefully planned shutdown. A workable roadmap connects both realities and documents the compensating controls needed until the permanent fix can be implemented.


This is the foundation of defensible automation. The next generation of SCADA will connect operational information with maintenance, asset management, analytics, regulatory reporting, digital twins, and field workflows. Those capabilities become more valuable when operators can verify the underlying data, trace changes, limit access, isolate critical processes, and recover configurations with confidence.


Defensible automation increases capability while preserving control.


Five Questions Utility Leaders Should Be Able to Answer

A practical SCADA readiness review should determine whether leadership can confidently answer five questions:

  • Do we know every pathway into our operational environment, including vendor-managed and cellular connections?

  • Can we prove that active PLC logic and HMI configurations match an approved baseline?

  • Can operators maintain safe service without remote SCADA, cloud tools, or normal telecommunications?

  • Can we restore critical systems in the correct order from protected, known-good configurations?

  • Is one accountable roadmap connecting cyber risk, equipment upgrades, vendors, funding, and operational ownership?


A “no” or “not sure” does not automatically require a major technology purchase. EPA has emphasized that many meaningful improvements involve procedural and architectural changes rather than expensive hardware and software replacements.[1]

What matters is turning the answer into a sequenced plan.


From Cyber Warnings to an Executable SCADA Roadmap

The latest incidents do not mean every water utility faces an imminent catastrophe. They do mean the threshold for responsible modernization has changed.


Modern SCADA must help utilities trust operational information, control remote access, detect unauthorized changes, contain compromised systems, maintain service during disruption, and recover safely. Achieving that standard requires a roadmap that reflects the utility’s actual operating environment rather than a generic cybersecurity checklist.


Tamazari helps utilities move from awareness to execution. In the past, we supported the modernization of a regional water environment spanning 12 drinking water plants and eight wastewater facilities. The project centralized monitoring across 20 sites, audited and standardized more than 4,800 data points, improved alarm response, automated regulatory reporting, and strengthened remote-site connectivity.[9]


Learn more about Tamazari’s SCADA Modernization Services and recent projects.


Sources

[1] U.S. EPA, FBI, CISA, NSA, and federal partners, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure,” originally published April 7, 2026, and updated July 22, 2026.

[2] Minnesota IT Services, “MNIT Activates Statewide Cybersecurity Response,” July 28, 2026; FBI and EPA, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers,” July 30, 2026; CISA, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” July 30, 2026.

[3] CISA and U.S. EPA, “Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems,” December 13, 2024.

[4] National Institute of Standards and Technology, “Cybersecurity for the Water and Wastewater Sector: Build Architecture,” NIST SP 1800-45, June 2026.

[5] U.S. EPA Office of Inspector General, “Cybersecurity Concerns Related to Drinking Water Systems,” November 13, 2024.

[6] WaterISAC, “CISA ICS Advisories, Additional Alerts, Updates, and Bulletins,” June 4, 2026.

[7] U.S. EPA, “EPA 2026 National Cyber Drill,” July 8, 2026.

[8] U.S. Senate Committee on Environment and Public Works, “Identifying and Addressing Cybersecurity Challenges to Protect America’s Water Infrastructure,” February 4, 2026; U.S. Government Accountability Office, “Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector,” May 21, 2026.


 
 

Get in Touch

Your Energy Transformation Partner

Subscribe to our newsletter

832-862-5616

  • LinkedIn

Thanks for submitting!

bottom of page