Cyberattacks on utilities are rapidly increasing. The recent takedown of programmable logic controllers (PLCs) at a dozen water and wastewater systems in the U.S. have resulted in boil water notices and forced manual operations.
Because these PLCs are operational technology (OT) and function as the industrial process brains that monitor and operate critical infrastructure, these attacks expose fundamental failures.
System architecture. Hackers are gaining control of utilities’ critical infrastructure by finding PLCs connected to gateways that directly connect to the public Internet with inadequate authentication, segmentation, or hardening. The common culprits are improperly configured cellular modems or VPN-less port forwarding.
In the case of these recent attacks, the identified perpetrators developed a coordinated model that enables affiliated hacktivist groups to replicate similar industrial control system (ICS) exploitation techniques.
That is the broader significance of these types of attacks: the proliferation effect.
Initial assessments indicate the attacker’s likely objective is to modify operational parameters and control logic, disable alarms, and prevent operators from monitoring or controlling the system. These actions could damage equipment, compromise water treatment, and create dangerous working conditions.
For utilities, the lesson is clear: Cybersecurity must be considered during planning, design, integration, and operations. Controls such as network segmentation, secure remote access, and routine architecture reviews can significantly reduce exposure to cyber threats.
These cyberattacks on OT systems often start with an exposed connection. Once inside, attackers may be able to change control logic, disable alarms, disrupt monitoring, or interfere with utility operations. Source: Brown and Caldwell
Prevention is key to protect against threats whether physical or digital.
While the connection between OT systems and enterprise IT, cloud platforms, and the Internet creates genuine operational value (remote monitoring, predictive maintenance, centralized data analytics), it also increases risk.
Organizations pursuing OT/IT integration should treat the connection architecture as a security decision, not an IT task delegated to a vendor. This is because IT and OT each bring their own security assumptions into an environment built on very different principles.
In IT, confidentiality is often the primary goal. In OT, availability comes first. Correct architecture and network design should be at the forefront of system development and deployment. That begins with asking the right question.
Instead of:
Can we connect this system?
Utilities should focus on:
What is the minimum necessary connectivity, and what controls govern every byte that crosses the OT/IT boundary?
This exposure is why cyber-informed design should be built into OT architecture from the start.
Simple gaps, such as an unsegmented network or an unhardened remote access point, are what turned these into real-world attacks.