Securing Industrial PLCs: How Water Utilities Can Defend Against Targeted OT Attacks
If you've ever watched a pump station hum along on autopilot — flow rates stable, valves cycling on schedule, nobody touching a thing — you know the quiet confidence that comes with a well-tuned OT setup.

The Alert That Should Make Every Plant Engineer Pause
Now imagine that same station going dark, remotely, because someone on the other side of the internet decided your programmable logic controller was an easy target. That scenario isn't hypothetical anymore: the Cybersecurity and Infrastructure Security Agency has issued a direct alert urging the Water and Wastewater Systems sector to secure operational technology against threats specifically targeting PLCs, following coordinated cyberattacks on over 30 water systems in Minnesota in late July 2026.
What This Means When You're Standing Next to the Manifold
On the ground, the conversation around OT security can feel abstract — until you remember that the PLC sitting in your control cabinet is the thing telling your variable-frequency drives when to ramp up, your pressure-reducing valves how to modulate, your chemical dosing pumps what rate to maintain. WaterWorld's recent overview puts it plainly: OT directly interacts with equipment in the physical world. If an OT system fails, pumps stop, tanks overflow, treatment processes get interrupted. The attackers in the Minnesota incidents weren't after customer data — they were after disruption of the physical process itself.
Here's what matters for us: most affected utilities kept running by switching to manual controls. That's both reassuring and instructive. Manual override remains the last line of defense, and if you've ever had to wrestle a stubborn gate valve into position during an unplanned shutdown, you understand why CISA's recommendation to disconnect unnecessary internet-exposed OT devices isn't just a cybersecurity checkbox — it's about keeping that manual fallback from becoming your only option at three in the morning.
The Real-World Checklist
CISA's guidance boils down to a few concrete moves: audit which PLCs, remote terminal units, and SCADA interfaces are actually exposed to the internet, then pull back anything that doesn't need to be there. Strengthen access controls on what remains connected. If your system relies on remote monitoring for pump stations or valve actuators — and increasingly, it does — ask yourself whether every connection point is one you'd defend under pressure. The attack surface has grown because utilities adopted cloud-based analytics, mobile access, and connected sensors for good operational reasons. But each convenience is a doorway, and not all of them are locked.
If you design, install, or service the hardware in these systems — the pumps, the valves, the control panels — this is your reminder that cybersecurity is no longer someone else's department. The PLC managing your proportional pressure-reducing valve doesn't care whether the attacker is a nation-state actor or a bored teenager; it just stops doing what it's told. Build in the manual fallback. Document it. Make sure the operator on the next shift knows where it is and how it feels to use it. That tactile, on-the-ground knowledge might be the thing that keeps water flowing when the network doesn't.