<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Why are water utilities increasingly concerned about cybersecurity?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Cyber risk is rising as more water and wastewater systems face attacks against internet-exposed operational technology. In a live WaterISAC poll of 55 attendees, 80% said they were very or extremely concerned about cyber risk today, compared with 52% who said they had that level of concern a year earlier. The poll was self-selected and is not nationally representative, but it shows how quickly concern is increasing among participating operators."
}
},
{
"@type": "Question",
"name": "What is the biggest cybersecurity obstacle for water utilities?",
"acceptedAnswer": {
"@type": "Answer",
"text": "In the WaterISAC poll, 34% of respondents identified budget or funding as their biggest obstacle—more than twice the share of any other response. However, the blog argues that funding is not always the first problem to solve. Utilities can reduce immediate risk by addressing exposed systems and unsafe remote access before beginning large equipment-replacement projects."
}
},
{
"@type": "Question",
"name": "Why are internet-exposed PLCs a major risk for water utilities?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Internet-exposed programmable logic controllers can give attackers a direct path to operational systems. CISA advisory AA26-097A describes exploitation of exposed PLCs, including Rockwell Automation Logix controllers affected by CVE-2021-22681, an authentication-bypass vulnerability rated CVSS 9.8. The blog emphasizes that utilities should first determine whether controllers, including those connected through cellular modems, can be reached from the public internet."
}
},
{
"@type": "Question",
"name": "What cybersecurity improvements are water utilities planning?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Among the 55 WaterISAC poll participants, 37% planned to replace legacy equipment and 37% planned to add monitoring tools within the next 12 months. Other planned measures included firewalls at 35%, multifactor authentication at 33%, and secure remote access that is not exposed to the internet at 22%. Twenty percent reported that they were planning no changes."
}
},
{
"@type": "Question",
"name": "What should a water utility do before replacing legacy equipment?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The blog recommends reducing exposure first. Utilities should identify internet-facing controllers, eliminate unnecessary public access, secure remote connections, separate OT from IT, create offline backups of PLC logic, test restoration procedures, and make sure operators can continue running critical processes manually when necessary."
}
},
{
"@type": "Question",
"name": "How can BlastShield help protect water and wastewater OT environments?",
"acceptedAnswer": {
"@type": "Answer",
"text": "BlastShield is designed to make OT assets invisible and unreachable from the public internet, require passwordless, phishing-resistant authentication before users connect, and segment industrial networks without requiring IP-address changes or operational downtime. The goal is to reduce the attack surface around legacy and difficult-to-patch systems."
}
},
{
"@type": "Question",
"name": "Can smaller water utilities improve OT cybersecurity without an enterprise-sized budget?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Yes. The blog argues that smaller utilities should prioritize controls that reduce immediate exposure rather than waiting for large modernization projects. Some BlastWave water customers are protected through annual subscriptions costing less than $5,000, while free resources from CISA and WaterISAC can also help operators assess and reduce risk."
}
}
]
},
{
"@type": "HowTo",
"name": "How To Reduce Cyber Risk in a Water Utility Before a Major Upgrade",
"description": "A practical sequence for reducing immediate OT cyber risk in water and wastewater environments before undertaking larger modernization or equipment-replacement projects.",
"step": [
{
"@type": "HowToStep",
"position": 1,
"name": "Find every internet-exposed OT asset",
"text": "Identify PLCs, remote-access devices, cellular modems, and other operational technology that can be reached from the public internet. Do not assume that equipment is private simply because it is located inside a plant or remote facility. CISA's free vulnerability-scanning services can help identify exposed systems."
},
{
"@type": "HowToStep",
"position": 2,
"name": "Remove unnecessary public exposure",
"text": "Disconnect controllers and management interfaces from direct internet access wherever possible. The immediate objective is to prevent attackers from discovering and directly reaching OT assets."
},
{
"@type": "HowToStep",
"position": 3,
"name": "Secure remote access before allowing connections",
"text": "Replace exposed remote-access systems and consumer-grade cellular equipment with an authenticated access method that does not leave OT devices publicly reachable. Require users to authenticate before a connection to the protected environment exists."
},
{
"@type": "HowToStep",
"position": 4,
"name": "Use physical controller protections where operations allow",
"text": "For PLCs that include physical operating-mode switches, consider placing them in RUN mode when appropriate for normal operations. This can restrict certain programming changes, although utilities should confirm that the setting is compatible with their operational requirements."
},
{
"@type": "HowToStep",
"position": 5,
"name": "Separate OT from IT networks",
"text": "Create clear boundaries between business systems and operational technology. Segmentation can help prevent an attacker who compromises an IT device or account from moving directly into systems that control pumps, treatment processes, and other physical operations."
},
{
"@type": "HowToStep",
"position": 6,
"name": "Back up PLC logic offline",
"text": "Maintain current offline copies of PLC programs and other critical configurations. A backup is useful only if it can actually be restored, so periodically test the recovery process."
},
{
"@type": "HowToStep",
"position": 7,
"name": "Prepare to operate manually",
"text": "Document and practice manual operating procedures for critical processes. Recent attacks have demonstrated the value of operators being able to disconnect compromised equipment and continue running essential services by hand."
},
{
"@type": "HowToStep",
"position": 8,
"name": "Modernize in the right sequence",
"text": "Legacy-equipment replacement, monitoring platforms, firewalls, MFA, and other investments can all contribute to stronger security. The blog's central recommendation is to close immediate exposure first, then proceed with larger modernization projects from a safer starting point."
}
]
}
]
}
</script>
On Wednesday, I had the privilege of spending an hour with members of WaterISAC, the information-sharing and analysis center for the U.S. water and wastewater sector. Our session was titled "The Advisory Is Correct. Now What?" and I want to thank Chase Snow and the WaterISAC team for trusting us with that hour, and every operator, manager, and engineer who gave up part of their Wednesday to be there.
It was also our first session as a WaterISAC Champion. BlastWave has joined the Champion program, alongside organizations like Claroty and the SANS Institute, and it means a great deal to us. It is not a logo on a web page. It is a commitment to a sector under active attack, mostly defended by people who never signed up to be cyber defenders, much less against “nation-state” adversaries. They signed up to deliver safe water. We signed up to help them accomplish this.
On July 26 and 27, water and wastewater systems around the US were hit in a coordinated attack. Braham lost its computerized controls and recovered manually in about two hours. Plymouth disconnected its cellular equipment and kept running by hand. Drinking water quality was not affected, and no boil-water advisories were issued, which is a credit to operators who knew their plants well enough to run them without the screens. CISA has since said it observed more than 100 internet-exposed water systems hit across at least a dozen states in July alone.
The federal guidance is not ambiguous. CISA advisory AA26-097A, updated July 22, describes attackers exploiting internet-exposed PLCs, including CVE-2021-22681, an authentication bypass in Rockwell Automation Logix controllers rated CVSS 9.8. It is five years old. There is no vendor patch. And, Rockwell is not the only PLC vendor to have such exposure.
We polled attendees live during the session. The results are below.
Three things jumped out at me.
Concern has moved. A year ago, 52 percent said they were very or extremely concerned about cyber risk to their utility. Today it is 80 percent. Out of 55 people, exactly one still called themselves only slightly concerned.
Budget is the wall. Asked for the single biggest obstacle, 34 percent said budget or funding, more than double any other answer.
The plans are big. The most common plans for the next 12 months were replacing legacy equipment (37 percent), adding monitoring tools (37 percent), firewalls (35 percent) and MFA (33 percent). Secure remote access that is not exposed to the internet accounted for 22 percent. And 20 percent have no changes planned.
A fair caveat: this is a live poll of a self-selected room, not a national survey, and I would not extrapolate this to the larger population of water authorities. But the pattern is hard to miss. The most-feared problem is exposure. The most-cited obstacle is money. And the most popular plans are the ones that take the most money and the most time.
Replacing a legacy controller and standing up a monitoring program are both worth doing, and I would never talk a utility out of either. But they run on budget cycles and capital plans. The attackers in Minnesota did not need either of those things. They needed an IP address that answered.
This is not a budget problem first. It is a sequencing problem.
When a hurricane warning goes up on the Gulf Coast, nobody starts a kitchen remodel. You close the shutters, move the car, and fill the bathtub. The remodel can wait until the storm passes. The shutters cannot.
The short-term steps we walked through on Wednesday are shutters. None of them requires ripping out a controller:
The full checklist is in the community advisory we published on August 5. Please pass it along, especially to the small systems that do not have a security team.
BlastShield exists because of that list. It makes OT assets invisible and unreachable from the internet, requires passwordless, phishing-resistant authentication before anyone connects, and segments the network without re-addressing it or scheduling downtime. You cannot hack what you cannot see, and you cannot hack what you cannot reach.
We also learned something from water customers early on: a small system with a handful of lift stations and one SCADA server should not need an enterprise budget, a six-month project, or a security team it does not have. So we scaled and priced BlastShield for water deployments specifically, to be installed and run by the people who run the plant. We have water customers who are fully protected with annual subscriptions under $ 5,000.
Utilities have noticed. Water and wastewater is now the fastest-growing part of our customer base by volume. BlastShield already protects more than 5,000 industrial sites in 22 countries, and a growing share of them treat and deliver water.
If you run a water or wastewater system and you are part of that 80 percent, call me or email me at tom@blastwave.com. That offer does not come with a sales quota attached. We will help you find out what is exposed, walk through the advisory with you, and point you to the free CISA and WaterISAC resources that fit your situation, whether or not BlastShield is part of the answer.
That is what being a Champion means to us. We are in this sector for the long haul.
And if you think I got something wrong on Wednesday, or in this post, tell me. I would rather be argued with than agreed with.
Cyber risk is rising as more water and wastewater systems face attacks against internet-exposed operational technology. In a live WaterISAC poll of 55 attendees, 80% said they were very or extremely concerned about cyber risk today, compared with 52% who said they had that level of concern a year earlier. The poll was self-selected and is not nationally representative, but it shows how quickly concern is increasing among participating operators.
In the WaterISAC poll, 34% of respondents identified budget or funding as their biggest obstacle—more than twice the share of any other response. However, the blog argues that funding is not always the first problem to solve. Utilities can reduce immediate risk by addressing exposed systems and unsafe remote access before beginning large equipment-replacement projects.
Internet-exposed programmable logic controllers can give attackers a direct path to operational systems. CISA advisory AA26-097A describes exploitation of exposed PLCs, including Rockwell Automation Logix controllers affected by CVE-2021-22681, an authentication-bypass vulnerability rated CVSS 9.8. The blog emphasizes that utilities should first determine whether controllers, including those connected through cellular modems, can be reached from the public internet.
Among the 55 WaterISAC poll participants, 37% planned to replace legacy equipment and 37% planned to add monitoring tools within the next 12 months. Other planned measures included firewalls at 35%, multifactor authentication at 33%, and secure remote access that is not exposed to the internet at 22%. Twenty percent reported that they were planning no changes.
The blog recommends reducing exposure first. Utilities should identify internet-facing controllers, eliminate unnecessary public access, secure remote connections, separate OT from IT, create offline backups of PLC logic, test restoration procedures, and make sure operators can continue running critical processes manually when necessary.
BlastShield is designed to make OT assets invisible and unreachable from the public internet, require passwordless, phishing-resistant authentication before users connect, and segment industrial networks without requiring IP-address changes or operational downtime. The goal is to reduce the attack surface around legacy and difficult-to-patch systems.
Yes. The blog argues that smaller utilities should prioritize controls that reduce immediate exposure rather than waiting for large modernization projects. Some BlastWave water customers are protected through annual subscriptions costing less than $5,000, while free resources from CISA and WaterISAC can also help operators assess and reduce risk.
Identify PLCs, remote-access devices, cellular modems, and other operational technology that can be reached from the public internet. Do not assume that equipment is private simply because it is located inside a plant or remote facility. CISA's free vulnerability-scanning services can help identify exposed systems.
Disconnect controllers and management interfaces from direct internet access wherever possible. The immediate objective is to prevent attackers from discovering and directly reaching OT assets.
Replace exposed remote-access systems and consumer-grade cellular equipment with an authenticated access method that does not leave OT devices publicly reachable. Require users to authenticate before a connection to the protected environment exists.
For PLCs that include physical operating-mode switches, consider placing them in RUN mode when appropriate for normal operations. This can restrict certain programming changes, although utilities should confirm that the setting is compatible with their operational requirements.
Create clear boundaries between business systems and operational technology. Segmentation can help prevent an attacker who compromises an IT device or account from moving directly into systems that control pumps, treatment processes, and other physical operations.
Maintain current offline copies of PLC programs and other critical configurations. A backup is useful only if it can actually be restored, so periodically test the recovery process.
Document and practice manual operating procedures for critical processes. Recent attacks have demonstrated the value of operators being able to disconnect compromised equipment and continue running essential services by hand.
Legacy-equipment replacement, monitoring platforms, firewalls, MFA, and other investments can all contribute to stronger security. But the blog's central recommendation is to close immediate exposure first, then proceed with larger modernization projects from a safer starting point.
Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.
