After Minnesota: A 30-Minute Architecture Fix for Water Utility OT Networks

In July 2026, a coordinated cyberattack targeted more than 30 Minnesota water utilities, disrupting remote monitoring and control and forcing some operators to rely on manual procedures. While the incident centered on water infrastructure, the underlying weaknesses are familiar across OT and IT environments: exposed industrial systems, vulnerable remote-access pathways, legacy infrastructure, and insufficient segmentation.

In this 30-minute webinar replay, BlastWave CEO Tom Sego and UTSI CEO Shaun Six examine how attackers can reach operational environments and what organizations can change at the architecture level to reduce that exposure—without replacing the PLCs, HMIs, SCADA systems, servers, and other infrastructure already in service.

What You’ll Learn

  • How exposed PLCs, HMIs, remote connections, and internet-facing services can create paths into OT environments
  • Why patching, firewalls, VPNs, and monitoring alone may leave important gaps
  • How network cloaking can prevent unauthorized users and scanning tools from discovering protected assets
  • How passwordless secure remote access can remove reusable credentials from the attack path
  • How microsegmentation can restrict lateral movement after an initial compromise
  • How organizations can strengthen legacy environments without disruptive infrastructure replacement

The Architectural Reality

Most organizations cannot simply replace every aging system, eliminate every remote connection, or take critical infrastructure offline whenever a new vulnerability appears. OT teams, IT teams, contractors, vendors, and integrators still need reliable access to systems that may remain in service for years.

That makes the architecture around those systems just as important as the systems themselves.

When assets are discoverable, remote access depends on credentials, and networks allow broad east-west communication, one compromised entry point can create far more exposure than intended. A stronger model reduces what unauthorized users can see, tightly controls who can connect, and limits where any connection can go.

The goal is not to rebuild the entire environment. It is to add modern protections around the infrastructure organizations already depend on.

See How BlastWave Applies Across Your Environment

BlastWave combines network cloaking, passwordless secure remote access, and software-defined microsegmentation to reduce attack paths across OT and IT environments while preserving the connectivity and uptime operations require.

Schedule a personalized demo to see how these controls can protect industrial systems, remote sites, legacy infrastructure, third-party access, and critical network segments without requiring a disruptive redesign.

SCHEDULE A DEMO

About BlastWave

BlastWave makes networks easy to use and hard to hack.

Its platform combines Passwordless Industrial MFA and Software-Defined Microsegmentation to deliver Zero Trust security for complex OT and IT environments — without the cost or complexity of traditional tools.

BlastWave empowers enterprises to protect critical infrastructure, reduce the attack surface, and comply with industrial security standards such as IEC 62443 — all while minimizing downtime and deployment friction.