Water Utility OT Cybersecurity: Who Owns the Control Path?
FBI findings on attacks against internet-exposed water-sector PLCs raise a broader governance issue: utilities need to verify external OT access, current configurations, manual fallback, and third-party-provided network paths.
Water utility OT cybersecurity now extends beyond exposed PLCs. The FBI findings put external access, configuration verification, manual resilience, and third-party network paths into the same governance review.
What you need to know
- The change: Since July 27, utilities in at least seven states have reported incidents involving internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs; some activity degraded water operations. (FBI)
- Who is affected: Water and wastewater operators and the security, engineering, risk, and third-party-management functions responsible for OT connectivity and resilience.
- Why it matters: Attackers changed device IP addresses and enabled and set passwords, resulting in loss of monitoring and control functionality. Reported operational effects included loss of pressure and flooding. (FBI)
- What to do first: Identify PLCs exposed directly to the public internet and move necessary remote access behind connections that are mediated, monitored, and controlled, consistent with FBI/EPA guidance. (FBI)
- Key date or trigger: The FBI and EPA issued the public warning on July 30, 2026, after incidents were reported beginning July 27. (FBI)
Want the full decision layer?
Paid members receive deeper analysis, early-warning signals, and scenario breakdowns on how AI and policy shifts play out in practice.