The most concerning finding?
Many attacks are targeting systems that remain directly accessible from the internet.
Over the past few weeks, a series of cyberattacks targeting municipal water systems has put a spotlight on a growing concern: the security of the technology that keeps essential services running. From Minnesota to several other states, water utilities have reported disruptions that forced operators to switch to manual processes to keep systems functioning. While officials say drinking water remained safe, the incidents serve as a reminder that cyberattacks are no longer confined to data theft or ransomware. Increasingly, they are targeting the operational systems that communities rely on every day.
Those incidents align with a broader trend identified by federal cybersecurity agencies. In a joint advisory, the Cybersecurity and Infrastructure Security Agency (CISA), FBI, National Security Agency (NSA), Department of Energy (DOE), Environmental Protection Agency (EPA), and U.S. Cyber Command warned that Iranian-affiliated cyber actors have been actively targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs), across multiple U.S. critical infrastructure sectors. According to the advisory, these attacks have resulted in operational disruptions and financial losses, demonstrating how cyber incidents can quickly move beyond the digital world and affect real-world operations.
According to the advisory, attackers are exploiting internet-exposed systems to gain unauthorized access, alter device configurations, and in some cases lock operators out of critical equipment, causing operational disruptions and financial losses. For organizations that depend on operational technology, the message is clear: cybersecurity is no longer just an IT concern. Protecting operational systems is now a fundamental part of maintaining safe, reliable, and resilient infrastructure.
What Are PLCs and Why Do They Matter?
For most people, PLCs are technology they've never heard of, yet they help power many of the services we depend on every day. Programmable Logic Controllers are specialized industrial computers designed to monitor and control physical processes. They operate water pumps, wastewater treatment systems, manufacturing equipment, electrical generation systems, and countless other components of modern infrastructure.
Most of the time, PLCs work quietly in the background, unnoticed by the public. However, when they are compromised, the consequences can extend far beyond computer networks. According to federal agencies, recent threat activity included the manipulation of PLC project files and the alteration of information displayed on Human Machine Interface (HMI) and SCADA systems. In practical terms, that means operators could be making decisions based on inaccurate or misleading information, increasing the risk of operational disruptions and safety concerns.
A Growing National Security Concern
What makes these attacks particularly concerning is their apparent focus on operational disruption rather than data theft. For years, cybersecurity discussions centered on protecting customer information, financial records, and intellectual property. While those threats remain important, today's threat landscape has evolved.
Nation-state and state-affiliated actors are increasingly targeting the infrastructure that supports daily life, including water systems, energy facilities, transportation networks, and manufacturing operations. Federal agencies have repeatedly warned that foreign adversaries continue to probe poorly secured operational technology environments and internet-connected industrial devices in search of opportunities to create disruption.
In many ways, cyberattacks have become an extension of geopolitical competition. Adversaries can create economic pressure, disrupt public services, and generate uncertainty without engaging in traditional military conflict. As critical infrastructure becomes more connected, the potential impact of these attacks continues to grow.
The Biggest Risk Isn't Always Sophisticated Malware
One of the most important takeaways from the federal advisory is that many successful attacks do not require advanced malware or previously unknown vulnerabilities.
Instead, attackers often succeed because critical systems are exposed directly to the internet or lack basic security controls. Weak passwords, poor remote-access configurations, inadequate network segmentation, and insufficient monitoring frequently create opportunities for threat actors to gain a foothold.
Federal agencies specifically recommend removing PLCs from direct internet exposure whenever possible, placing them behind secure gateways and firewalls, and closely monitoring industrial network traffic for signs of suspicious activity. Organizations that address these fundamentals can significantly reduce their exposure to many of today's most common operational technology threats.
Questions Every Executive Team Should Ask
As cyber threats continue to evolve, cybersecurity can no longer be viewed solely as a technical issue. Leadership teams should have clear visibility into the systems that support their operations and understand the risks associated with them.
Consider the following questions:
- Do we operate industrial control systems or operational technology environments?
- Are any PLCs or OT devices directly accessible from the internet?
- Have we properly segmented operational networks from corporate IT systems?
- Are we monitoring industrial network traffic and security logs?
- Do we have an incident response plan that addresses operational disruptions?
These are no longer questions reserved for IT departments. They are business continuity, operational resilience, and risk management questions that deserve executive-level attention.
The Bottom Line
The recent water system attacks and the latest federal warnings reinforce a simple but important reality: critical infrastructure remains a high-value target for nation-state cyber actors. As operational technology becomes increasingly connected, organizations must recognize that cybersecurity is no longer just about protecting data. It is about protecting the systems that keep businesses operating, communities functioning, and essential services available.
Organizations that take the time to assess their exposure, strengthen security controls, and limit unauthorized access to critical systems today will be far better positioned to withstand the threats of tomorrow.






