Published Thursday, October 01, 2026 at 11:53 AM PT

BLUF: Recent confirmed cyberattacks against U.S. water and wastewater systems (WWS) are targeting operational technology (OT) infrastructure, specifically Programmable Logic Controllers (PLCs). CISA and NIST have issued urgent guidance. All water utilities and system operators must immediately audit OT network isolation and PLC access controls; update SCADA/ICS firmware and implement network segmentation to restrict unauthorized PLC commands.
DETAILS
• Active attack pattern confirmed: Recent cyberattacks on U.S. water and wastewater sector are documented; CISA has issued specific warnings about activity targeting PLCs in operational environments.
• OT systems in scope: Attacks focus on operational technology (not IT), particularly building automation and control systems (BACS) and industrial control systems (ICS) that depend on continuous connectivity—creating tension between operational availability and security isolation.
• NIST guidance issued: NIST Cybersecurity Blog published “Securing Water and Wastewater Operational Technology Environments” and has released updated IoT and OT security guidance; NIST also revised guidance on Building Automation & Control System Cybersecurity (latest iteration).
• Federal response underway: Project Watershed 250 (U.S. government initiative) launched to address water system vulnerabilities using AI-assisted tools and red-team exercises; SLCGP (State Loan Credit Grant Program) and liability protections available to operators.
• Scope uncertain but significant: Material indicates “escalating threat to critical infrastructure” but specific incident count, geographic distribution, and attack vector details are not fully detailed in available advisories.
IMPACT
Affected organizations: All U.S. water and wastewater utilities operating connected SCADA, ICS, or building control systems. Smaller utilities with legacy or minimally monitored OT are at elevated risk due to limited detection and isolation capability.
Scope: Critical infrastructure sector — compromise can disrupt water treatment, distribution, or chemical dosing operations, affecting public health and supply continuity.
Threat level: Active exploitation; not theoretical or historical — operators are seeing real-time attack activity.
RECOMMENDED ACTIONS
Immediate (24–48 hrs):
- Audit network topology: confirm OT systems are NOT directly internet-exposed or on shared networks with IT systems.
- Inventory all PLCs, SCADA servers, and HMI (Human-Machine Interface) devices.
- Enable command logging on all control systems.
Short-term (1–2 weeks):
- Apply latest firmware updates to PLCs and SCADA platforms per vendor guidance.
- Implement or strengthen network segmentation (demilitarized zone for any internet-facing monitoring).
- Review and restrict user/service account permissions to PLC write commands.
- Deploy or enable network intrusion detection on OT segments.
Ongoing:
- Enroll in CISA alerts (cisa.gov); monitor NIST updates on OT and IoT security guidance.
- Participate in Project Watershed exercises and vulnerability assessments.
- Establish or update OT incident response playbooks.
SOURCES
- NIST Cybersecurity Blog: “Securing Water and Wastewater Operational Technology Environments”
- CISA Current Activity: Warnings on PLC-targeting activity in water/wastewater sector
- NIST guidance updates on OT and Building Automation & Control System cybersecurity
- Project Watershed 250 (U.S. federal water system security initiative)
Recent high-severity events at publish time:

