Prioritize OT Security Investments After Water Utility Cyberattacks

Access this content by contacting one of our representatives for assistance.

Author(s): Bevin Chau

Water and wastewater utilities have become an active target for external threat actors who intend to target critical infrastructure with the potential to cause public unrest. The trend started as early as 2023, and most recently water utilities across 12 states were victims of a coordinated attack exploiting internet-exposed PLCs.

For many utilities, the barrier is incomplete asset inventories and lack of visibility into what assets are within the OT environment and what their level of public internet exposure is. Without knowing what assets are in the environment, utility organizations have no way of effectively managing them and understanding the scope of risk inherent in their system. The purpose of this research is to raise awareness and provide actionable next steps and considerations to combat the vulnerabilities exposed from the recent attacks. Utility leadership must come together to address OT security as an enterprise issue to prevent future attacks from causing harm to the public.