Water Utilities Face Rising Cyberattacks as Old Equipment Remains Exposed
Water treatment systems across the United States were built for durability, not for today's connected world. As cyberattacks on the water sector increased this summer, industry officials say old operational technology (OT) and programmable logic controllers (PLCs), many still accessible from the internet, remain some of the easiest ways for attackers to break in.
Tom Dobbins, executive director of the Water Information Sharing and Analysis Center (WaterISAC), said the sector's biggest weaknesses include exposed OT, vulnerable PLCs, insecure connections through third party integrators, and poor cyber hygiene at smaller utilities. He noted that threat activity has increased alongside global conflicts involving the US, with concerns about state-linked actors from Iran, China, and Russia.
To help address these gaps, WaterISAC is partnering with threat intelligence company Cyware to speed up information sharing across the sector, building on an existing partnership with the National Rural Water Association that supports 20,000 of the smallest water utilities. Dobbins said many older PLCs were designed for a 'simpler, gentler time' and were never meant to face internet-based threats, making them a common entry point for attackers this summer.