惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Fortinet All Blogs

FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations | Fortinet Blog The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective From Awareness to Action: Building A Behavior-Based Security Program | Fortinet Blog Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog Fortinet Achieves IEC 62443-4-2 Security Level 4 Certification for FortiOS 7.6 | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog While External Threats Are Driving Security Awareness, Internal Risks Are Growing | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog The AI Era Needs a New SASE. Here’s What That Actually Looks Like. | Fortinet Blog
Defending Critical Infrastructure in the Age of Internet-...
Pat Vitalone · 2026-09-01 · via Fortinet All Blogs

The recent cyberattacks on American water and wastewater critical infrastructure systems underscore an important distinction in operational technology (OT) cybersecurity: Impact cannot be measured solely by records lost or systems encrypted, as in a typical ransomware attack. Programmable logic controllers (PLCs), human-machine interfaces (HMIs), pumps, valves, and treatment systems control the physical processes communities rely on daily for safe drinking water and wastewater treatment. When those processes are disrupted by a cyberattack, the impact can quickly extend to public health, environmental safety, economic activity, and community resilience.

Water infrastructure relies heavily on trust. Communities trust that their water is safe; operators trust that HMIs accurately represent physical processes; and utilities trust that remote connections to plants, pump stations, lift stations, and other field assets are secure. Cyberattacks threaten this trust by damaging confidence in system availability, accuracy, integrity, and safety.

One of the main challenges is structural. Utilities often operate in geographically distributed environments, combining treatment facilities, legacy controllers, pump and lift stations, wells, tanks, cellular field sites, and third-party or OEM remote access. While connectivity offers significant operational value, it also introduces pathways that must be understood and managed. Remote connections accumulate, temporary access can become permanent, third-party connections become trusted by default, and legacy systems can remain accessible well after the initial design has changed. In the field, there can be a noticeable difference between the documented architecture and what is actually installed, configured, and working.

The potential issues are substantial. In 2026, the U.S. Environmental Protection Agency reported resolving vulnerabilities at 277 water systems, building on the 350 vulnerabilities addressed in 2025. These numbers highlight that the challenge is both real and ongoing. Today, vulnerabilities related to exposure, authentication, and access control remain common in operational environments.

From Opportunistic Access to Operational Effects

Recent government advisories highlight a common trend: Attackers often do not need advanced OT malware when operational pathways are already vulnerable. In 2023, and again in a broader 2024 advisory, U.S., U.K., and allied agencies reported that an APT group linked to the Iranian Government’s Islamic Revolutionary Guard Corps compromised internet-connected PLCs by exploiting default or missing passwords. Investigators documented more than 75 affected U.S. devices, including 34 in the water and wastewater sectors, and noted changes to ladder logic and actions that prevented operators from remotely accessing systems.

A 2025 joint advisory warned that pro-Russia hacktivists were exploiting minimally protected, internet-facing VNC connections to access HMIs in water, energy, and food infrastructure. While these were not always sophisticated intrusions, operational disruption and physical damage still occurred.

The risk has continued to escalate. A 2026 multi-agency advisory reports Iranian-affiliated targeting of internet-facing PLCs. Actors accessed cellular modems, exfiltrated project files, and manipulated PLC logic and HMI/SCADA data, including alarm functions and safe shutdown.

In August, legislation was introduced that would expand the Environmental Protection Agency’s (EPA) cybersecurity authority over drinking water and wastewater systems following a series of cyberattacks against U.S. water utilities.

The Water Cyber Shield Act would authorize the EPA to conduct cybersecurity assessments of public water systems and require corrective actions when significant vulnerabilities are identified. The lawmakers said that while the EPA serves as the federal Sector Risk Management Agency for the water sector, it currently lacks many of the authorities needed to oversee cybersecurity.

Fortinet Head of Cyber Policy and global field CISO Jim Richberg said, “The ongoing targeting and successful exploitation of water systems is shining a light on a long-standing problem in the security of the small water/wastewater utilities that comprise 81% of all US public water systems. Theses utilities account for 93% of violations for noncompliance with federal drinking water standards.”

Richberg continued: “Setting requirements is part of the answer, but it needs to be matched with providing resources, which can be ‘parachuted’ in from the state or federal level but ultimately need to be built into utility rates [often set and approved by someone other than the utility] to be sustainable. There are volunteers pitching in to help the sector such as DEF CON Franklin. Many small utilities lack the expertise to address the problem on their own, so they need to rely on external expertise, both paid and pro bono.”

Then on August 19, 2026, the NSA and its partners issued a warning about an active threat to additional PLCs. Malicious actors are employing internet-scanning tools and AI-powered scripts, disguised as legitimate monitoring tools, to identify exposed or poorly segmented controllers. The agencies assess this activity as reconnaissance and capability development that could enable future cyber operations. The gap between the ease of attacking OT and the growing attack surface of organizations is narrowing rapidly. This trend is especially significant because AI and automation are lowering the technical skills needed to identify and exploit exposed industrial systems.

A Private Network Is Not Automatically a Protected Network

Cellular connectivity is indispensable for remote utility sites where fiber is impractical. The issue isn’t with cellular technology itself but with the trust model associated with it. Water utilities often manage numerous remote locations, such as pump stations, lift stations, wells, tanks, and telemetry sites, spread over large areas. Cellular is usually the most practical connection method for these sites. Interestingly, the most vulnerable part of this setup is probably not inside the treatment plant but rather an unmanned cabinet located miles away, which relies on a persistent, trusted connection back to the operational network.

The 2026 advisory from the NSA and other co-signing agencies recommends using isolated architectures like private Access Point Names (APNs), cellular SD-WAN, ZTNA, and site-to-site VPNs. While a private APN can offer useful separation, it doesn't establish a complete security boundary. Connections still need authentication, encryption, segmentation, policy enforcement, inspection, logging, and monitoring relevant to the operational systems they access. Highlighting the global nature of this issue, the U.K. NCSC warns that an APN provides separation but not encryption within the telecommunications network.

The NCSC’s Secure Connectivity Principles for OT reinforce the architectural goal: eliminate exposure of inbound ports, use controlled gateways to manage necessary access, centralize connections, reduce the consequences of a security breach, and ensure logging and activity monitoring. Its recent water-sector example illustrates how these principles can be implemented in a practical, distributed utility environment.

Building Resilience with the Fortinet OT Security Platform

Water utilities do not need another collection of disconnected cybersecurity products. They need an architecture that can consistently apply security from the treatment plant to the remote operational edge without creating additional complexity for already resource-constrained teams.

The Fortinet OT Security Platform unifies networking and security so that segmentation, secure connectivity, controlled remote access, OT-aware protection, vulnerability mitigation, and centralized management can operate as part of a common architecture.

For resource-constrained critical infrastructure, simplicity acts as a security measure, and consistency enhances resilience. FortiGate firewalls and rugged Fortinet solutions can establish OT zones, DMZs, and secure boundaries across treatment plants and remote locations. OT-aware application control, intrusion prevention, and virtual patching help protect vulnerable devices when immediate patching or replacement is operationally impractical. FortiExtender 5G gateways, Secure SD-WAN, and encrypted tunnels ensure secure cellular connectivity. Meanwhile, ZTNA, multifactor authentication, and privileged-access controls restrict maintainers to approved systems and services.

FortiNAC provides asset visibility and access control, complemented by centralized management, analytics, and OT-aware monitoring. These features assist teams in detecting unexpected connections, protocol activity, and configuration changes. Additionally, integration with the Fortinet OT Security Platform enables resource-constrained utilities to implement consistent policies across sites without establishing isolated security silos.

Fortinet is the only cybersecurity provider offering a comprehensive OT security portfolio that is certified to IEC 62443-4-2, the globally accepted standard for component-level security in industrial automation and control systems. As highlighted in Fortinet’s announcement, this certification verifies that Fortinet’s OT solutions have undergone independent evaluation against strict standards for secure development, secure-by-design architecture, and resilience in industrial settings.

This distinction matters in practice. IEC 62443-4-2 certification is not a marketing label. It is a third-party validation of how deeply security is engineered into the product. In contrast, many solutions on the market rely heavily on perimeter controls or bolt-on capabilities that have not been evaluated to the same component-level security standard. For utilities, that difference directly affects how confidently they can secure both legacy and modern OT environments within a unified, standards-based framework.

Technology alone cannot replace tested backups, engineering change control, or practiced recovery procedures. However, it can reduce exposure, restrict access to critical controllers, detect unauthorized behavior, and contain compromise before a localized incident escalates into a broader operational event. The objective is not to prevent every intrusion. It is to preserve the ability to operate safely even when prevention fails.

Take the Next Step in Securing OT Environments

To better understand how these threats are evolving, and how utilities can prepare, download the Fortinet 2026 State of Operational Technology and Cybersecurity Report for the latest research, trends, and guidance shaping industrial cybersecurity.

You can also explore how Fortinet is helping organizations strengthen resilience across critical infrastructure by visiting Fortinet’s Safeguarding OT resource center.

The question is no longer simply, “Is this PLC connected to the internet?” Operators should ask:

  • What digital pathways can reach the physical process?
  • Who and what are trusted along those pathways? What communications and commands should be permitted?
  • If one security layer fails, can the organization contain the impact and continue operating safely?

For U.S. and global critical infrastructure, true cyber resilience means securing every path to the process, validating every point of trust, and ensuring essential services continue when prevention fails.