











The recent cyberattacks on American water and wastewater critical infrastructure systems underscore an important distinction in operational technology (OT) cybersecurity: Impact cannot be measured solely by records lost or systems encrypted, as in a typical ransomware attack. Programmable logic controllers (PLCs), human-machine interfaces (HMIs), pumps, valves, and treatment systems control the physical processes communities rely on daily for safe drinking water and wastewater treatment. When those processes are disrupted by a cyberattack, the impact can quickly extend to public health, environmental safety, economic activity, and community resilience.
Water infrastructure relies heavily on trust. Communities trust that their water is safe; operators trust that HMIs accurately represent physical processes; and utilities trust that remote connections to plants, pump stations, lift stations, and other field assets are secure. Cyberattacks threaten this trust by damaging confidence in system availability, accuracy, integrity, and safety.
One of the main challenges is structural. Utilities often operate in geographically distributed environments, combining treatment facilities, legacy controllers, pump and lift stations, wells, tanks, cellular field sites, and third-party or OEM remote access. While connectivity offers significant operational value, it also introduces pathways that must be understood and managed. Remote connections accumulate, temporary access can become permanent, third-party connections become trusted by default, and legacy systems can remain accessible well after the initial design has changed. In the field, there can be a noticeable difference between the documented architecture and what is actually installed, configured, and working.
The potential issues are substantial. In 2026, the U.S. Environmental Protection Agency reported resolving vulnerabilities at 277 water systems, building on the 350 vulnerabilities addressed in 2025. These numbers highlight that the challenge is both real and ongoing. Today, vulnerabilities related to exposure, authentication, and access control remain common in operational environments.
Recent government advisories highlight a common trend: Attackers often do not need advanced OT malware when operational pathways are already vulnerable. In 2023, and again in a broader 2024 advisory, U.S., U.K., and allied agencies reported that an APT group linked to the Iranian Government’s Islamic Revolutionary Guard Corps compromised internet-connected PLCs by exploiting default or missing passwords. Investigators documented more than 75 affected U.S. devices, including 34 in the water and wastewater sectors, and noted changes to ladder logic and actions that prevented operators from remotely accessing systems.
A 2025 joint advisory warned that pro-Russia hacktivists were exploiting minimally protected, internet-facing VNC connections to access HMIs in water, energy, and food infrastructure. While these were not always sophisticated intrusions, operational disruption and physical damage still occurred.
The risk has continued to escalate. A 2026 multi-agency advisory reports Iranian-affiliated targeting of internet-facing PLCs. Actors accessed cellular modems, exfiltrated project files, and manipulated PLC logic and HMI/SCADA data, including alarm functions and safe shutdown.
In August, legislation was introduced that would expand the Environmental Protection Agency’s (EPA) cybersecurity authority over drinking water and wastewater systems following a series of cyberattacks against U.S. water utilities.
The Water Cyber Shield Act would authorize the EPA to conduct cybersecurity assessments of public water systems and require corrective actions when significant vulnerabilities are identified. The lawmakers said that while the EPA serves as the federal Sector Risk Management Agency for the water sector, it currently lacks many of the authorities needed to oversee cybersecurity.
Fortinet Head of Cyber Policy and global field CISO Jim Richberg said, “The ongoing targeting and successful exploitation of water systems is shining a light on a long-standing problem in the security of the small water/wastewater utilities that comprise 81% of all US public water systems. Theses utilities account for 93% of violations for noncompliance with federal drinking water standards.”
Richberg continued: “Setting requirements is part of the answer, but it needs to be matched with providing resources, which can be ‘parachuted’ in from the state or federal level but ultimately need to be built into utility rates [often set and approved by someone other than the utility] to be sustainable. There are volunteers pitching in to help the sector such as DEF CON Franklin. Many small utilities lack the expertise to address the problem on their own, so they need to rely on external expertise, both paid and pro bono.”
Then on August 19, 2026, the NSA and its partners issued a warning about an active threat to additional PLCs. Malicious actors are employing internet-scanning tools and AI-powered scripts, disguised as legitimate monitoring tools, to identify exposed or poorly segmented controllers. The agencies assess this activity as reconnaissance and capability development that could enable future cyber operations. The gap between the ease of attacking OT and the growing attack surface of organizations is narrowing rapidly. This trend is especially significant because AI and automation are lowering the technical skills needed to identify and exploit exposed industrial systems.
Cellular connectivity is indispensable for remote utility sites where fiber is impractical. The issue isn’t with cellular technology itself but with the trust model associated with it. Water utilities often manage numerous remote locations, such as pump stations, lift stations, wells, tanks, and telemetry sites, spread over large areas. Cellular is usually the most practical connection method for these sites. Interestingly, the most vulnerable part of this setup is probably not inside the treatment plant but rather an unmanned cabinet located miles away, which relies on a persistent, trusted connection back to the operational network.
The 2026 advisory from the NSA and other co-signing agencies recommends using isolated architectures like private Access Point Names (APNs), cellular SD-WAN, ZTNA, and site-to-site VPNs. While a private APN can offer useful separation, it doesn't establish a complete security boundary. Connections still need authentication, encryption, segmentation, policy enforcement, inspection, logging, and monitoring relevant to the operational systems they access. Highlighting the global nature of this issue, the U.K. NCSC warns that an APN provides separation but not encryption within the telecommunications network.
The NCSC’s Secure Connectivity Principles for OT reinforce the architectural goal: eliminate exposure of inbound ports, use controlled gateways to manage necessary access, centralize connections, reduce the consequences of a security breach, and ensure logging and activity monitoring. Its recent water-sector example illustrates how these principles can be implemented in a practical, distributed utility environment.
Water utilities do not need another collection of disconnected cybersecurity products. They need an architecture that can consistently apply security from the treatment plant to the remote operational edge without creating additional complexity for already resource-constrained teams.
The Fortinet OT Security Platform unifies networking and security so that segmentation, secure connectivity, controlled remote access, OT-aware protection, vulnerability mitigation, and centralized management can operate as part of a common architecture.
For resource-constrained critical infrastructure, simplicity acts as a security measure, and consistency enhances resilience. FortiGate firewalls and rugged Fortinet solutions can establish OT zones, DMZs, and secure boundaries across treatment plants and remote locations. OT-aware application control, intrusion prevention, and virtual patching help protect vulnerable devices when immediate patching or replacement is operationally impractical. FortiExtender 5G gateways, Secure SD-WAN, and encrypted tunnels ensure secure cellular connectivity. Meanwhile, ZTNA, multifactor authentication, and privileged-access controls restrict maintainers to approved systems and services.
FortiNAC provides asset visibility and access control, complemented by centralized management, analytics, and OT-aware monitoring. These features assist teams in detecting unexpected connections, protocol activity, and configuration changes. Additionally, integration with the Fortinet OT Security Platform enables resource-constrained utilities to implement consistent policies across sites without establishing isolated security silos.
Fortinet is the only cybersecurity provider offering a comprehensive OT security portfolio that is certified to IEC 62443-4-2, the globally accepted standard for component-level security in industrial automation and control systems. As highlighted in Fortinet’s announcement, this certification verifies that Fortinet’s OT solutions have undergone independent evaluation against strict standards for secure development, secure-by-design architecture, and resilience in industrial settings.
This distinction matters in practice. IEC 62443-4-2 certification is not a marketing label. It is a third-party validation of how deeply security is engineered into the product. In contrast, many solutions on the market rely heavily on perimeter controls or bolt-on capabilities that have not been evaluated to the same component-level security standard. For utilities, that difference directly affects how confidently they can secure both legacy and modern OT environments within a unified, standards-based framework.
Technology alone cannot replace tested backups, engineering change control, or practiced recovery procedures. However, it can reduce exposure, restrict access to critical controllers, detect unauthorized behavior, and contain compromise before a localized incident escalates into a broader operational event. The objective is not to prevent every intrusion. It is to preserve the ability to operate safely even when prevention fails.
To better understand how these threats are evolving, and how utilities can prepare, download the Fortinet 2026 State of Operational Technology and Cybersecurity Report for the latest research, trends, and guidance shaping industrial cybersecurity.
You can also explore how Fortinet is helping organizations strengthen resilience across critical infrastructure by visiting Fortinet’s Safeguarding OT resource center.
The question is no longer simply, “Is this PLC connected to the internet?” Operators should ask:
For U.S. and global critical infrastructure, true cyber resilience means securing every path to the process, validating every point of trust, and ensuring essential services continue when prevention fails.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。