Why is industrial equipment connected to the internet at all?
Because somebody needs to reach it and driving there costs a day. A small utility may be run by a handful of operators covering everything, with an integrator two hundred miles away, and a controller on a cellular modem is how the site gets looked after at all. The exposure is a consequence of a staffing reality rather than of carelessness.
What happened to water utilities in 2026?
Through July, CISA observed malicious activity against more than a hundred internet-exposed systems in the water and wastewater sector, most often programmable logic controllers reachable through a cellular modem. Utilities in at least seven states reported incidents, some of which degraded operations, and a joint alert followed at the end of the month urging owners to take exposed controllers off the internet.
How sophisticated are these attacks?
Mostly they are not. The controller answers on a known port, often with a default or unchanged password, and the attacker logs in and speaks to the process directly — reads the operator screen, changes a setpoint, changes the password, or takes the device offline. There is no exploit in that sequence. There is a search engine and a login form.
Why can't operational systems just be patched?
Because applying a patch means restarting something that is currently doing a job, and the job may be a water treatment stage or a furnace. Maintenance windows are scheduled quarterly or annually, vendor approval is often required to keep a warranty or a safety certification, and some equipment has no update mechanism at all.
What is the difference between IT and OT security?
The ordering of what matters. Office systems put confidentiality first and treat downtime as an acceptable cost of containment; control systems put availability first, because the thing they control is physical and stopping it has consequences a disconnection in an office does not. Nearly every practical disagreement between the two worlds follows from that reversal.
Is disconnecting a compromised system the right response?
In an office, almost always. On a plant, sometimes it is the incident. Isolating a controller mid-process can leave a valve, a heater or a press in an undefined state, which is why response plans in these environments are written with the process engineers rather than handed to them.
How old is the equipment in question?
Frequently older than the security profession's assumptions. Industrial hardware is specified for twenty to thirty years because the plant around it is, so a controller installed when the risk model was a locked door is now on a network. Replacement is a capital project measured in years, not a patch cycle.
Did Colonial Pipeline show that attackers can control physical systems?
No, and the distinction is the useful part. The incident hit business systems, and the operator halted distribution as a precaution — partly because billing was affected. The lesson is that the boundary between office and plant matters far less than organisations assume once the two are connected, which is a different and more common problem than direct manipulation of a process.
What is network segmentation and why does it come up constantly here?
It is the practice of keeping the plant network reachable only through controlled, few and monitored paths, rather than flat with the office. It dominates this subject because it is the one control that does not require touching the fragile equipment: it changes what can reach the controller instead of changing the controller.
Who is actually responsible for securing a small utility?
Often nobody whose job title says so. Most community water systems are small operations without dedicated security staff, where the same people handle treatment, compliance, billing and whatever the integrator left behind. Advice written for organisations with a security function does not survive contact with that reality.
Should a small utility buy specialist OT security products?
Usually not first. The equipment that monitors industrial protocols is genuinely capable and it assumes somebody will read what it produces, which is the resource the operator does not have. Removing internet exposure and arranging remote access properly costs nothing in licences and addresses the pattern behind the recent incidents; specialist monitoring earns its place once there is somebody whose job includes looking at it.
Does the integrator who built the plant still have access?
Almost certainly, because the warranty and the support arrangement depend on it. That concentrates risk in a way an individual operator cannot see: a firm serving fifty sites holds remote access to fifty sites, sometimes through shared credentials. It is worth asking how their engineers reach your equipment, whether the credential is shared, and what they could tell you if they were compromised.
What should an operator do first?
Find out what of theirs answers from the internet, which is a question an outsider can already answer about them. Removing direct exposure and putting remote access behind something that authenticates properly addresses the specific pattern behind the 2026 incidents, and it requires no change to the control equipment itself.
Does safety certification conflict with security updates?
Regularly. Equipment certified for a safety function is certified in a configuration, and changing that configuration can invalidate the certificate until reassessment. The result is a genuine standoff rather than an excuse, and it is resolved by compensating controls around the device rather than by arguing that the certificate should not matter.