Protecting Water Infrastructure: Lessons Learned From A Water Utility Cyberattack

Estimated reading time: 5 minutes
Key Takeaways
- Parsons experts discussed the recent cyber attacks targeting community water systems in the United States.
- The attack appeared technically simple but operationally significant, relying on internet-exposed programmable log controllers (PLCs), cellular-connected devices, weak credentials, and vendor access paths.
- Rather than manipulating water quality directly, attackers caused disruption by locking out operators, changing IP addresses, and creating loss of visibility and control.
- The discussion emphasized practical defenses, including removing direct internet exposure, inventorying remote access points, improving logging, strengthening privileged access, and preparing incident response playbooks.
In this discussion, we hear from two of Parsons’ cybersecurity experts, Juan Espinosa, Vice President of Critical Infrastructure Cybersecurity, and Scotty Carlisle, Senior Technical Cybersecurity Leader. They break down the coordinated cyberattack that affected community water utilities in Minnesota and potentially several other states.
How Basic Vulnerabilities Enabled A Large-Scale Water Utility Cyberattack
Juan and Scotty emphasize that the most striking aspect of the incident was not the sophistication of the methods, but the scale. Attackers appear to have taken advantage of exposed PLCs, unmonitored cellular modems, weak passwords, and vendor-installed remote access paths. Instead of deploying advanced custom malware, they disrupted systems by changing passwords, modifying IP addresses, and denying operators visibility into their networks.
This is significant because it demonstrates how basic, preventable security weaknesses can enable large-scale disruption of critical systems. As a result, there can be operational downtime, safety risks, financial losses, and a decline in public trust.
In the water sector, disruptions of this kind can also jeopardize a community’s reliable access to clean water. This highlights the direct impact these incidents have on essential services.
Their conversation also explores why these weaknesses are common in the water sector. Small and remote utilities often depend on cellular connectivity for pumping stations and other distributed assets. This happens because private infrastructure is too expensive. In many cases, convenience can leave devices directly accessible from the public internet if secure architecture is not in place. The discussion also highlights the risks posed by third-party remote access devices that utilities may not fully monitor.
Practical Steps To Improve Water Utility Cybersecurity
A key theme throughout the conversation is resilience. Our experts point to the ability to revert to manual operations as one of the most important reasons water services remained safe during the recent water utility cyberattack.
They also share practical recommendations that utilities can implement to strengthen cybersecurity and reduce operational risk, including:
- Eliminating direct internet exposure for critical systems
- Securing remote access pathways and third-party connections
- Improving network baselines, monitoring, and backup strategies
- Defining incident response roles and responsibilities
- Conducting regular tabletop exercises to improve preparedness
Together, these measures can help utilities strengthen operational resilience and better protect critical infrastructure from future cyber threats.
The discussion also explores the growing role of artificial intelligence (AI) in cybersecurity. While AI can help defenders improve vulnerability management, patching, and incident preparedness, it may also enable attackers to identify exposed devices and scale similar campaigns more efficiently. As a result, proactive cybersecurity practices remain essential for protecting critical water infrastructure.
Episode Breakdown
- Incident Overview (11:23-13:17) – The discussion begins with an overview of the recent attack on Minnesota water systems. The speakers explain that more than 30 community water systems were targeted. In addition, the campaign may extend across multiple states.
- Why This Attack Matters (13:19-15:20) – Juan and Scotty explain that the attack was relatively low in technical sophistication but highly concerning because of its scale and coordination. Attackers reportedly leveraged weak credentials and internet-exposed PLCs rather than specialized malware. This demonstrates how basic vulnerabilities can be exploited across numerous facilities simultaneously.
- Operational Impact On Utilities (15:20-17:23) – This section focuses on the real-world consequences of the incident. While there was no indication that water quality was directly compromised, the loss of visibility and remote control created significant operational disruption.
- Why PLCs End Up Exposed (17:31-23:30) – Our experts explain why remote connectivity is common in water operations. Cellular modems are frequently used to monitor remote pumping stations and field assets because dedicated infrastructure is costly. They also discuss how PLCs may remain in remote mode after maintenance activities. This creates avoidable exposure when secure settings are not restored.
- Practical Defensive Steps (23:47-29:12) – The conversation shifts to actions utilities can take immediately to strengthen cybersecurity and improve resilience. Recommended defensive measures are discussed throughout this portion of the webinar.
- Incident Response Priorities (29:53-36:04) – The speakers outline the critical first steps utilities should take if they suspect PLC tampering or operator lockout. The priority is maintaining safe operations by switching to manual or local control. Then, it is important to contain network access to prevent further intrusion.
- AI And Future Risk (40:10-45:15) – The discussion concludes with a look at AI’s evolving role in cybersecurity. Juan and Scotty note that AI can help defenders improve vulnerability management, patching, and tabletop planning. However, it can also enable attackers to discover exposed devices more quickly and scale attacks against critical systems.
Contact Us To Learn More
Interested in exploring our critical infrastructure protection and water utility services? Contact us today to learn how we can help your utility strengthen operational resilience and protect your critical infrastructure from future cyber threats.