Plugging the Leaks: Locking Down Community Water Systems
It’s been an eye-opening summer for US critical infrastructure.
In the space of just two months, cybercriminals (suspected to be, but not confirmed as, Iranian state-sponsored) launched attacks on at least 12 states, including Michigan, Minnesota, Georgia, and South Dakota.
Due to, ahem, “factors,” attacks on critical infrastructure aren’t much of a surprise. What is surprising is that we saw similar attacks, launched by the same groups on the same programmable logic controllers (PLCs) two years ago. So, why hasn’t the water industry closed the gap in that time?
What Happened in this Summer’s Water System Attacks?
Let’s start by looking a little closer at how these attacks played out.
According to the FBI, cybercriminals are targeting publicly exposed Rockwell Automation/Allen Bradley PLCs, specifically MicroLogix 1100 and 1400 series. They then modify passwords to lock out operators and disconnect the PLCs by changing their IP addresses.
Materially, the impacts have been minimal. Experts told the BBC that the biggest threat is not to the water supply itself, but in degrading public confidence in the security of their water.
That said, a recent advisory from CISA reported that activity resulted in boil water notices (a public health advisory telling you to boil your tap water before use) and forced organizations into manual operations, while the Guardian reported low-pressure water flow in people’s homes.
How Bad are Attacks on Water Systems, Really?
Attacks on critical infrastructure, understandably, tend to get people’s hackles up. If you want to bring a country to its knees, that’s what you target.
However, it’s exceedingly difficult to actually poison or gain control over a country’s water supply. Thus far, attacks on US water infrastructure - both in 2024 and 2026 - have done little beyond causing operational nuisance.
Of course, that doesn’t mean we can just ignore water system cybersecurity. In theory, cybercriminals could poison or meaningfully disrupt a water supply, and continued negligence will make the likelihood of that theory playing out in the real world. And that brings us to our next question…
Why Haven’t US Water Systems Closed the Cybersecurity Gap?
Now, we don’t want to victim blame here. While it’s concerning that organizations have failed to address the gaps that caused these attacks, the fault doesn’t entirely fall with the operators themselves. Securing US water systems is an extremely complex task.
There are approximately 50,000 Community Water Systems (CWSs), 91% of which serve small, rural communities of fewer than 10,000 residents. They’re run by a patchwork of city-run, government, and quasi-governmental agencies with no top-down coordination or mandate. Ensuring all of them action CISA or FBI advisories is nigh-on impossible.
By their nature, some CWSs are tiny, managed either by a single person or MSP. There’s a decent chance they won’t see an advisory in the first place and, even if they do, won’t have the budget to act on it - especially if they see early incidents as low impact.
And finally, water infrastructure tends to be pretty old. We’re talking systems as old as 20-40 years. Upgrading that infrastructure often means replacing an entire management system. Again, that’s not something a CWS can easily do on a shoestring budget and with a single-person IT team.
How Can CWSs Protect Themselves on a Tight Budget?
Budget constraints are real, but that’s not an excuse to do nothing.
Implementing just the first five of the CIS Critical Security Controls can prevent or mitigate roughly 85% of cyberattacks. Put simply, you don’t have to spend a ton of money to protect yourself, and beyond those first controls, you get diminishing returns.
The FBI outlines a few simple steps that even the tiniest organizations can take to protect themselves for when these attacks show up again (and they will):
- Change default passwords: Factory-set or guessable credentials are a common entry point for attackers, and changing them costs nothing.
- Restrict access with ACLs: If a PLC doesn’t need to be reachable from outside a small set of trusted IPs, lock it down at the network level.
- Keep key switches in run position: Many Rockwell Automation/Allen Bradley PLCs have a physical switch controlling whether the device accepts remote programming. Leaving it in run/program-lock mode blocks remote logic changes even if an attacker gets network access.
- Confirm manual operating capability: Staff should be able to run critical systems locally if a PLC or its connection goes down.
- Inventory what’s internet-facing: You can’t protect what you don’t know is exposed.
Some of this you can do this afternoon. Others might take a call to your MSP or whoever manages your network. None of it, however, requires a new budget or new hardware.
Overall, though, the best fix is to take exposed PLCs off the public internet entirely. But what if that isn’t possible?
How Can CWSs Hide Unprotected Devices on Their Network?
For a lot of water systems, taking a PLC off the internet isn’t an option. The device might need remote access for a vendor, or the system that would replace it might be years and a budget cycle away. So, what do you do with a device that has to stay reachable?
You hide it.
I recently spoke to an IT Director that had this exact problem. They had a stack of firewalls they couldn’t patch fast enough and needed a way to hide those devices in the meantime.
That’s the whole premise of Network Cloaking. It’s essentially the network security equivalent of the invisibility cloak from Harry Potter. A cloaked PLC is effectively invisible to unauthorized traffic, while remaining reachable to the people who need to reach it.
How Nomic Can Help
The good news is that help is out there, and CWSs don’t need a huge budget to access it.
Nomic Outpost is a managed layer that cloaks internet-facing devices so they’re invisible to the scans and automated probing that led to this summer’s attacks. And it’s backed by a support team that helps small, lean, utilities teams implement changes without hiring more staff.
What’s more, we have proven experience helping small government teams bolster their security without breaking the bank. Just ask the City of Newton, Kansas.
To find out more on the layered approach to network security that underpins everything described here, check out an instant demo of Nomic’s Smart Managed Security Solution.


Ted has worked with network security and web technologies for almost 30 years, beginning his career as a full-stack web engineer and transitioning to network security. He now guides Nomic and its supporting initiatives, including CINS Active Threat Intelligence.


