CISA Warns Water System PLCs Still Exposed Online Amid Multistate Cyberattacks

CISA Warns Water System PLCs Still Exposed Online Amid Multistate Cyberattacks

The persistent vulnerability of water system programmable logic controllers (PLCs) to cyber intrusion has once again taken center stage, as officials from the Cybersecurity and Infrastructure Security Agency (CISA) delivered a sobering assessment at the Black Hat cybersecurity conference in Las Vegas. Despite years of advisories, joint FBI-EPA warnings, and high-profile attacks on municipal water utilities across multiple U.S. states, thousands of PLCs—the compact industrial computers that govern pumps, valves, and chemical dosing systems—remain openly accessible on the public internet, often protected by nothing more than a factory-default password, or no password at all.

A CISA representative, speaking candidly in a brief interview on the sidelines of Black Hat, did not mince words about the state of operational technology (OT) security in America's water sector. "We're seeing things like programmable logic controllers that are open and accessible on the internet with either no password set or default password set," the official said. "We're not making ourselves hardened targets."

šŸ“Š Key Exposure Statistics: Water System PLCs at a Glance

Forescout Research Findings (2025–2026): Over 4,400 programmable logic controllers across U.S. water and wastewater utilities were identified as directly reachable from the public internet.

Authentication Status: A significant percentage of these exposed PLCs were found with either no password configured or the manufacturer's factory-default credentials still active.

Affected Equipment: Controllers from multiple major automation vendors—including Siemens, Rockwell Automation, and Schneider Electric—were among those discovered in exposed configurations.

Geographic Spread: Exposed devices were identified across all regions of the United States, from small rural water districts to suburban municipal systems.

Attack Surface: Each exposed PLC represents a potential entry point for threat actors to manipulate physical processes, including water pressure, chemical treatment levels, and valve operations.

The Convergence of Connectivity and Risk in Industrial Automation

PLCs occupy a foundational role in modern industrial automation. Inside water treatment facilities, these ruggedized microcomputers execute the real-time control logic that keeps pumps running, monitors tank levels, adjusts chemical dosing, and manages filtration cycles. Their reliability and longevity—many units remain in service for 15 to 20 years—make them the workhorses of critical infrastructure worldwide.

Yet the same attributes that make PLCs indispensable also create a widening security gap. Many legacy controllers were designed and deployed long before cybersecurity considerations entered the industrial automation conversation. Internet connectivity, often added retrospectively for remote diagnostics or SCADA integration, has transformed these once-isolated devices into internet-facing assets that adversaries can discover, fingerprint, and exploit with readily available tools.

šŸ” Analyst Insight: The Legacy PLC Security Debt

Industrial automation professionals have long understood that the PLCs commissioned in the 1990s and 2000s were built for uptime, not for cyber resilience. The CISA findings at Black Hat underscore a structural problem: utilities often lack the in-house OT cybersecurity expertise to audit their own attack surfaces. The result is a "security debt" that accumulates silently over decades—until a nation-state actor or ransomware group cashes it in. The 4,400-plus exposed controllers identified by Forescout likely represent only the visible tip of a much larger submerged risk profile.

From Advisory to Action: Why "Set a Password" Remains Unheeded

CISA's immediate guidance to water utilities is almost disarmingly simple: "Get your operational technology off the internet, set a password." The agency has reiterated this advice repeatedly, including in a joint advisory with the FBI and the Environmental Protection Agency (EPA) that followed a spate of attacks on water systems in multiple states. Yet the Black Hat disclosure confirms that basic cyber hygiene remains elusive across significant portions of the sector.

The reasons are multifaceted. Many small and mid-sized water utilities operate with constrained budgets and limited IT staff, often relying on third-party system integrators who configured PLCs years ago and may no longer be under contract. Default credentials persist because changing them requires coordinated downtime, familiarity with proprietary engineering software, and an awareness that the risk exists in the first place—an awareness that, CISA's comments suggest, is still not universal.

šŸ“ˆ Market Trend: OT Cybersecurity Spending Accelerates

The persistent exposure of water system PLCs is driving accelerated investment in OT-specific cybersecurity solutions. Analysts tracking the industrial automation sector note a sharp uptick in demand for network segmentation tools, OT asset discovery platforms, and managed security services tailored to utilities. For system integrators and automation vendors, the CISA disclosures represent both a reputational challenge and a commercial opportunity: customers are increasingly demanding PLCs with embedded security features—secure boot, encrypted firmware, and role-based access control—as baseline specifications rather than optional add-ons.

ā“ Frequently Asked Questions: Water System PLC Security

Why are water system PLCs targeted by hackers?
Water utilities are classified as critical infrastructure. Compromising a PLC allows attackers to manipulate physical processes—altering chemical dosing, disabling pumps, or triggering pressure anomalies—that can endanger public health and safety. These systems are attractive targets for both nation-state actors seeking geopolitical leverage and cybercriminals pursuing ransomware payouts.

What makes a PLC "exposed" online?
A PLC is considered exposed when its management interface—typically communicating via protocols such as Modbus TCP, EtherNet/IP, or proprietary vendor protocols—is directly reachable from the public internet. Attackers can use search engines like Shodan to locate these devices, then attempt authentication using default or commonly known credentials.

How can utilities determine if their PLCs are exposed?
CISA recommends conducting regular OT asset inventories using passive network monitoring tools. Free resources such as CISA's Cyber Hygiene Vulnerability Scanning service can help identify internet-facing industrial devices. Third-party OT security assessments from qualified integrators are also strongly advised.

Is removing PLCs from the internet sufficient protection?
Disconnecting PLCs from direct internet access is the single most impactful immediate step, but it is not a complete security strategy. Utilities should also implement network segmentation, enforce strong unique passwords, apply vendor security patches where available, and deploy OT-specific intrusion detection systems to monitor for lateral movement within operational networks.

Implications for the Industrial Automation Supply Chain

The CISA findings carry implications that ripple well beyond water utilities. For PLC manufacturers, the era of shipping controllers with well-known default credentials and expecting end users to harden them post-installation is drawing to a close. Regulatory pressure—from the EPA's heightened scrutiny of water sector cybersecurity to potential SEC disclosure requirements for critical infrastructure operators—is converging with insurance underwriting trends that increasingly penalize poor OT security postures.

System integrators and automation engineering firms face a parallel reckoning. Contracts for PLC programming and SCADA integration are beginning to include explicit cybersecurity deliverables: documented password policies, network architecture diagrams showing segmentation boundaries, and provisions for post-deployment vulnerability management. For the broader industrial automation community, the Black Hat message from CISA serves as an unambiguous signal that cybersecurity can no longer be treated as a separate discipline from controls engineering—it is now integral to the profession.

šŸ›”ļø Analyst Insight: The Regulatory and Insurance Landscape Is Shifting

The "set a password" guidance from CISA may sound elementary, but its repetition at Black Hat signals growing impatience at the federal level. Water utilities that fail to implement basic controls may soon face not only heightened regulatory enforcement but also exclusion from cyber insurance markets. For industrial automation professionals, the strategic takeaway is clear: PLC procurement specifications, commissioning checklists, and maintenance contracts must now embed cybersecurity requirements as non-negotiable line items. The era of assuming air-gapped security by default is over—and the evidence from Forescout's 4,400 exposed controllers proves it.

The message from Las Vegas is unambiguous. America's water infrastructure—and the PLCs that control it—remains dangerously accessible to adversaries. CISA's call to action is simple, but the path to universal compliance will demand sustained engagement from automation vendors, integrators, regulators, and utility operators alike. Until then, every default-password PLC sitting on the open internet represents a breach waiting to happen.

Related Articles

Tillbaka till blogg