The cyber event already crossed into operational consequence
Minnesota IT Services reported that a coordinated cyberattack targeted operational technology at more than 30 community water systems on 26 and 27 July 2026. Days later, the FBI and EPA said water and wastewater utilities in at least seven U.S. states had reported incidents, with some activity degrading operations.
The mechanism matters. FBI/EPA described remote access to internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, followed in some cases by changes to device configuration, IP addresses and passwords. Those changes caused loss of monitoring and control functionality. At least one organisation reported modified PLC project files after detecting ladder-logic discrepancies across several sites.
The effects were not confined to screens. The FBI/EPA notice lists loss of pressure and flooding among reported operational impacts, and notes that consequences depended partly on whether utilities could switch to manual operation. That moves the problem beyond detection quality. It becomes a question of whether the organisation can turn a cyber signal into a safe process decision fast enough.
The control chain is not complete when monitoring generates an alert. Protection appears only when independent process evidence, clear authority and a rehearsed degraded-mode action converge.
Can the team verify process state independently and execute a rehearsed safe action before control uncertainty grows?
The missing control is often the handoff
Consider the alert arriving at 02:00: an unexpected PLC write, no obvious process deviation and a tank level that still looks normal. The operator understands pumps, pressure and chemical dosing. They should not need to become a malware analyst before deciding whether the process can remain under remote control.
This is where a technically capable monitoring stack can still fail operationally. A playbook may say to isolate remote access, compare PLC logic or move a process to local control. But under pressure, an unpractised instruction competes with years of operating habit, production or service continuity concerns, and uncertainty about who owns the final decision.
The useful interface is therefore deliberately simple: what to isolate, what to verify physically, when to move to local or manual control, which limits must never be crossed, and who must be called. Specialist MDR, integrators or external OT responders can perform deeper cyber analysis. The plant operator needs a safe operating decision.
Simulation belongs in the control design
EPA's 2026 National Cyber Drill tested exactly the kind of degraded environment that makes these handoffs difficult: unreliable or unavailable telecommunications and internet access, with limited or no remote SCADA connectivity. EPA's cyber planning material also emphasises preparation, response, recovery and the ability to transition to manual operations.
That makes joint cyber-physical simulation more than awareness training. Teams should rehearse cases where the HMI disagrees with an independent instrument, a PLC remains online after its logic changes, or a cyber alert arrives before any visible process deviation. The purpose is not to predict the exact next attack. It is to make authority, evidence and degraded-mode behaviour familiar before they are needed.
NIST SP 800-82 Rev. 3 reinforces the engineering context: OT security has to preserve performance, reliability and safety while security controls are applied. WaterISAC similarly recommends reducing control-system exposure, maintaining independent cyber-physical safeguards, monitoring for threats and preparing incident and emergency response. Those controls only become a system when the handoffs between them are tested.
- Define which physical indicators can independently validate critical HMI or PLC state.
- Pre-agree the conditions for isolating remote access or moving a process to local/manual control.
- Give operators a bounded decision path rather than requiring them to diagnose malware.
- Exercise scenarios where cyber evidence arrives before process deviation is visible.
- Test who owns escalation, specialist support and residual operational risk outside normal working hours.
Sources & further reading
- GOVERNMENT RECORDFBI / EPA · Malicious cyber actors targeting water and wastewater sector internet-facing PLCs↗
- GOVERNMENT RECORDMinnesota IT Services · Coordinated cyberattack against community water systems↗
- GOVERNMENT RECORDEPA · 2026 National Cyber Drill↗
- STANDARD / GUIDANCENIST · SP 800-82 Rev. 3 — Guide to Operational Technology Security↗
- STANDARD / GUIDANCEWaterISAC · 12 Cybersecurity Fundamentals for Water and Wastewater Utilities↗
