Observed versus hypothetical. FBI/EPA and Minnesota reporting support coordinated targeting, PLC/configuration changes, loss of monitoring or control, ladder-logic discrepancies and physical operational effects. The example alert “Unexpected Modbus write from an unknown source” is a deliberately hypothetical operating scenario, not a reported message from the incident.

The cyber event already crossed into operational consequence

Minnesota IT Services reported that a coordinated cyberattack targeted operational technology at more than 30 community water systems on 26 and 27 July 2026. Days later, the FBI and EPA said water and wastewater utilities in at least seven U.S. states had reported incidents, with some activity degrading operations.

The mechanism matters. FBI/EPA described remote access to internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, followed in some cases by changes to device configuration, IP addresses and passwords. Those changes caused loss of monitoring and control functionality. At least one organisation reported modified PLC project files after detecting ladder-logic discrepancies across several sites.

The effects were not confined to screens. The FBI/EPA notice lists loss of pressure and flooding among reported operational impacts, and notes that consequences depended partly on whether utilities could switch to manual operation. That moves the problem beyond detection quality. It becomes a question of whether the organisation can turn a cyber signal into a safe process decision fast enough.

What this diagram shows

The control chain is not complete when monitoring generates an alert. Protection appears only when independent process evidence, clear authority and a rehearsed degraded-mode action converge.

Alert-to-action chainDetection only becomes protection when cyber evidence can drive a safe physical decision
Uncertain / potentially compromised state Independent evidence or governed action
Decision and evidence flow
Cyber signalUnexpected PLC or network changeMonitoring detects behaviour that may precede visible process deviation
Independent evidencePhysical process verificationPressure, level, dosing or local indication is checked outside the suspect view
Operational authorityIsolate, localise or continueThe operator receives a bounded process decision, not an open-ended malware investigation
Continuity stateManual / degraded operationCritical function continues while specialist cyber analysis proceeds
Decision gate

Can the team verify process state independently and execute a rehearsed safe action before control uncertainty grows?

YESThe cyber alert becomes an operational protection mechanism.
NODetection exists, but the decision path remains an untested dependency.
How to read this: the dark node marks the uncertain cyber state. The remaining nodes represent the evidence, authority and degraded-mode controls needed to prevent that uncertainty from dictating the physical process.

The missing control is often the handoff

Consider the alert arriving at 02:00: an unexpected PLC write, no obvious process deviation and a tank level that still looks normal. The operator understands pumps, pressure and chemical dosing. They should not need to become a malware analyst before deciding whether the process can remain under remote control.

This is where a technically capable monitoring stack can still fail operationally. A playbook may say to isolate remote access, compare PLC logic or move a process to local control. But under pressure, an unpractised instruction competes with years of operating habit, production or service continuity concerns, and uncertainty about who owns the final decision.

The useful interface is therefore deliberately simple: what to isolate, what to verify physically, when to move to local or manual control, which limits must never be crossed, and who must be called. Specialist MDR, integrators or external OT responders can perform deeper cyber analysis. The plant operator needs a safe operating decision.

Simulation belongs in the control design

EPA's 2026 National Cyber Drill tested exactly the kind of degraded environment that makes these handoffs difficult: unreliable or unavailable telecommunications and internet access, with limited or no remote SCADA connectivity. EPA's cyber planning material also emphasises preparation, response, recovery and the ability to transition to manual operations.

That makes joint cyber-physical simulation more than awareness training. Teams should rehearse cases where the HMI disagrees with an independent instrument, a PLC remains online after its logic changes, or a cyber alert arrives before any visible process deviation. The purpose is not to predict the exact next attack. It is to make authority, evidence and degraded-mode behaviour familiar before they are needed.

NIST SP 800-82 Rev. 3 reinforces the engineering context: OT security has to preserve performance, reliability and safety while security controls are applied. WaterISAC similarly recommends reducing control-system exposure, maintaining independent cyber-physical safeguards, monitoring for threats and preparing incident and emergency response. Those controls only become a system when the handoffs between them are tested.

In critical infrastructure, an alert becomes protection only when a prepared team can convert it into a safe action before the process forces the decision.
The decision
Treat cyber-physical exercises as an operational control: rehearse the evidence, authority and manual-operation handoffs that turn OT detection into safe process action.
Operational checks
  • Define which physical indicators can independently validate critical HMI or PLC state.
  • Pre-agree the conditions for isolating remote access or moving a process to local/manual control.
  • Give operators a bounded decision path rather than requiring them to diagnose malware.
  • Exercise scenarios where cyber evidence arrives before process deviation is visible.
  • Test who owns escalation, specialist support and residual operational risk outside normal working hours.
Related episodeListen to the companion episodeLinkedInJoin the discussion
Source record

Sources & further reading

5 cited sourcesHow we source →
← All analysisCompanion episode →