ProjectX: Prince William Water SCADA Modernization
July 28, 2026
ProjectX: Prince William Water SCADA Modernization
July 28, 2026
EXPERT INSIGHTS

What the Minnesota Water Cyberattacks Mean for Every Utility

 
 
ScottC.Speaking
SCOTT CHRISTENSEN, GrayMatter Cyber Practice Director

By Scott Christensen

Apparent cyber attacks targeted more than 30 community water systems in Minnesota. The incidents have disrupted automated controls and communications. Operators fell back to manual procedures and kept essential services running.

The coordinated cyberattacks across Minnesota on July 26–27, 2026, offer a lesson for water and wastewater leaders: OT cyber resilience is not measured only by whether an attacker gets in.

It is measured by how safely and quickly the utility can continue operating when automation, visibility or remote control is lost.

What Happened and Why It Matters

Minnesota officials described a coordinated cyberattack targeting technology at more than 30 community water systems. Braham, Plymouth, South St. Paul and Maple Plain publicly reported impacts ranging from a temporary plant outage to communications failures and affected automated controls. Operators used manual or contingency procedures, and officials reported no known impact to drinking water quality.

The incidents also arrived amid broader federal warnings. On July 30, CISA urged water and wastewater organizations to remove publicly exposed PLCs and other OT from the internet. The FBI and EPA reported similar incidents in at least seven states since July 27, including cases that degraded water operations.

Why Water Utilities Face Outsized Risk

Water and wastewater operations combine essential public services with distributed assets, aging equipment, third-party connectivity and constrained cybersecurity resources. That creates an attractive attack surface: internet-exposed controllers, undocumented cellular connections, remote-access pathways and common configurations that may be repeated across multiple sites.

The Minnesota incidents show that attackers do not need to compromise an entire enterprise to create operational consequences. Disrupting a controller, modem or remote interface can be enough to reduce visibility, interrupt automated control and force operators into manual mode.

The Defining Lesson: Resilience Is an Operational Capability

The strongest takeaway is not simply “disconnect exposed devices.” It is that resilient utilities prepare for degraded operations before an incident. They know what is connected, understand critical dependencies, maintain clean backups, establish secure access paths and rehearse how to operate safely when normal automation is unavailable.

That preparation is what separates a disruptive cyber incident from a prolonged operational crisis.

Four Priorities for Utility Leaders

Federal guidance and the lessons from Minnesota point to four immediate priorities:

  • Reduce exposure. Remove PLCs and other OT devices from direct internet access, including undocumented cellular connections.
  • Control remote access. Use secure gateways or VPNs, strong unique credentials, multi-factor authentication where supported and allowlisted communications.
  • Improve visibility and recovery. Maintain an accurate OT asset inventory, monitor critical communications and preserve known-clean controller backups.
  • Prepare to operate safely. Validate manual procedures, escalation paths and cross-functional incident response before they are needed.

What You Can Do in the Next 30 Days

Meaningful risk reduction does not have to wait for a multiyear transformation. Start with six focused actions:

  1. Identify every externally connected PLC, modem, gateway and remote-access path.
  2. Remove direct internet exposure and review firewall and allowlist rules.
  3. Change default or shared credentials and secure privileged access.
  4. Validate known-clean backups and restoration procedures.
  5. Exercise manual operating procedures for priority processes.
  6. Confirm internal, vendor and government incident-response contacts.

Build the Program Beyond the First 30 Days

Durable OT resilience requires connected capabilities. The roadmap should include comprehensive OT asset inventory, passive monitoring, risk-based segmentation, secure remote access, OT vulnerability management, tested recovery procedures, regular exercises and governance aligned with NIST CSF 2.0 and ISA/IEC 62443.

The goal is reliable, safe operation under adverse conditions with operations, engineering, IT, security and leadership working from the same plan.

Join the Webinar: From Minnesota’s Warning to Your Resilience Plan

In this webinar at 4 p.m. ET on Aug. 3 available on GrayMatter's LinkedIn page, we will translate the recent attacks and federal guidance into an actionable plan for water and wastewater organizations. We will examine the pathways that create exposure, the controls that matter most and the operational practices that help utilities continue safely when automation is disrupted.

You will learn how to:

  • Find hidden internet exposure across PLCs, cellular modems and vendor connections.
  • Prioritize immediate protections without disrupting operations.
  • Design secure remote access and practical IT/OT segmentation.
  • Validate backups, manual procedures and incident-response readiness.
  • Build a phased resilience roadmap that fits your risk, resources and mission.

Turn the Wake-Up Call Into Action

GrayMatter helps critical infrastructure organizations assess OT exposure, strengthen architecture, secure remote access, improve visibility and build resilience programs aligned with NIST CSF 2.0 and ISA/IEC 62443.

GrayMatter: Thinkers+Doers

 
 
 
 

 

Start a Project

 
 
 
// // //