Explore Elite Risk Management Services

Private Strategic Group

Search

Intelligence Analysis

US Water-System Cyberattacks Expose a Security Gap Across Industries

21 AUG 2026

/

3 min read


Aerial view of metropolitan waterworks authority. Drinking Water Treatment aerial top view

In late July, attackers breached operational technology (OT) at more than 30 municipal water systems across Minnesota, changing controller settings and locking operators out of their own systems. Within days, the FBI confirmed similar incidents at water and wastewater utilities in at least seven other states. The pattern points to a weakness in OT security that reaches well beyond the water sector — and it says as much about business continuity risk as it does about defense. 

Why OT Security Failed Where IT Security Held

Operational technology cybersecurity protects the systems that run physical equipment: pumps, valves, motors, and treatment processes. That is a different job from securing the corporate networks that handle data, and the Minnesota incidents show what happens when it lags behind. Programmable logic controllers, the devices that actually control this equipment, often remain reachable through remote-access pathways that receive far less oversight than a company's core network. Attackers did not need sophisticated custom tools to reach physical processes; common, poorly governed remote-access configurations that many industrial organizations still rely on were enough.

Shared vendor practices make this worse. When several customers configure remote access the same way, a breach at one site can hand attackers a blueprint for the next. That is how one campaign touched dozens of utilities across multiple states without a custom intrusion built for each target. 

Critical Infrastructure Vulnerabilities That Cross Sectors

The same exposure extends into manufacturing, energy, logistics, food production, and commercial facilities — anywhere PLCs and industrial control systems keep physical operations running. And the risk is not confined to direct targets. Companies depend on public water, power, transport, and communications infrastructure, so disruption to a single utility can affect hotel operations, office occupancy, data-center cooling, or site access even when a company's own network stays secure. 

Business Continuity Risk Depends on Preparedness

CISA publicly confirmed that attackers changed passwords and IP addresses and forced some utilities into manual operations. What kept the disruption limited was not a lack of attacker capability, but the fact that affected utilities had stored water, manual controls, available staff, and rapid response plans ready to go. A facility with less spare capacity, fewer staff, or weaker manual procedures could have faced far more severe consequences from the same intrusion.

That distinction reframes business continuity risk for any organization that relies on industrial control systems. The real question is no longer only whether an attacker can be stopped, but how long operations can run manually once one gets through anyway. A practical starting point treats remote-access security as a business-continuity issue as much as a defensive one: map every pathway into OT systems, and test how long operations can run manually before a shutdown becomes necessary. 


The complete strategic outlook contains the intelligence analysis behind these findings, including the sector- and region-specific risk breakdowns, and the complete set of implications and recommended safeguard measures.

Sharpen your 
view of risk

Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.