The Federal Bureau of Investigation (FBI) and U.S. Environmental Protection Agency (USEPA) are warning the operators of critical infrastructure, such as water and wastewater utilities, to guard against cyberattacks.
Since July, municipal water and wastewater systems in Minnesota, South Dakota, Wisconsin, Michigan, New York, New Jersey, Georgia, Alabama, Pennsylvania, Washington, and California have reported cybersecurity incidents.
How the Attacks Occurred
After remotely accessing internet-facing devices, some attacks involved changes to IP addresses and passwords resulting in a loss of monitoring and control functionality. Some of the impacted utilities were found to have Supervisory Control and Data Acquisition (SCADA) system architecture that relied on publicly accessible communication paths, including exposed controllers and cellular connections utilizing open ports.
Safeguarding Your Critical Infrastructure
The incidents reinforce the importance of secure industrial control systems, resilient network architectures, and maintaining an experienced response team. To immediately reduce the risk of compromise, the FBI and USEPA recommend the following:
- Remove Programmable Logic Controllers (PLC) from direct internet exposure via secure gateway and firewalls.
- Set up strong, unique passwords.
- Utilize an access control list (ACL) to allow only authorized communication between expected control system devices.
“There are several things water and wastewater systems can do to protect their infrastructure from cyber criminals through security validation and verification,” says Erika Kukaswadia, AE2S I&C Practice Leader. She recommends critical infrastructure entities such as water/wastewater utilities and rural water systems complete the following checklist:
Security Validation & Verification Checklist
- Verify firewall configurations.
- Validate Virtual Private Network (VPN) and other remote-access connectivity.
- Review remote telemetry network operations and validate security protocols are in use, particularly with internet or cellular based deployments.
- Confirm that remote-access pathways are properly secured.
- Review publicly accessible IP addresses for potential exposure.
- Recheck systems using established security-verification procedures.
Key Lessons Learned
Kukaswadia says the recent cyber incidents highlight several important cybersecurity best practices. “Cybersecurity is not a one-time effort. It requires continuous review, validation, and improvement. Layered security remains essential – firewalls, VPNs, network segmentation, controller protections, monitoring, and user awareness all play an important role,” she says. “Thorough review of SCADA communications infrastructure, remote-access methods, and network security controls is important. Routine reviews and cybersecurity assessments provide significant value by helping utilities identify risks before incidents occur.”
The bottom line is strong coordination between operational technology, controls engineering, and information technology teams is essential for protecting critical infrastructure from cyber criminals. Contact AE2S I&C Practice Leader Erika Kukaswadia if you have questions about your SCADA system.

