Critical Infrastructure Cybersecurity: What Water Utility Attacks Reveal About Operational Resilience
- JV
- 2 days ago
- 7 min read
In brief: Recent attacks on water utilities highlight that cybersecurity for critical infrastructure is an operational leadership issue. When digital controls fail or become unreliable, organizations must sustain essential services while investigating the incident, coordinating response, and restoring normal operations. The key issue is operational resilience: can staff continue serving customers and communities despite disruptions to normal systems?
Key Takeaways
Cyber incidents can spread from digital systems to physical operations and public services.
Manual capabilities, clear decision authority, and trusted partnerships help safeguard continuity.
Organizations outside the water sector face many of the same cyber-physical dependencies.

What Happened in the Water Utility Cyberattacks?
Since July 27, 2026, water and wastewater utilities in at least seven states have reported cyber incidents to the FBI. Some of the activity has degraded water operations.
According to a joint public service announcement by the FBI and the Environmental Protection Agency (EPA), attackers remotely accessed internet-facing operational technology devices, including certain programmable logic controllers (PLCs).
The actors changed device passwords and internet protocol addresses. Those changes affected some operators' ability to monitor or control connected equipment. Reported operational effects included pressure loss and flooding at certain facilities.
The incidents remain under investigation, and federal authorities have not publicly confirmed who was responsible.
More than 30 community water systems in Minnesota were reportedly targeted.
In Braham, a small rural city roughly 50 miles north of the Twin Cities, the incident briefly affected controls at the city’s well and treatment plant.
The city of Plymouth, a suburb of Minneapolis-St. Paul, experienced a communications disruption that affected water infrastructure. Public reporting indicated that water quality remained unaffected in those communities.
Operators continued to serve their communities, adjusted operating methods as needed, communicated with residents, and worked with government partners to restore normal operations.
What Is Operational Technology Cybersecurity?
Operational technology is the technology that enables physical equipment to operate. It controls real-world systems such as pumps, valves, production lines, elevators, medical equipment, and building systems.
Operational technology cybersecurity protects these systems from disruption, manipulation, or being taken offline.
In a water system, operational technology can help manage water pressure, storage levels, pumps, valves, and treatment processes.
A programmable logic controller, often called a PLC, is a small industrial computer that helps control this equipment. It receives inputs, follows programmed instructions, and directs connected machinery what to do.
The same type of technology is used across many industries.
Manufacturers use it to run production lines. Hospitals rely on it for connected equipment and facility systems. Hotels use it for access control, elevators, environmental systems, reservations, and payments. Entertainment organizations depend on it for venues, ticketing, security, and production.
When operational technology fails, the impact can quickly reach physical operations.

Why Attackers Target Essential Water Systems
Water utilities support a service every community depends on. Even a temporary disruption can create operational pressure, public concern, and urgent demands on leadership.
Attackers understand this pressure. By targeting systems connected to water operations, they may seek attention, leverage, financial gain, or broader disruption.
The value of the target lies in the service's importance.
Water Utility Cyberattack Response: What Was Affected and How Service Continued
Attackers disrupted some of the digital controls used to monitor and operate water infrastructure.
Think of those controls as the system’s dashboard and remote control. The pumps, valves, and storage equipment may still function, but operators may lose some of their normal visibility or ability to manage them remotely.
In Braham, water already stored in the city’s tower continued to supply the community while normal controls were restored. In Plymouth, the water system continued operating during a temporary communications outage.
Keeping water flowing does not make the incident insignificant.
Loss of visibility or control can affect pumps, pressure, storage, and other physical processes. Some reported incidents led to degraded operations.
Service continued because operators had alternative ways to respond. Stored water, manual procedures, experienced staff, and coordination with government partners helped limit the disruption and support recovery.
During an incident like this, operators may need to verify equipment readings, switch to alternative procedures, communicate with residents, preserve evidence, and work with investigators simultaneously.
That is why federal guidance emphasizes manual operating capabilities, backup systems, standby systems, and tested continuity plans.
The lesson is simple: continued service shows the response worked. It does not mean the threat lacked the potential to cause serious disruption.
Why Critical Infrastructure Cybersecurity Matters Beyond Water Utilities
The water utility cyberattacks are specific incidents that carry a much broader leadership lesson.
Over the past two decades, society has moved toward an always-connected model. More systems are digital, equipment is remotely managed, and more operations depend on internet access, cloud platforms, outside vendors, and connected devices.
That connectivity creates speed and efficiency. It also gives attackers more ways to reach systems that support physical operations.
Attackers may seek money, disruption, leverage, attention, or access for a future campaign. In some cases, the motive may remain unclear. Organizations still have to respond quickly, even when the attacker’s objective makes little sense.
Effective cybersecurity for critical infrastructure starts with understanding where digital systems intersect with essential operations.
For a global hospitality organization, this may include room access, reservations, payment systems, elevators, environmental controls, executive communications, and guest services across hundreds of properties.
For a major healthcare network, it may include clinical workflows, connected medical equipment, pharmacy systems, emergency operations, scheduling, facility controls, and patient communications.
For a high-profile consumer brand, it may include production, distribution, customer transactions, corporate offices, intellectual property, public communications, and executive operations.
For a global entertainment or media organization, it may include venues, ticketing, content production, physical security, intellectual property systems, live events, and crowd operations.
For a financial institution or other highly regulated organization, it may include customer access, transaction processing, branch operations, identity systems, sensitive communications, and public confidence.
A cyber incident affecting any of these environments can create several problems at once:
Digital systems may become unavailable.
Physical operations may require alternate procedures.
Technical findings may remain incomplete.
Customers, regulators, or communities may expect answers.
Multiple outside partners may need to coordinate.
Leaders may have to make decisions before certainty arrives.
The executive question is broader than whether the security team can investigate an affected device.
Leaders need to know whether essential work can continue, who can authorize operational changes, how information will be verified, and which trusted partners are ready to respond.

Five Critical Infrastructure Cybersecurity Questions Every Leadership Team Should Answer
The water utility cyberattacks offer a practical lesson for any organization that depends on connected systems.
Leadership teams should be able to answer five simple questions before those systems are disrupted.
1. What could stop working if a digital system fails?
Start with the organization’s essential services.
Which physical operations depend on internet access, remote controls, cloud platforms, connected equipment, or outside vendors?
Leadership should know:
Which service would be affected first
Which systems support physical operations
Which disruption would reach customers, patients, guests, or the public
The goal is to understand how a digital problem could become an operational problem.
2. Can we continue to operate without that system?
A backup plan only helps when people can actually use it.
Teams may need to operate equipment manually, move work to another location, use alternate communication channels, or follow temporary procedures.
Leadership should ask:
Can essential work continue?
How long can alternate operations last?
Have employees practiced the plan?
Can the right people access it outside normal business hours?
Continued service during an attack often results from preparation, experienced personnel, and workable alternatives.
3. Who can make emergency decisions?
Cyber incidents may require rapid changes to normal operations.
Someone may need to isolate a system, disable remote access, move equipment to manual control, close part of a facility, or communicate with customers and public officials.
Leadership should know:
Who can authorize those actions;
Who coordinates technical and operational teams;
Who briefs executives and the board; and
Who approves public communications.
Clear authority reduces confusion when time and information are limited.
4. How will we know which information is accurate?
During an incident, different teams may receive different information.
A digital system may show one result. An employee may observe something else. A vendor may still be reviewing logs. Investigators may need more time to determine the full scope.
Leadership should establish:
Who confirms technical findings;
Who verifies operational impact;
Who records important decisions; and
Who approves internal and external updates.
Accurate information helps leaders protect operations, credibility, and public trust.
5. Who is ready to help us immediately?
Outside partners should be identified before an active incident.
That may include cyber incident responders, operational technology specialists, outside counsel, communications advisors, insurers, equipment providers, regulators, and government agencies.
Leadership should ask:
Are the right partners already approved?
Can they access the systems and information they will need?
Are contracts and contact details current?
Can they begin working without procurement delays?
Prepared relationships allow the organization to focus on the response instead of searching for help during the crisis.
The answers may involve technology, operations, legal obligations, communications, and public safety. Together, they reveal whether an organization is prepared to keep serving people when normal digital systems become unavailable or unreliable.
Preparing Before Digital Risk Becomes Operational Risk
Organizations should know whether decision authority is clear, alternate operations have been practiced, and outside partners can respond promptly.
Fortalice helps leadership teams test those conditions through executive tabletop exercises, incident response planning, operational readiness assessments, and Incident Commander support.
The purpose is straightforward: to help people protect operations, public confidence, and organizational trust when normal systems become uncertain.
Preparation cannot eliminate every threat.
It can provide leaders and responders with the structure they need to maintain continuity when an incident enters the physical world.

About Fortalice Solutions
Fortalice is a cybersecurity firm specializing in cyber incident response, cyber risk management, and cybersecurity for executives, chosen by leaders who need elite, discreet support when cyber incidents threaten operations, reputation, and leadership credibility.
Founded by former White House CIO Theresa Payton, who served in a position defined by trust, discretion, and decision-making at the highest levels, Fortalice brings national-level experience and seasoned judgment to high-pressure, time-sensitive situations where decisions cannot wait and mistakes are costly.
The firm integrates cyber advisory, cyber incident response, technical testing, executive digital protection, and training into a unified approach shaped by real-world incidents and human decision-making, delivering clear, actionable guidance trusted by both executive leadership and security teams.
Connect with Fortalice to ensure trusted, discreet expertise is in place before, during, and after a cyber incident.


