VYPR
advisoryPublished Jul 31, 2026· 1 source

OTCC Urges CISA to Mandate OT Security Improvements Following Iran-Linked Water Utility Attacks

The Operational Technology Cybersecurity Coalition (OTCC) is calling on CISA to issue a binding directive mandating federal agencies improve their operational technology security after Iran-linked attacks targeted water utilities in Minnesota and at least six other states.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is being urged by the Operational Technology Cybersecurity Coalition (OTCC) to issue a mandatory directive requiring federal agencies to enhance the security of their operational technology (OT) and industrial control systems (ICS). This call to action follows recent cyberattacks attributed to Iran that targeted water utilities in Minnesota and at least six other states, highlighting the escalating threat to critical infrastructure.

The OTCC, a trade association representing OT manufacturers and security companies, stated that CISA should implement a "binding operational directive focused on OT security that places fundamental cybersecurity controls across these systems." This directive would aim to prevent future attacks by ensuring baseline security measures are in place.

According to OTCC Executive Director Tatyana Bolton, the specific controls mandated would vary based on the type of OT network. However, general requirements would include comprehensive asset inventory, continuous network visibility, microsegmentation, and secure remote access protocols. Bolton emphasized that such a directive should apply to thousands of federally owned facilities, including laboratories, hospitals, research campuses, warehouses, and ports of entry, while also signaling the importance of these baseline controls to the broader critical infrastructure community.

The recent attacks, which have been increasingly linked to an Iranian cyber offensive targeting U.S. water utilities, involved actors gaining remote access to internet-facing devices. The attackers then altered IP addresses and passwords, disrupting monitoring and control functionalities. A joint statement from the FBI and EPA recommended that programmable logic controllers (PLCs) be removed from direct internet exposure and accessed only through secure gateways and firewalls.

Sean Tufts, Field CTO at OT security firm Claroty, noted that water systems are particularly attractive targets due to the sector's fragmentation. He pointed out that while Minnesota has fewer than 100 electric utilities, it hosts over 1,000 water systems serving approximately 5 million residents. Despite the disruptions, affected cities reported no impact on water quality, as crews were able to maintain or quickly restore operations using manual or contingency procedures.

Bolton stressed the urgency of the situation, stating, "there is no more time to twiddle our thumbs and play games. We must take action." She also called on Congress to reauthorize the 2015 Cybersecurity Information-Sharing Act, which provides legal protections for critical infrastructure owners and operators sharing incident and threat information. The act is set to expire on September 30th, and a legislative fix is not expected until after the mid-term elections.

The attacks underscore the growing vulnerability of OT systems, which are increasingly connected and targeted by nation-state actors. The OTCC's plea for a CISA directive reflects a broader concern within the cybersecurity community about the need for stronger regulatory oversight and mandatory security standards for critical infrastructure to defend against sophisticated and persistent threats.

Synthesized by Vypr AI