VYPR
advisoryPublished Aug 3, 2026· Updated Aug 10, 2026· 5 sources

OTCC Urges CISA to Mandate OT Security Improvements Following Iran-Linked Water Utility Attacks

The Operational Technology Cybersecurity Coalition (OTCC) is calling on CISA to issue a binding directive mandating federal agencies improve their operational technology security after Iran-linked attacks targeted water utilities in Minnesota and at least six other states.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is being urged by the Operational Technology Cybersecurity Coalition (OTCC) to issue a mandatory directive requiring federal agencies to enhance the security of their operational technology (OT) and industrial control systems (ICS). This call to action follows recent cyberattacks attributed to Iran that targeted water utilities in Minnesota and at least six other states, highlighting the escalating threat to critical infrastructure.

The OTCC, a trade association representing OT manufacturers and security companies, stated that CISA should implement a "binding operational directive focused on OT security that places fundamental cybersecurity controls across these systems." This directive would aim to prevent future attacks by ensuring baseline security measures are in place.

According to OTCC Executive Director Tatyana Bolton, the specific controls mandated would vary based on the type of OT network. However, general requirements would include comprehensive asset inventory, continuous network visibility, microsegmentation, and secure remote access protocols. Bolton emphasized that such a directive should apply to thousands of federally owned facilities, including laboratories, hospitals, research campuses, warehouses, and ports of entry, while also signaling the importance of these baseline controls to the broader critical infrastructure community.

The recent attacks, which have been increasingly linked to an Iranian cyber offensive targeting U.S. water utilities, involved actors gaining remote access to internet-facing devices. The attackers then altered IP addresses and passwords, disrupting monitoring and control functionalities. A joint statement from the FBI and EPA recommended that programmable logic controllers (PLCs) be removed from direct internet exposure and accessed only through secure gateways and firewalls.

Sean Tufts, Field CTO at OT security firm Claroty, noted that water systems are particularly attractive targets due to the sector's fragmentation. He pointed out that while Minnesota has fewer than 100 electric utilities, it hosts over 1,000 water systems serving approximately 5 million residents. Despite the disruptions, affected cities reported no impact on water quality, as crews were able to maintain or quickly restore operations using manual or contingency procedures.

Bolton stressed the urgency of the situation, stating, "there is no more time to twiddle our thumbs and play games. We must take action." She also called on Congress to reauthorize the 2015 Cybersecurity Information-Sharing Act, which provides legal protections for critical infrastructure owners and operators sharing incident and threat information. The act is set to expire on September 30th, and a legislative fix is not expected until after the mid-term elections.

The attacks underscore the growing vulnerability of OT systems, which are increasingly connected and targeted by nation-state actors. The OTCC's plea for a CISA directive reflects a broader concern within the cybersecurity community about the need for stronger regulatory oversight and mandatory security standards for critical infrastructure to defend against sophisticated and persistent threats.

The Schneier on Security article adds a layer of political commentary to the ongoing discussion of the Iranian cyberattacks against US water systems. It highlights former President Trump's public dismissal of the attribution, suggesting Minnesota may have "hacked itself," and questions whether this skepticism extends to other targeted states. This commentary contrasts with the more technical and policy-focused discussions in other reports.

The scope of the cyberattacks targeting the water sector has expanded significantly, with at least 12 US states now confirmed to be affected, an increase from the seven states previously reported by the FBI. While Minnesota and Michigan were among the first to confirm intrusions, Georgia's Clayton County Water Authority has also reported a temporary disruption to its operational systems, leading to reduced water pressure. The FBI has identified Rockwell Automation's MicroLogix 1100 and 1400 series PLCs as the specific targets, noting that attackers are remotely tampering with device configurations, which can lead to loss of view and function of connected equipment.

The scope of cyberattacks targeting water utilities has significantly expanded, now affecting at least 12 states, including new public confirmations from South Dakota and Georgia. These incidents, allegedly linked to Iranian hackers, involve disruptions to operational technology systems, with some leading to precautionary boil water advisories. Federal agencies like CISA have issued updated warnings about the increasing threat to programmable logic controllers (PLCs) used in water systems, emphasizing the need to remove these devices from public internet exposure.

This latest report indicates that the scope of the cyberattacks on water systems has expanded significantly, now affecting facilities across a dozen U.S. states. The attacks are exploiting vulnerabilities in internet-exposed Programmable Logic Controllers (PLCs), a common component in industrial control systems. The coordinated nature and broad reach of these incidents strongly suggest a state-sponsored actor, with intelligence pointing towards Iran as a potential perpetrator.

Synthesized by Vypr AI