Water Utilities Face Hidden Cyber Risks via Cellular-Connected OT Systems
Recent cyberattacks on water utilities exploited operational technology systems connected through public cellular networks, bypassing traditional IT security and highlighting critical gaps in asset visibility and network segmentation.

Recent cyber incidents targeting water and wastewater utilities have exposed a critical vulnerability: many operational technology (OT) systems are connected to the internet via public cellular networks, effectively bypassing established IT security perimeters. Attackers have leveraged this exposure to compromise controllers, leading to operational disruptions such as the failure of pump stations. This reliance on cellular connectivity means these devices often remain invisible to standard asset inventories and network scans, posing a significant, unaddressed risk.
The incidents, which affected utilities across multiple states in late July, typically involved controllers directly connected to cellular modems. While no federal agency has officially attributed these specific late-July attacks, a joint advisory from CISA, the FBI, and the EPA noted Iranian-affiliated actors in a broader campaign. The advisory was updated to include a wider range of controller brands, such as Schneider Electric and Siemens, in addition to Rockwell Allen-Bradley, indicating that the specific hardware brand is no longer a reliable indicator of vulnerability.
The primary impact of these intrusions has been operational. In Clayton County, Georgia, a pump station failure on July 27th led to a boil-water advisory, with the authority later stating that unauthorized cyber activity may have caused or contributed to the disruption. These events underscore a fundamental challenge: while utilities may have implemented network segmentation for their IT infrastructure, these cellular-connected OT devices often exist outside these protected zones.
A key takeaway from the incidents is the difficulty in identifying these cellular-connected devices. Standard asset lists and network scans typically fail to detect modems installed years ago. The most effective method for utilities to identify these devices is by reviewing carrier invoices for SIM card usage, a task that usually falls under accounts payable. Matching these invoices to actual devices is a low-cost, actionable step that can be implemented immediately.
Beyond technical solutions, the article highlights that the core issues are organizational and financial. Most OT systems are managed by departments outside of traditional IT, such as public works, and often have their own budgets and vendors. This distributed ownership means no single entity is accountable for the security of the entire network. Furthermore, reporting requirements for security incidents, such as those in Texas, often exclude intrusions that do not involve personal data breaches or ransomware, leaving many OT compromises unreported.
Addressing these vulnerabilities requires a shift in accountability and funding. While some argue there is no budget for cybersecurity improvements, funding mechanisms already exist. For instance, the Texas Water Development Board has incorporated cybersecurity into its scoring criteria for the Drinking Water State Revolving Fund. This incentivizes utilities to conduct cybersecurity assessments and implement remediation plans.
The article draws on the experience of Waco, Texas, which successfully segmented its water treatment plants' networks within 43 days without requiring a new bond or capital request. The utility director funded the project from operating accounts using an existing contract. This approach demonstrates that network segmentation, while technically achievable, is often a matter of budget prioritization and executive decision-making rather than a lack of funds or technical expertise.
Ultimately, securing these critical infrastructure components necessitates a holistic approach. Utilities must gain visibility into all connected devices, including those on cellular networks, establish clear lines of accountability for network security, and leverage existing funding channels to implement necessary protections. The principle of least privilege, where devices are granted only the necessary access to perform their functions, should be a guiding operational rule.