Blog
CISA Told Water Utilities to Get Their PLCs Off the Internet. Here's What Stands in the Way.
)
Key takeaways
CISA's July 30 warning came out of an active, ongoing attack, not a hypothetical. More than 30 Minnesota water systems were hit July 26–27 through exposed Rockwell MicroLogix PLCs, with attackers locking operators out by changing IPs and passwords.
CISA's fix (get PLCs off the internet) is correct but assumes resources a lot of utilities don't have. For a regional water district running on one engineer, a twice-a-year vendor visit, and a firewall-only IT budget, "disconnect it and put it behind a VPN" is a bigger lift than the alert lets on.
Closing that gap doesn't require a bigger budget or ripping out equipment. An overlay approach, closing inbound ports and opening scoped outbound-only access for just the people who need it, lets a small operations team actually execute CISA's guidance this quarter instead of needing a network redesign.
On July 30, CISA warned the water and wastewater sector that attackers are actively hunting exposed programmable logic controllers, and it told operators plainly to disconnect those controllers from the internet [LINK]. While that guidance is sound, it is also harder for a lot of utilities to carry out overnight than the alert accounts for.
The Minnesota Incident Shows What This Kind of Exposure Actually Costs
Let’s back up a short time. Four days before the alert, more than 30 community water systems across Minnesota, including Maple Plain, Braham, South St. Paul, and Plymouth, were hit by a coordinated attack on their PLCs. Attackers changed device IP addresses and reset passwords, locking operators out of the same controllers they use to run treatment and distribution. Utilities lost monitoring and control functionality, some switched to manual operations to keep water moving safely. An FBI alert later confirmed that similar activity had spread to utilities in seven or more states, with pressure loss and flooding reported at some sites.
The FBI's alert pointed to Rockwell Automation MicroLogix 1100 and 1400 controllers specifically, though it notes that the same weakness runs across other brands as well. In at least one case, attackers went further than locking operators out: they got into the PLC project files themselves and changed the ladder logic, which contains the actual instructions telling the equipment what to do.
This kind of vulnerability can be found in any number of environments, including other critical infrastructure, utilities, highways, or other industries that have remote equipment.
CISA's Mitigation List Assumes Resources Many Utilities Don't Have
CISA's mitigation list itself is short and reasonable: get PLCs off direct internet access, route remote connections through a VPN or gateway, eliminate default credentials, and keep clean offline backups of PLC firmware.
What the alert doesn't spell out is that a regional water district or a small municipal utility rarely runs that PLC connection the same way a defense contractor runs its network. Often it's a sole engineer checking pressure and flow from a laptop at home, or a vendor who dials in twice a year for maintenance, and an IT budget that covers a firewall and little else. Telling that utility to disconnect the PLC and put it behind a VPN assumes there's staff and time available to build and maintain that architecture, and for a lot of SLED and critical infrastructure operators, there simply isn't.
That isn't a knock on those operators. It reflects the actual shape of the problem CISA is asking them to solve, and it deserves to be said plainly rather than assuming the guidance closes the gap on its own.
An Overlay Can Close That Gap Without Adding Headcount or Rebuilding the Network
This is the exact problem Terniion was built to close, and it does so without asking a utility to rip out or reconfigure the PLCs, RTUs, and HMIs already running the plant.
Terniion allows you to close every inbound port on the device, then opens an outbound-only connection to exactly the engineer, vendor, or central team that's meant to reach it, and nothing beyond that. The PLC stops being something an attacker can scan, find, or connect to from outside. The operator checking pressure at 2 a.m. can still do it from home, and a vendor dialing in for maintenance can still do it too, but it’s all through a connection scoped to that one task instead of the whole network behind it.
That kind of scoped access turns disconnecting a PLC from a directive into something a three-person operations team can actually carry out this quarter, without
Firmware changes
A requalification cycle
Network redesign
That’s because the overlay goes on top of what's already running, one site at a time, starting with whatever's highest-risk.
Terniion's architecture aligns with NIST CSF 2.0 and CISA's own Cross-Sector Cybersecurity Performance Goals, which is a fancy way of saying it does what this urgent alert is asking utilities to do.
Whether Utilities Can Act on This Guidance Will Matter More Than Whether They Agree With It
Minnesota will not be the last state to receive this kind of alert firsthand, and the utilities that come out ahead of the next one will likely be the ones that found a way to get their PLCs off the internet without needing a bigger budget to do it.
See how Terniion secures OT, IIoT, and SCADA environments without touching a device or interrupting a process, then book a demo built around what's actually running in your environment.
Related content
)
The Security Blind Spot in Long Lifecycle Assets
There’s a whole category of IoT/OT/CPS assets with long lifecycles like EV chargers, wind turbines, aircraft, ships, industrial machinery, and medical devices whose systems last a long time and are vulnerable to dangers that change quickly.
Read Blog