- › A coordinated attack hit operational technology at more than 30 Minnesota community water systems on July 26 and 27, with at least one treatment plant going offline.
- › Small utilities were chosen because the consequence of disrupting them is large while the defense they can afford is small, and that gap is the target.
- › A community water system serving a few thousand people often has no dedicated security staff, no overnight monitoring, and a control network someone connected to the internet for convenient remote access.
- › The control that matters most is the ability to run the plant manually when the control system cannot be trusted, practiced by the operators who would have to do it.
- › Get HMI and PLC interfaces off the public internet, write and rehearse manual operating procedures, and use the free federal and state assessment services already available to you.
Sometime on July 26 and 27, more than 30 community water systems across Minnesota were hit in a coordinated attack on their operational technology. Braham, Plymouth, South St. Paul, and Maple Plain have described a plant outage, communications failures, or affected systems. The state opened a coordinated cybersecurity response. Officials have not formally named who did it, and suspicion has fallen on CyberAv3ngers, a group linked to Iran that has gone after water utilities before.
I want to set aside the attribution question, because it will take months and it is not the part an operator can act on. The part worth your attention is the targeting. Thirty-odd small water systems, all at once, in one state. That is not opportunistic scanning that happened to find something. That is a choice, and understanding why it was made tells you what to do about it.
The Gap Is the Target
Here is the uncomfortable arithmetic underneath this. A community water system serving five thousand people produces something nobody can go three days without. The consequence of disrupting it is enormous, measured in boil advisories, closed schools, hospitals on backup supply, and public trust that takes years to rebuild.
Now look at what defends it. That same utility often has no dedicated security staff at all. It may have one IT person who also handles billing software, or a part-time contractor who visits monthly. There is no overnight monitoring, because there is no overnight anyone. The control system was installed by an integrator years ago and has not been meaningfully touched since, because it works and the budget goes to pumps and pipes and chemicals, which are the things that visibly fail when neglected.
The distance between those two facts is the whole story. An adversary looking for maximum consequence per unit of effort finds it exactly where the importance of a system and the resources protecting it are furthest apart. Large investor-owned utilities have security teams and budgets. Federal facilities have both plus oversight. The community water system in a town of four thousand has neither, and it produces the same essential thing.
We have written before about the cyber poverty line, the threshold below which an organization cannot afford the basic security capabilities that larger peers take for granted. Small utilities live well below it, and they are not there through negligence. They are there because a rate base of a few thousand households does not fund a security program, and nobody has ever asked them to price one.
Why Hitting Thirty at Once Matters
The coordination is the second signal, and it changes what the attack means.
Compromising one small water system is a local incident. The state can send help, neighboring utilities can lend expertise, and the story stays in the regional news. Compromising thirty simultaneously does something different. It exhausts the response capacity of the entire state at once. Every utility that would normally receive expert assistance is now competing for the same small pool of people who understand these control systems. The mutual aid arrangement where a neighboring town’s operator drives over to help does not work when the neighboring town is also down.
That is the operational lesson regardless of who did it or why. Your incident response plan almost certainly assumes you will be the only one calling for help. Simultaneous, sector-wide targeting breaks that assumption, and the utilities that fared best this week are the ones that could keep operating without waiting for anyone to arrive.
The Control That Actually Held
So what works, for an operator with a small budget and a plant to run?
The single most valuable capability in an incident like this is the ability to operate manually. If your control system is compromised or simply untrusted, can your staff run the treatment process by hand, using local controls, physical gauges, and written procedures? Can they dose chemicals, manage flow, and monitor quality without the SCADA system telling them what is happening?
This is not a nostalgic preference for analog. It is the recognition that during an incident you will face a period, possibly days, where you cannot trust what the control system tells you and cannot safely use it to make changes. Water still has to be treated during that window. The utilities that have written manual operating procedures, and whose operators have actually practiced them rather than filed them, can absorb that window. The ones that cannot are choosing between running blind on a system they do not trust and stopping.
Practicing it matters more than writing it. A procedure that has never been executed is a document, not a capability. Run it once a year on a normal day, with the people who would actually be on shift, and find out what is missing while the stakes are low.
Get the Control Network Off the Internet
The other change worth making this week is more basic and more common than it should be.
Control system interfaces, the HMI screens and PLC management ports that let someone see and change what the plant is doing, end up reachable from the public internet with remarkable regularity. Almost always for a defensible reason: an operator needs to check a reading from home at 2 a.m., or the integrator needs remote access for support, and exposing the interface was the fastest way to make that work. Nobody made a reckless decision. Somebody made a convenient one, years ago, and it stayed.
Go find yours. Search your public addresses for anything that answers on the protocols your control equipment speaks. If remote access is genuinely required, put it behind a VPN with multi-factor authentication rather than exposing the interface itself, and give the integrator time-limited access rather than a standing account. The Purdue model and ICS segmentation fundamentals exist precisely to keep the control network separated from everything else, and even a partial implementation is worth far more than none.
Segmentation between the business network and the control network deserves the same look. Billing, email, and the plant control system should not share a flat network, because the phishing email that lands in the office is otherwise one hop from the equipment that treats the water.
Use the Help That Already Exists
The part small utilities most often miss is that a meaningful amount of assistance is free and already funded.
Federal and state agencies offer no-cost cybersecurity assessments, vulnerability scanning, and technical advisories specifically for water systems and other critical infrastructure. Sector information sharing organizations distribute threat intelligence written for operators rather than analysts. State agencies frequently have staff whose job is helping municipal systems exactly like yours. None of this requires a budget line, and all of it goes underused because small utilities do not know it exists or assume it is meant for someone larger.
If your system does not currently receive advisories about threats to water utilities, that is a fifteen-minute fix and it would have told you about this group before this week. The same layered approach we describe for defending dispersed critical infrastructure applies at any size, and at small scale the layers are cheaper than most operators expect: network separation, remote access that requires a second factor, backups you have restored from at least once, and a practiced manual mode.
What This Week Should Tell Every Small Operator
If you run a small utility, a municipal system, a rural clinic, a regional co-op, or any other operation that matters far more than its budget suggests, the message from Minnesota is not that you need an enterprise security program. You cannot have one and pretending otherwise wastes the effort you do have.
The message is that you are a deliberate target because of the gap, and that a handful of unglamorous controls close most of it. Take the control interfaces off the internet. Separate the plant network from the office network. Make sure you can run manually and prove it once a year. Take the free assessment. Get on the advisory list.
None of that stops a determined nation-state actor from getting in eventually. All of it means that when they do, your community still has water while you sort it out, which is the outcome that actually matters to the people you serve.
If you want to know what your control network looks like from outside, and whether your team could actually run the plant without it, that is the work we do. Start with our free Human Attack Surface Score, or contact Grab The Axe and we will assess it the way an adversary would.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability. He leverages high-logic strategies to pinpoint high-ROI vulnerabilities, ensuring defense measures actually scale with the business.
View Author Page →