* [Blog](https://www.paloaltonetworks.com/blog) * [Network Security](https://www.paloaltonetworks.com/blog/network-security/) * [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/) * The Water-Sector Reckonin... # The Water-Sector Reckoning Is Here --- and the Controls That Stop It Already Exist [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fthe-water-sector-reckoning-is-here-and-the-controls-that-stop-it-already-exist%2F) [](https://twitter.com/share?text=The+Water-Sector+Reckoning+Is+Here+%E2%80%94+and+the+Controls+That+Stop+It+Already+Exist&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fthe-water-sector-reckoning-is-here-and-the-controls-that-stop-it-already-exist%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fthe-water-sector-reckoning-is-here-and-the-controls-that-stop-it-already-exist%2F&title=The+Water-Sector+Reckoning+Is+Here+%E2%80%94+and+the+Controls+That+Stop+It+Already+Exist&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/network-security/the-water-sector-reckoning-is-here-and-the-controls-that-stop-it-already-exist/&ts=markdown) \[\](mailto:?subject=The Water-Sector Reckoning Is Here — and the Controls That Stop It Already Exist) Link copied By [Keith Higgins](https://www.paloaltonetworks.com/blog/author/keith-higgins/?ts=markdown "Posts by Keith Higgins") and [Anurag Thantharate](https://www.paloaltonetworks.com/blog/author/anurag-thantharate/?ts=markdown "Posts by Anurag Thantharate") Aug 17, 2026 7 minutes [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown) [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown) [OT Security](https://www.paloaltonetworks.com/blog/network-security/category/ot-security/?ts=markdown) [OT](https://www.paloaltonetworks.com/blog/tag/ot/?ts=markdown) Recently, a coordinated intrusion locked operators out of water and wastewater controls across more than 30 Minnesota communities.^1^ Within days, the count crossed multiple states, prompting the FBI and EPA to issue an alert regarding malicious cyber actors targeting internet-facing programmable logic controllers.^2^ The instinct after an attack like this is to patch faster. Today, there's a better answer. ## What happened wasn't sophisticated. That's the point. The attackers didn't burn a zero-day. They reached internet-exposed controllers, authenticated against weak or default credentials --- in several cases exploiting CVE-2021-22681, an authentication-bypass flaw with no vendor patch --- then changed device IP addresses and passwords to lock legitimate operators out of their own booster and pump stations. Investigators found modified ladder logic on at least one system. CISA had already catalogued the pattern in advisory AA26-097A, published four days before the campaign began, and it is the same technique that disabled a booster station in Aliquippa, Pennsylvania in late 2023.^3^ ### As Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition, put it, this is "*a reckoning of the consequences of ignoring the importance of investing in our nation's cybersecurity for our critical infrastructure.* "^4^ Nothing in that sequence required advanced tooling. It required a controller reachable from the open internet, a credential nobody had changed, and a flat network with nothing between the attacker and the process. That is not a patching failure. It is a hygiene and controls failure --- which is also why it is fixable without waiting on a single vendor update. ## You can't patch your way out of this --- and you don't need to. A water system can't be rebooted for a patch on demand. Safety recertification, process-continuity requirements, and vendor dependencies mean planned outages happen once or twice a year. Many of the controllers running production today --- legacy PLCs, RTUs, aging HMIs --- will likely never receive another vendor patch at all. Telling a two-person utility team to "patch faster" ignores the physics of their plant. The right question isn't "when can we patch?" It's "how do we shield the system while patching waits for its scheduled downtime?" Three network controls do exactly that --- and none of them require touching or rebooting the vulnerable device. ## First: See what's actually exposed. You can't segment or protect what you can't see. These utilities were breached through PLCs and cellular field gear that operators didn't know were internet-reachable --- the towers and lift stations in Plymouth, Minnesota were connected over consumer cellular with no firewall in front of them. Continuous, passive asset visibility fixes the blind spot: it identifies every controller, its firmware and function, and --- critically --- every path that reaches it, including the remote and cellular-connected sites that never appear on a network diagram. **What it means for you:** an internet-exposed PLC stops being the thing you discover during an incident and becomes something you find and close on a normal Tuesday. ## Then: Contain the blast radius with micro-segmentation. One technique hit more than 30 communities because the same flat, exposed design repeated in each of them. Segmentation is what stops a single exposed controller from becoming plant-wide loss of control. Micro-segmentation enforced at the firewall isolates PLCs from engineering workstations, separates IT from OT, and puts remote and cellular field sites behind an inspected, authenticated path instead of an open one. Visibility shows the exposure; segmentation removes the path to it. And because the next-generation firewall is both the sensor that sees the asset and the enforcement point that governs traffic to it, closing that path is a policy change on the same platform --- not a detection handed to someone to translate into a firewall rule while an attack is underway. **What it means for you:** the exposed controller in one town can't be reached from the internet, and even inside the plant an attacker who lands on a workstation can't pivot to the chlorine-dosing controller. ## Finally: Protect what you can't patch --- with risk-prioritized virtual patching. Some exposures can't be closed by a patch at all. CVE-2021-22681 had none, and the PLC units and legacy RTUs across these systems will likely never get another vendor update. That's where prioritization and virtual patching work together. Prioritize first --- by operational consequence, not CVSS score. A vulnerability on a production-critical or safety-classified controller carries far more operational risk than a higher-scoring CVE on a non-essential workstation. Palo Alto Networks Industrial OT Security scores vulnerabilities by real-world operational risk --- factoring in device function, safety classification, blast radius, and existing network controls so protected assets aren't misranked. For the exposures that matter, AI-driven virtual patching shifts protection to the network layer. OT Security correlates those vulnerabilities with available threat-prevention signatures and automatically generates enforceable inline protections that intercept exploit attempts before they reach the controller --- no maintenance window, no vendor involvement, no change to the running system. Because the firewall is already the IT-OT and OT segmentation enforcement point, that protection applies immediately to both north-south and east-west traffic. And when a new protection is ready, cloud delivery puts it in force fast. In an OT context, that speed is an uptime and public-safety argument, not a spec --- the compensating control is live before the next shift, not the next scheduled outage. For a water operator, that is the difference that matters. The chlorine-dosing controller you can't take offline, the booster-station PLC a vendor stopped supporting years ago, the remote pump site reachable over cellular --- each can be shielded inline while traditional remediation runs on its own timeline. ## What it means for you. The Minnesota campaign wasn't a sophistication problem you out-patch. It was a hygiene and controls problem you architect against --- and the three controls that would have contained it exist today, none of them dependent on a maintenance window. See every asset and every path that reaches it. Segment so one exposed controller can't become plant-wide loss of control. Virtually patch the legacy and unpatchable devices inline. Do that, and patch timing comes off the critical path: your remediation keeps its own schedule, and your defense stops waiting on it. For the deeper technical case behind this approach, read the [Palo Alto Networks blog](https://www.paloaltonetworks.com/blog/network-security/protecting-ot-environments-from-frontier-ai-powered-attacks-starts-with-operational-risk-prioritization-and-virtual-patching/?ts=markdown) on operational risk prioritization and virtual patching for OT. ## Talk to a Critical Infrastructure Security Specialist. Schedule a 30-minute strategy call to evaluate your OT and 5G posture against exposed assets, flat networks, and legacy visibility gaps. What you'll get from the call: * A tailored visibility review: Map your current asset coverage against enterprise baselines where, according to Palo Alto Networks' [2025 Device Security Threat Report](https://www.paloaltonetworks.com/resources/infographics/device-security-threat-2025?ts=markdown), 32.5% of devices on corporate networks operate completely unmanaged and invisible to security teams. * Architecture and segmentation guidance: Identify opportunities to eliminate tool sprawl, harden OT segmentation, and protect legacy OT systems without operational downtime. * 5G \& edge security: Learn how inline inspection and identity intelligence protect private cellular expansions. To schedule a brief call or to receive more information, please [contact us](mailto:dl-otsecurityfreetrial@paloaltonetworks.com). ^1^ Minnesota IT Services. (2026, July 28). *MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure* . State of Minnesota.[https://mn.gov/mnit/media/blog/?id=38-761869](https://mn.gov/mnit/media/blog/?id=38-761869) ^2^Federal Bureau of Investigation, \& Environmental Protection Agency. (2026, July 30). *Malicious cyber actors targeting water and wastewater sector internet-facing programmable logic controllers, causing operational disruptions* (Alert: I-073026-PSA). Internet Crime Complaint Center (IC3).[https://www.ic3.gov/PSA/2026/PSA260730.pdf](https://www.ic3.gov/PSA/2026/PSA260730.pdf) ^3^ Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, \& National Security Agency. (2023, December 1). *IRGC-Affiliated Cyber Actors Exploit Programmable Logic Controllers in Multiple Sectors* (Advisory AA23-335A). [https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a) ^4 Operational Technology Cybersecurity Coalition. (2026, July 31). *A Wake Up Call for OT Security: OTCC Statement on Critical Infrastructure Cybersecurity and the Need for Congressional Action* . [https://www.otcybercoalition.org/post/a-wake-up-call-for-ot-security-otcc-statement-on-critical-infrastructure-cybersecurity-and-the-nee](https://www.otcybercoalition.org/post/a-wake-up-call-for-ot-security-otcc-statement-on-critical-infrastructure-cybersecurity-and-the-nee)^ *** ** * ** *** ## Related Blogs ### [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Safeguard OT Environments with the Power of Precision AI](https://www.paloaltonetworks.com/blog/2024/10/safeguard-ot-environments-power-precision-ai/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Forrester Names Palo Alto Networks a Leader in OT Security](https://www.paloaltonetworks.com/blog/2024/06/forrester-names-leader-in-ot-security/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Zero Trust Security](https://www.paloaltonetworks.com/blog/network-security/category/zero-trust-security/?ts=markdown) [#### Untangling IT-OT Security Knots with a Zero Trust Platform Approach](https://www.paloaltonetworks.com/blog/2024/05/untangling-it-ot-security-knots/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### Turning Device Context into Action: The Power of Contextual Segmentation](https://www.paloaltonetworks.com/blog/network-security/turning-device-context-into-action-the-power-of-contextual-segmentation/) ### [OT Security](https://www.paloaltonetworks.com/blog/network-security/category/ot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Omdia Analysis Estimates $2M+ Risk Reduction with OT Device Security](https://www.paloaltonetworks.com/blog/network-security/omdia-analysis-estimates-2m-risk-reduction-with-ot-device-security/) ### [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing OT Infrastructure: 10 Transformative Use Cases](https://www.paloaltonetworks.com/blog/network-security/securing-ot-infrastructure-10-transformative-use-cases/) ### Subscribe to Network Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language