
Recent attacks on US water utilities trace back to a decades-old principle: don't put vulnerable systems on reachable networks. Forrester analysts say the lesson remains unlearned.
Recent attacks on US water and wastewater facilities trace back to a principle security researchers demonstrated years ago. Connect an unprotected computer directly to the internet and attackers will find it within minutes. That principle applies just as much to operational technology as to traditional IT, Forrester analysts wrote in a blog post.
Many discussions about water-sector cybersecurity focus on budget constraints and staffing shortages. Those are real problems. They are not the primary cause, the analysts said. The more fundamental issue is that organizations continue to expose programmable logic controllers, industrial control systems, and other OT assets to networks attackers can reach.
Services like Shodan continuously scan the internet for exposed devices. What was once manual reconnaissance is now automated. Attackers no longer need to know about a specific utility to find its systems. Visibility itself becomes a risk. Forrester noted that not every attack is driven by ideology or ransom demands. Sometimes attackers compromise a system simply because they can.
Agentic AI adds a new dimension. Organizations are exploring how AI can improve productivity and security. Threat actors are doing the same, using automation to identify exposed assets and gather intelligence. The economics of reconnaissance are shifting in the attacker's favor. Finding exposed systems no longer requires significant effort. Correlating those systems with known weaknesses becomes easier. Building repeatable attack workflows becomes faster. Forrester warned that future threats will increasingly involve automated systems continuously searching for opportunities, not highly skilled adversaries manually targeting individual assets.
There are positive developments. After the recent water-sector incidents, some managed detection and response providers have stepped forward with programs to help municipalities improve visibility. Some OT cybersecurity vendors are offering discounted solutions for critical infrastructure operators that lack resources. Policymakers are renewing conversations around critical infrastructure protection requirements. These efforts matter, Forrester said. They should not distract from the most important lesson. Technology alone cannot compensate for poor architecture.
Many of the most effective protections have existed for decades. As IT and OT converge, security boundaries remain relevant. Human resources personnel do not need direct paths into manufacturing systems. Administrative networks do not need unrestricted access to industrial control environments.
One additional risk deserves attention. Many critical infrastructure operators rely on remote sites connected via private cellular networks or other communications links. Recent incidents show attackers are increasingly targeting that communications infrastructure. Forrester said organizations should treat those connections with the same rigor as internet-facing assets. Secure and monitor them. Verify access continuously. Remote connectivity should not become an unmonitored pathway into operational systems.
The cybersecurity challenges facing municipalities and critical infrastructure operators are complex. Funding shortages and aging infrastructure contribute. Staffing gaps also play a role. Before pursuing new tools or new regulations, Forrester said, organizations should ask a simpler question: are vulnerable systems exposed to networks attackers can reach? That question, the analysts wrote, is the one that matters most.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.