The Minnesota Water Attack Was a Warning. Here's What Public Works Leaders Should Do Now.
The lesson isn't panic. It's recognition.
In late July 2026, more than 30 water and wastewater utilities across Minnesota were hit in a single, coordinated cyberattack. Over two days, communities including Braham, Plymouth, South St. Paul, and Maple Plain reported brief shutdowns, communication errors, and lift-station disruptions. Operators disconnected vulnerable equipment from the internet, switched to manual operations, and leaned on backup storage and contingency plans to keep service running.
State and local officials were clear on the most important point: drinking water and wastewater treatment quality were never compromised. But it shouldn't be mistaken for "no harm done." The attack didn't target the water. It targeted the operational technology that controls the water, the programmable logic controllers and SCADA systems that automate treatment, and it succeeded in taking those controls offline.
Public CISA and FBI advisories indicate the activity is consistent with activity CISA and the FBI have publicly attributed to IRGC-affiliated actors targeting internet-exposed PLCs. It followed repeated warnings from CISA and the FBI about foreign exploitation attempts on industrial control systems, and Minnesota wasn't alone. Reporting pointed to municipal water systems in several states being probed in the same window.
For anyone responsible for a public water system, the lesson isn't panic. It's recognition. Attacks like this are getting more common, not less, and the reasons are structural.
Why water systems are in the crosshairs
Water and wastewater utilities sit at a difficult intersection. They run essential services that communities notice immediately when they fail, which makes them attractive targets for anyone trying to sow disruption or make a political point. At the same time, many operate on tight budgets with small teams and aging control systems that were installed long before anyone imagined connecting them to the internet.
Over the years, remote monitoring, vendor support, and convenience have quietly put more and more of that equipment within reach of the open internet. A controller that was perfectly safe in an isolated plant becomes a doorway once it's reachable from anywhere. Attackers know this, and increasingly they scan for exactly these devices.
The disruption doesn't have to poison the water to cause real damage. Losing automated controls forces operators into manual mode, raises the risk of errors, increases costs, and stretches already-thin staff. In a serious incident, it can threaten the continuity of an essential public service. The Minnesota utilities did well to fall back on manual operation and contingency plans, but not every system is prepared to do the same, and doing it under pressure is far harder than practicing it in advance.
Why standard IT security isn't enough
Many utilities assume their existing IT protections cover this. They don't, at least not fully. Operational technology doesn't behave like office IT. You can't reboot a PLC in the middle of a treatment cycle or patch an HMI on Microsoft's schedule. These systems speak specialized protocols, run for years without updates, and prioritize safety and uptime above all else. Securing them takes people who understand the process, not just the network.
That's why an OT-specific approach matters. Instead of scanning for generic vulnerabilities, it asks operator questions: Which controllers are critical to safety? Where is the internet exposure? How is remote and vendor access handled? Do we have clean, offline backups of controller logic and configurations if we need to rebuild fast? Those answers are what actually reduce risk.
What leaders can do now
There are practical steps that don't require a year-long program. Start by getting a clear, honest picture of your OT exposure, an inventory of critical PLCs, HMIs, SCADA, remote connections, and vendor access, along with a check of internet exposure, segmentation, credentials, logging, and backups. From there, focus on immediate risk reduction: get internet-exposed controllers off the internet, secure remote access with gateways and multifactor authentication, harden controller and firewall configurations, and validate offline backups. Then build response readiness, connect cyber-response procedures to plant operating procedures, define who does what across operations, IT, leadership, vendors, and emergency management, and practice a scenario where automated controls go down. Finally, put it all into a prioritized roadmap leadership can fund and track.
This is the heart of the Koniag Public Works OT Cyber Resilience Package, and it reflects something rare in this market. Securing a water system thoroughly takes two capabilities that almost never sit under one roof: deep knowledge of how the plant physically runs, and specialized OT/ICS cybersecurity. Koniag brings both. Koniag Energy & Water builds and maintains water and wastewater facilities, including their automation and controls. Koniag Cyber secures the OT and SCADA behind them. Together, the same team has done this work at remote and unmanned sites across the country and throughout Alaska, for exactly the kind of resource-constrained crews that most public works organizations run.
A cyber incident shouldn't have to become a public-service crisis. The best time to find your exposure is before someone else does. The fastest place to start is a Rapid OT/ICS Assessment, a clear read on your risk in 2 to 3 weeks, and a plan you can act on.
Start with the Rapid OT/ICS Assessment: https://koniagcyber.com/the-catch/accelerated-ot-security-assessment
Find the content useful? Subscribe to The Catch, our exclusive weekly LinkedIn newsletter focused on real-life experiences doing cyber right in the most highly regulated industries.


