If you still have problems, please let us know. Thank you!
Public Agency Compensation Trust
T (775) 885-7475
Email: info@poolpact.com
POOL/PACT
201 South Roop Street, Carson City NV 89701
Federal authorities confirmed in late July that attackers are taking control of water and wastewater equipment reachable from the public internet, and the activity is spreading. For Nevada public entities that operate water or wastewater systems, the exposure is direct: the same controllers, the same vendor-installed remote access, and the same small-utility staffing constraints exist here. This report summarizes what happened, what existing law already requires, the three controls federal authorities recommend, and how the Enterprise Risk Management Excellence Program already assesses this exposure.
Between July 26 and 27, 2026, more than 30 Minnesota community water systems reported cyber activity affecting the technology that monitors and controls water equipment; some operated equipment by hand, and one intrusion briefly knocked out controls for a city well and treatment plant. On July 30, the Cybersecurity and Infrastructure Security Agency issued an alert reporting a significant increase in attacks on programmable logic controllers, the devices that automate pumps, wells, valves, and treatment equipment, and urged utilities to remove publicly exposed controllers from the internet as soon as possible. The FBI and EPA issued a companion announcement the same day: utilities in at least seven states had reported incidents, and some attacks degraded water operations. By early August the activity had reached systems in Michigan and Georgia.
The method is simple. Attackers located controllers directly reachable from the internet, then changed device passwords and IP addresses, locking operators out of their own equipment. Reported effects include loss of pressure, flooding, boil water notices, and extended manual operation. No advanced exploit was required; the exposure itself was the vulnerability. CISA states that water entities of every size are being targeted, and specifically warns that even well-run utilities should validate external connections, including cellular modems installed by vendors or integrators that may not appear on any asset inventory. In Minnesota, staff switching to manual operation is what contained the damage.
Federal drinking water security requirements. A community water system serving more than 3,300 persons must conduct a risk and resilience assessment that covers the security of its electronic, computer, and other automated systems, and must maintain an emergency response plan that addresses the resilience of the system, including cybersecurity. 42 U.S.C. Sec. 300i-2. If your assessment or plan treats cyber as an information technology topic only and does not reach the control systems that run the plant, it is incomplete.
Nevada incident response planning. Every Nevada political subdivision must adopt and maintain a cybersecurity incident response plan, file each new or revised plan with the Office of Information Security and Cyber Defense within 10 days after adoption or revision, and file annually, by December 31, either the revised plan or a written certification that the plan on file remains current. NRS 242.1289. Note that the 2025 Legislature repealed the prior requirement at NRS 480.900 through 480.950 and moved it to NRS Chapter 242; a plan that still cites NRS 480.935 or the former Office of Cyber Defense Coordination is out of date. Member entities should confirm current filing and incident reporting instructions directly with the Office.
CISA's July 30 alert distills the response to three direct mitigations. Each is achievable by a small utility working with its system integrator.
Disconnect the PLC from the internet. No controller should be directly reachable from the public internet. Where remote access is needed for operations, it should go through a VPN or gateway device, not directly to the PLC. Ask your integrator, in writing, what remote access exists into your system, including any cellular modem installed for after-hours access; these are the most common blind spot.
Enable password protection and change default passwords. Many controllers ship with no password or a published default. Enable password protection on every device and replace default passwords with strong, unique credentials.
Allowlist known devices. Configure the system to accept remote connections only from known IP addresses, such as your engineering laptops and other critical control system assets, and reject everything else. The FBI and EPA add one readiness measure: confirm your staff can operate the system manually if control is lost, because that capability is what contained the Minnesota incidents.
Member entities do not need new tools to respond to this threat. The Enterprise Risk Management Excellence Program Cybersecurity and Public Works sections already assess the exposures the federal government is now urging every utility to close. The Public Works section asks whether the entity employs a cybersecurity risk management program that regularly examines critical infrastructure vulnerabilities in its SCADA systems by establishing cybersecurity requirements for all online utility systems, and the Cybersecurity section asks the same question from the information technology side. The two questions are deliberate: they require public works and information technology to each account for the same equipment, which is precisely where undocumented remote access hides.
The federal mitigations themselves are already embedded in the ERMEP Cybersecurity assessment. CISA's first control, remote access only through a VPN or gateway, is the program's question on prohibiting remote network access without a VPN. The second, password protection, is the program's question on multi-factor authentication and strong passwords aligned to NIST guidance. The third, restricting access to known devices, is supported by the program's questions on firewalls, network monitoring, and maintaining a current list of every vendor with network access. The program likewise assesses the backup strategy, patching, incident response planning, and continuity of operations that determine how well an entity absorbs an attack that gets through. An entity that puts these existing resources to work hardens its own operation, and in a member-owned pool, every hardened system strengthens the members around it. Appropriate policies still need to be in place, irrespective of the activity.
POOL/PACT Risk Management can assist member entities with ERMEP engagement, incident response plan review, and vendor and integrator remote access terms. CISA offers no-cost vulnerability scanning that identifies internet-exposed assets before an attacker does, and EPA offers cybersecurity technical assistance for drinking water and wastewater utilities. If you suspect an incident, preserve the equipment details, contact your local FBI field office, and notify POOL/PACT; early notice lets us assist you and warn other members with the same exposure. For more information, please contact marshallsmith@poolpact.com or jarrodhickman@poolpact.com.
The Risk on the Horizon Report is a monthly advisory published by POOL/PACT Risk Management for POOL/PACT members. Each issue provides timely, actionable guidance on a single risk topic tied to seasonal patterns, regulatory changes, or emerging threats.
The information presented in this Risk on the Horizon Report is not legal advice. Member entities with questions about water system cybersecurity, SCADA and control system security, or incident response planning should contact their entity counsel prior to taking action, amending, or implementing policies based on this report.