Water System Cyberattacks Put OT Exposure on the SMB Risk Register

Recent attacks against Minnesota water systems are a useful warning because they were practical, not

That combination matters for small and midsize organizations. Many businesses now depend on connecte

Why This Belongs in the SMB Risk Conversation

An April 2026 joint cybersecurity advisory from the FBI, CISA, NSA, EPA, and other federal partners

The business takeaway is straightforward: exposure management is not just a vulnerability scanner re

Five Controls to Start With

1. Find Every Internet-Reachable Operational System

Start with an inventory that includes OT, IoT, building systems, cellular gateways, remote monitoring tools, cameras, environmental controls, and vendor-managed appliances. Compare internal records with external exposure scans so you can identify devices that were installed outside the normal IT process. Record the device, location, business purpose, owner, support vendor, software or firmware version, and method of remote access.

Assign both a business owner and a technical owner to every system. Someone should be able to explain what would stop if the device failed, while someone else is accountable for configuration, patching, access, and monitoring. Review the inventory at least quarterly and whenever facilities, operations, or vendors add connected equipment.

2. Remove Direct Remote Access Wherever Possible

Remote access should not mean that a PLC, field device, camera, router, or management interface is directly exposed to the internet. Place remote administration behind a managed access layer such as a secure gateway, VPN, zero trust access service, or vendor access platform that supports strong authentication and detailed logging. Where feasible, restrict connections by approved user, device, location, time window, and destination.

The practical goal is to make reachability temporary, attributable, and reviewable. Schedule vendor access only when work is being performed, disable dormant accounts, and require a named internal owner to approve exceptions. Test the path periodically so the team knows both that authorized support can connect and that unauthorized internet access cannot.

3. Replace Default Credentials and Require MFA for Privileged Access

Default credentials and shared administrator passwords turn small exposure mistakes into easy compromises. Change factory credentials before deployment, eliminate generic shared accounts where the product allows it, and store privileged secrets in an approved password manager or vault. Require multifactor authentication on the gateway, management portal, and any identity service that can authorize access to operational systems.

The ownership model matters as much as the setting. Give one role responsibility for quarterly credential and access reviews, and immediately review access after an employee departure, vendor change, or incident. If a legacy device cannot support modern authentication, document the exception and compensate with network isolation, restricted jump-host access, session logging, and tighter monitoring.

4. Keep Manual Operations Real, Documented, and Exercised

The Minnesota incidents show why manual procedures still matter. A workaround that exists only in an old binder or in one employee's memory is not a reliable continuity control. Document the minimum steps needed to operate safely, communicate status, preserve records, and restore normal service when technology is unavailable.

Identify the systems where manual workarounds protect revenue, safety, compliance, or customer commitments. Assign decision authority, keep current contact information available offline, and confirm that required tools or paper forms are accessible. Exercise at least one scenario each year, record where the process breaks down, and update both the procedure and the technical recovery plan.

5. Monitor for Operational Changes, Not Just Malware Alerts

Traditional endpoint alerts may miss the operational signs that matter most. Monitor for unexpected configuration changes, altered set points, unusual remote sessions, new administrator accounts, unexplained reboots, loss of communications, and commands issued outside normal maintenance windows. Where full OT monitoring is not practical, begin with logs from the remote access gateway, firewall, identity provider, and vendor platform.

Decide in advance who receives those alerts and what they are allowed to do. The first response might be to disable a remote account, isolate a network segment, move to manual operations, or call an equipment vendor before making changes. Use a short escalation checklist so the help desk, operations team, leadership, and outside partners know when an event becomes an operational incident.

What Leaders Should Ask This Week

Leadership does not need to start with a large OT security program. Start with five questions: What

Those questions create a practical bridge between technical controls and business continuity. Cytech

Sources and Further Reading

FOX 9: https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack.amp

CBS Minnesota: https://www.cbsnews.com/minnesota/news/cyberattack-malware-braham-water-plant-outage/

Plymouth incident overview: https://plymouthmn.com/coordinated-cyberattack-targets-plymouth-and-stat

Joint advisory AA26-097A: https://www.ic3.gov/CSA/2026/260407.pdf

CISA Cybersecurity Performance Goals: https://www.cisa.gov/cybersecurity-performance-goals

Next
Next

Your Newest Employee Is an AI Agent: Does It Have Too Much Access?