Water System Cyberattacks Put OT Exposure on the SMB Risk Register
Recent attacks against Minnesota water systems are a useful warning because they were practical, not
That combination matters for small and midsize organizations. Many businesses now depend on connecte
Why This Belongs in the SMB Risk Conversation
An April 2026 joint cybersecurity advisory from the FBI, CISA, NSA, EPA, and other federal partners
The business takeaway is straightforward: exposure management is not just a vulnerability scanner re
Five Controls to Start With
1. Find Every Internet-Reachable Operational System
Start with an inventory that includes OT, IoT, building systems, cellular gateways, remote monitoring tools, cameras, environmental controls, and vendor-managed appliances. Compare internal records with external exposure scans so you can identify devices that were installed outside the normal IT process. Record the device, location, business purpose, owner, support vendor, software or firmware version, and method of remote access.
Assign both a business owner and a technical owner to every system. Someone should be able to explain what would stop if the device failed, while someone else is accountable for configuration, patching, access, and monitoring. Review the inventory at least quarterly and whenever facilities, operations, or vendors add connected equipment.
2. Remove Direct Remote Access Wherever Possible
Remote access should not mean that a PLC, field device, camera, router, or management interface is directly exposed to the internet. Place remote administration behind a managed access layer such as a secure gateway, VPN, zero trust access service, or vendor access platform that supports strong authentication and detailed logging. Where feasible, restrict connections by approved user, device, location, time window, and destination.
The practical goal is to make reachability temporary, attributable, and reviewable. Schedule vendor access only when work is being performed, disable dormant accounts, and require a named internal owner to approve exceptions. Test the path periodically so the team knows both that authorized support can connect and that unauthorized internet access cannot.
3. Replace Default Credentials and Require MFA for Privileged Access
Default credentials and shared administrator passwords turn small exposure mistakes into easy compromises. Change factory credentials before deployment, eliminate generic shared accounts where the product allows it, and store privileged secrets in an approved password manager or vault. Require multifactor authentication on the gateway, management portal, and any identity service that can authorize access to operational systems.
The ownership model matters as much as the setting. Give one role responsibility for quarterly credential and access reviews, and immediately review access after an employee departure, vendor change, or incident. If a legacy device cannot support modern authentication, document the exception and compensate with network isolation, restricted jump-host access, session logging, and tighter monitoring.
4. Keep Manual Operations Real, Documented, and Exercised
The Minnesota incidents show why manual procedures still matter. A workaround that exists only in an old binder or in one employee's memory is not a reliable continuity control. Document the minimum steps needed to operate safely, communicate status, preserve records, and restore normal service when technology is unavailable.
Identify the systems where manual workarounds protect revenue, safety, compliance, or customer commitments. Assign decision authority, keep current contact information available offline, and confirm that required tools or paper forms are accessible. Exercise at least one scenario each year, record where the process breaks down, and update both the procedure and the technical recovery plan.
5. Monitor for Operational Changes, Not Just Malware Alerts
Traditional endpoint alerts may miss the operational signs that matter most. Monitor for unexpected configuration changes, altered set points, unusual remote sessions, new administrator accounts, unexplained reboots, loss of communications, and commands issued outside normal maintenance windows. Where full OT monitoring is not practical, begin with logs from the remote access gateway, firewall, identity provider, and vendor platform.
Decide in advance who receives those alerts and what they are allowed to do. The first response might be to disable a remote account, isolate a network segment, move to manual operations, or call an equipment vendor before making changes. Use a short escalation checklist so the help desk, operations team, leadership, and outside partners know when an event becomes an operational incident.
What Leaders Should Ask This Week
Leadership does not need to start with a large OT security program. Start with five questions: What
Those questions create a practical bridge between technical controls and business continuity. Cytech
Sources and Further Reading
FOX 9: https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack.amp
CBS Minnesota: https://www.cbsnews.com/minnesota/news/cyberattack-malware-braham-water-plant-outage/
Plymouth incident overview: https://plymouthmn.com/coordinated-cyberattack-targets-plymouth-and-stat
Joint advisory AA26-097A: https://www.ic3.gov/CSA/2026/260407.pdf
CISA Cybersecurity Performance Goals: https://www.cisa.gov/cybersecurity-performance-goals