Executive Summary

On July 30, 2026, the FBI and EPA warned that water and wastewater utilities in at least seven states had reported incidents since July 27 involving internet-facing operational technology, including Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. [1] This report treats those statements as the verified incident boundary and does not infer a broader prevalence rate or a local risk level for another organization.

Research Methodology and Source Selection

This report is a secondary-research synthesis and proprietary operating-model analysis. Quantitative claims are retained only where the source defines the population or denominator; unlike datasets are not blended.

Evidence Universe and Sample Assumptions

The evidence universe is limited to the eight listed references. Guidance is not evidence that a specific operator has implemented a control or is exposed to a threat.

Evidence Grading

Table 1. Evidence Grading and Permitted Use

Grade

Source Standard

Permitted Use

A - Authoritative

Federal/state incident disclosure, regulator, government publication, or recognized consensus standard.

Incident facts, scoped threat activity, regulatory context, and guidance within the stated source boundary.

B - Primary technical guidance

Government laboratory, standards body, or technical publication with a defined method or architecture.

Control design, operating practices, and implementation considerations within stated scope.

C - Sector guidance

Sector body or industry guidance with defined subject matter and clear ownership.

Maturity questions, implementation detail, and corroboration; not local proof of exposure.

D - Contextual

Secondary synthesis or commentary.

Context only; not used as standalone evidence for incident attribution, prevalence, or quantitative claims.

Research Limitations

Public incident information can change as investigations continue. Local decisions require system-specific architecture, process, safety, and incident evidence.

Research Framework

Findings use the CyberTech Intelligence Critical Infrastructure Cyber Resilience Framework™: Know, Reduce Exposure, Control Access, Segment, Observe, Isolate, Recover, and Govern. The framework tests evidence against service purpose, reachable paths, continuity, recovery trust, and accountable closure.

Executive Findings

The July 30 federal warning documents a current attack path from internet-facing PLC access to changes that impaired monitoring or control in water operations. [1]

GAO says water-sector risk is increased by the connection of operational technologies that control physical devices with internet-enabled devices, while workforce, legacy technology, and resource constraints complicate risk reduction. [2]

Critical-infrastructure governance is fragmented across sector and cross-sector requirements; GAO identified 117 federal cybersecurity regulations across nine sectors and potential overlap in reporting duties. [3]

EPA’s risk-and-resilience guidance emphasizes that baseline threat likelihoods are only starting points and that systems must account for their unique circumstances. [4]

Current federal practice guidance prioritizes secure remote access, incident response, recovery, and impact-based categorization rather than assuming one control model fits every operational environment. [5] [6] [7] [8]

1. The Incident Converts Reachability Into Operational Consequence

The FBI/EPA alert says actors remotely accessed internet-facing devices and changed IP addresses and passwords, producing loss of monitoring and control. [1] These details support a resilience focus on exposure, configuration integrity, third-party architecture, and manual operations.

2. The Evidence Shows a Current Event Set, Not a Universal Probability

The alert covers incidents reported to the FBI in at least seven states since July 27, 2026. [1] [4]

3. Internet Connectivity Creates Value and Exposure

GAO notes that internet-enabled devices can help distributed water and sewer systems by enabling remote control of pumps and other infrastructure, but that greater connectivity also increases attackers’ ability to reach critical operational systems. [2] The decision is therefore not “connected or disconnected.” It is whether connectivity is necessary, designed, attributable, monitored, and separable from the vital process.

4. Legacy and Workforce Constraints Are Part of the Risk Model

GAO identifies varying cybersecurity capabilities, workforce shortages, older technologies that are difficult to update, and competing demands on limited resources. Exposure reduction, controlled gateways, network separation, configuration baselines, and manual procedures can change risk while longer-term modernization is planned.

5. Regulation Does Not Remove the Need for an Operating Model

GAO identified 117 established federal cybersecurity regulations from 37 agencies across nine critical-infrastructure sectors, with 80 containing a type of reporting requirement also present in another regulation. Operators need a common internal model that can support multiple reporting obligations without allowing compliance activity to substitute for service-specific resilience testing.

6. Secure Remote Access Is an Architecture Problem

NIST SP 1800-45 demonstrates secure remote-access architectures for water and wastewater OT, acknowledging that digital transformation and remote operations can improve service while increasing cyber risk. Direct device exposure should not be treated as the default architecture for convenience.

7. Recovery Must Restore Process Trust

NIST SP 1800-41 addresses response and recovery in manufacturing ICS environments and emphasizes operational resilience. Returning systems quickly without establishing trust can preserve the same failure condition.

8. Impact-Based Prioritization Is Already Embedded in Critical-Infrastructure Practice

NERC CIP-002-5.1a categorizes Bulk Electric System cyber systems based on the adverse impact that loss, compromise, or misuse could have on reliable operation. [7] The standard’s scope is electric reliability, but its impact-based logic is relevant to enterprise prioritization: protect and test the systems whose compromise can produce the greatest operational consequence.

9. Research Desk Observation: Risk Expands at the Handoffs

Critical infrastructure is operated across organizational boundaries. The operating model must join these handoffs around the essential service.

Board-Level Evidence and Decision Metrics

Percentage of essential services with a current OT asset and dependency map.

Count of internet-facing or externally reachable OT services by operational criticality and exception owner.

Percentage of vendor and remote-access paths with named identities, approved scope, logging, and tested revocation.

Median time to isolate a vital OT zone while sustaining the minimum safe service.

Percentage of critical controllers and engineering configurations restored successfully in the most recent recovery exercise.

Percentage of high-impact services with documented and exercised manual or disconnected operating procedures.

Age and operational impact of unresolved exceptions involving exposure, shared credentials, segmentation, monitoring, backups, or recovery.

Twelve-Month Implementation Roadmap

0-90 days: identify essential services, owners, externally reachable OT, remote-access and vendor paths, immediate credential gaps, and minimum safe manual procedures.

3-6 months: standardize asset inventory, secure remote-access patterns, segmentation, OT monitoring, configuration baselines, backup management, and graduated isolation plans.

6-9 months: run service-level exercises covering loss of remote connectivity, unauthorized configuration change, vendor compromise, isolation, manual operation, and staged recovery.

9-12 months: institutionalize metrics, regulatory evidence mapping, exception aging, supplier requirements, recurring recovery tests, and executive investment decisions.

Strategic Takeaway: Preserve the Essential Service

The cyber battlefield reaches critical infrastructure when an attacker can influence the systems that deliver a physical or public service. The July 2026 water-sector incidents make that operating discipline immediate; they do not make every system equally exposed.

Assess Your Readiness

Benchmark Your Current Readiness Against the Findings. Request a Critical Infrastructure Cyber Resilience Assessment With Cybertech Intelligence.

Standards and Threat Mapping

Sources are separated by purpose: FBI and EPA provide incident and sector context; GAO provides oversight; NIST provides practice guides; NERC provides a regulated impact-based example. They are not treated as interchangeable evidence. [1] [2] [3] [4] [5] [6] [7] [8]

Visual Decision Architecture

The following decision models convert the campaign thesis into a repeatable sequence for executive review, operational containment, continuity, recovery, and governance. They are CyberTech Intelligence synthesis tools, not claims that every incident follows the same path.

Critical Infrastructure Cyber Attack Path

Figure 1. Critical Infrastructure Cyber Attack Path - From Reachable OT to Verified Recovery

Stage

Operational Meaning

1. Find a reachable path

An internet-facing OT device, remote-access service, vendor connection, or weakly protected pathway makes operational technology reachable.

2. Gain operational access

The actor reaches a device or supporting system with enough access to view, change, or disrupt operations.

3. Change trusted state

Passwords, addresses, configurations, project files, logic, or other trusted settings are changed or misused.

4. Degrade visibility or control

Operators lose monitoring, control, or confidence and must determine what remains safe to operate.

5. Protect the essential service

Teams isolate the affected path, preserve evidence, and use approved manual or fallback procedures.

6. Restore and validate

Teams restore known-good settings and access, verify changes, strengthen monitoring, and stage normal operations.

Operational Isolation and Recovery Decision Workflow

Figure 2. Operational Isolation and Recovery Decision Workflow

Decision Step

Required Outcome

1. Define the essential service

Confirm the service, minimum safe state, dependencies, and accountable incident authority.

2. Isolate the risky path

Separate affected OT and enabling systems at preplanned isolation points without unnecessary service loss.

3. Preserve evidence

Retain configurations, access logs, network records, change history, vendor activity, and operator observations.

4. Sustain operations

Use approved manual operations, local control, alternate communications, or other continuity procedures.

5. Restore trust

Restore known-good configurations, rotate credentials, validate communications and logic, and reconnect in stages.

6. Improve the system

Close root causes, update architecture and procedures, assign owners, and retest response and recovery.

Critical Infrastructure Cyber Resilience Maturity Model

Figure 3. Critical Infrastructure Cyber Resilience Maturity Model

Maturity

Operating Pattern

Leadership Priority

Reactive

Exposure and recovery dependencies emerge during an incident.

Identify vital services, exposed assets, owners, and isolation options.

Defined

Policies exist, but IT, OT, vendors, and continuity remain separate.

Standardize inventory, access, segmentation, monitoring, response, and recovery.

Connected

Cyber, operations, engineering, safety, vendors, and executives share evidence.

Use one resilience model around essential-service outcomes.

Measured

Exposure, access, isolation, recovery tests, and exceptions are measured by service.

Prioritize investment using operational impact and tested evidence.

Adaptive

Controls evolve from incidents, exercises, architecture changes, and threat intelligence.

Scale proven patterns and retest assumptions as dependencies change.

Governance and Decision Rights

Figure 4. Critical Infrastructure Cyber Resilience Governance Framework

Decision Stage

Accountable Owner

Required Evidence

Exit Criteria

Critical-Service Scope

Business / Operations Owner

Essential service, safe state, dependencies, impact tolerance, and fallback method.

Service priority and continuity requirements approved.

Architecture and Access

OT / Engineering / Security

Asset inventory, exposure, remote access, identities, segmentation, vendors, and change controls.

Material paths are owned and constrained.

Detection and Response

CISO / Incident Commander

OT telemetry, network records, change events, escalation criteria, isolation, and communications.

Detection, escalation, and containment tested.

Continuity and Recovery

Operations / Engineering Owner

Manual operations, backups, known-good configurations, recovery sequence, validation, and rollback.

Return-to-service evidence and authority recorded.

Improvement and Investment

Executive Risk Committee

Exercises, incidents, exceptions, corrective actions, regulatory duties, and investments.

Actions are funded, owned, and closed with evidence.

CyberTech Intelligence Critical Infrastructure Cyber Resilience Framework™

Eight operating layers connect essential-service purpose to reduced exposure, controlled access, observable operations, reliable isolation, trusted recovery, and evidence-led governance.

Figure 5. CyberTech Intelligence Critical Infrastructure Cyber Resilience Framework™ - Eight-Layer Architecture

Layer

Name

Operating Requirement

01

Know

Identify essential services, OT assets, owners, dependencies, remote connections, vendors, and minimum safe states.

02

Reduce Exposure

Remove unnecessary internet exposure, retire unused pathways, secure gateways, and eliminate insecure defaults.

03

Control Access

Use named identities, strong authentication where feasible, least privilege, time-limited vendor access, and rapid revocation.

04

Segment

Separate business IT, OT zones, safety functions, remote-access paths, and management networks by operational need.

05

Observe

Monitor access, configuration change, network behavior, privileged actions, and service conditions for reconstruction.

06

Isolate

Predefine and test graduated isolation so teams can contain a cyber path without improvising.

07

Recover

Maintain tested backups and known-good configurations, manual alternatives, integrity checks, and staged restoration.

08

Govern

Align cyber, operations, engineering, safety, legal, compliance, vendors, and executives around service continuity.

Critical Infrastructure Cyber Resilience Readiness Score™

Table. Critical Infrastructure Cyber Resilience Readiness Score™

Domain

Executive Assessment Question

Ready-State Evidence

Asset Visibility

Can leaders identify OT assets and support systems for each essential service?

Current inventory, owner, function, criticality, version, dependencies, and review evidence.

Internet Exposure

Are public-facing OT devices and services known, justified, and minimized?

Exposure inventory, approved exceptions, secure gateways, rules, and recurring verification.

Remote Access

Is every remote-access path attributable, approved, monitored, and revocable?

Named accounts, approved methods, strong authentication where feasible, limits, logs, and revocation tests.

Network Segmentation

Can compromise in business IT or one OT zone be contained?

Documented zones, conduits, access rules, third-party paths, diagrams, and isolation tests.

Identity and Privilege

Do users, services, and vendors have only required operational access?

Role-based access, unique credentials, privileged controls, reviews, and termination procedures.

OT Monitoring

Can teams detect and reconstruct unauthorized access or configuration change?

Network telemetry, device-change records, time synchronization, retention, alerts, and investigation procedures.

Response and Isolation

Can teams isolate an affected path without unmanaged operational risk?

Graduated isolation plan, decision rights, test evidence, alternate communications, and preserved forensic data.

Manual Operations and Continuity

Can essential service continue if remote connectivity or central monitoring is unavailable?

Manual/local procedures, trained operators, dependency map, alternate communications, and exercises.

Backup and Recovery

Are configurations, logic, and support data recoverable from trusted copies?

Versioned backups, change integration, restore tests, known-good baselines, validation, and rollback.

Third-Party Access

Are vendor connections and shared support paths governed as operational exposure?

Vendor inventory, contract controls, access windows, monitoring, notification, and offboarding evidence.

Executive Governance

Are operational cyber risks, exceptions, exercises, duties, and investments owned?

Risk register, service metrics, exception aging, exercises, corrective-action closure, and executive decisions.

How to Calculate the Score

Rate each domain from 0 to 4: 0 = absent; 1 = informal; 2 = documented; 3 = implemented and tested; 4 = measured and improved. Divide the total by 44 and multiply by 100. Bands: Critical (0-24%), Developing (25-49%), Defined (50-69%), Managed (70-84%), Adaptive (85-100%). This is a readiness aid, not a certification or incident prediction.

Continue the Critical Infrastructure Cyber Resilience Journey

Use this asset to review one essential service. Confirm its owner, vital OT assets, external paths, access, segmentation, monitoring, isolation, manual operation, recovery evidence, vendors, and executive risk decision. CyberTech Intelligence can facilitate an evidence-led resilience assessment.

About CyberTech Intelligence

CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education and decision support.

Research and Citation Governance

Sources are current through August 21, 2026 and are used within their stated scope. CyberTech Intelligence does not infer local exposure, unattributed actor identity, control effectiveness, or incident probability without organization-specific evidence. The framework and scorecard are decision aids, not external proof points.

References

[1] Federal Bureau of Investigation, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions,” July 30, 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions Accessed August 21, 2026. Relevance: Primary federal source for the July 27-30 water-sector incidents, affected PLC models, observed configuration changes, operational effects, and mitigations.

[2] U.S. Government Accountability Office, “Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector,” May 21, 2026. https://www.gao.gov/products/gao-26-109159 Accessed August 21, 2026. Relevance: Explains water-sector cyber risk, OT/internet connectivity, workforce and legacy-technology constraints, and federal risk-management gaps.

[3] U.S. Government Accountability Office, “Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements,” July 22, 2026. https://www.gao.gov/products/gao-26-108606 Accessed August 21, 2026. Relevance: Identifies 117 federal cybersecurity regulations across nine critical-infrastructure sectors and potential reporting overlap.

[4] U.S. Environmental Protection Agency, “Baseline Information on Malevolent Acts for Community Water Systems Version 3.0,” updated June 8, 2026. https://www.epa.gov/waterresilience/baseline-information-malevolent-acts-community-water-systems-version-30 Accessed August 21, 2026. Relevance: Provides scoped baseline information for water-system risk and resilience assessments and cautions that default likelihood ranges are only starting points.

[5] U.S. Environmental Protection Agency, “Cybersecurity Response,” updated July 22, 2026. https://www.epa.gov/cyberwater/cybersecurity-response Accessed August 21, 2026. Relevance: Maintains current federal water-sector cybersecurity alerts and response resources, including the updated joint PLC advisory.

[6] National Institute of Standards and Technology, “Cybersecurity for the Water and Wastewater Sector: Build Architecture,” June 24, 2026. https://csrc.nist.gov/News/2026/cyber-for-water-wastewater-sector Accessed August 21, 2026. Relevance: Explains the final NIST SP 1800-45 secure remote-access architecture for water and wastewater OT.

[7] North American Electric Reliability Corporation, “CIP-002-5.1a: BES Cyber System Categorization,” modified June 12, 2025. https://www.nerc.com/standards/reliability-standards/cip/cip-002-5.1a Accessed August 21, 2026. Relevance: Illustrates impact-based categorization of cyber systems in the Bulk Electric System.

[8] National Institute of Standards and Technology, “NIST SP 1800-41: Responding to and Recovering from a Cyber Attack,” May 21, 2026. https://csrc.nist.gov/pubs/sp/1800/41/ipd Accessed August 21, 2026. Relevance: Provides an evidence-based practice guide for response and recovery in manufacturing ICS environments.