Skip to main content

PRISM Cyber Program Members: Urgent Action Recommended for Internet-Connected Water and Wastewater Systems

PRISM was recently notified by our associates at the Cybersecurity and Infrastructure Security Agency (CISA) of increased targeting of programmable logic controllers (PLCs) in the water and wastewater sector by an unknown threat actor. We believe this information may be of interest to PRISM Cyber Program members, particularly those that operate or support water and wastewater systems.
Threat actors have affected multiple systems nationwide, including incidents with operational impacts. CISA recommends taking the following actions as soon as possible:

  • Identify internet-facing PLCs, operational technology, communications equipment, and remote-access systems, including cellular-connected sites.
  • R emove PLCs from direct internet exposure and secure connectivity through properly configured gateways and firewalls.
  • Confirm that all remote-access points use strong authentication and are not using default or missing passwords.
  • Pay particular attention to tanks, pump stations, and other remote or unmanned locations.
  • Review available logs for suspicious activity and the indicators of compromise included in the attached joint advisory.
  • Contact third-party operators, vendors, or system integrators to confirm they have implemented the recommended safeguards.
  • Review incident-response and system-isolation procedures so affected equipment can be contained safely if necessary.

Please see the linked updated joint cybersecurity advisory:

Please share this information internally with personnel responsible for water and wastewater operations, cybersecurity, information technology, operational technology, and emergency response.
More resources and assistance:

Organizations that identify suspicious activity or experience a cyber incident should activate their established incident-response procedures and report the activity through the appropriate channels above. 

You may also reach out to your Risk Control team at riskcontrol@gsrma.org.