
When most people hear the word “cyberattack,” they picture stolen passwords, compromised email accounts, ransomware or exposed customer data. But what happens when a cyberattack reaches beyond a computer screen and affects the systems that keep physical operations running? Minnesota got a firsthand look at that risk this summer.
On July 26 and 27, a coordinated cyberattack targeted operational technology at more than 30 community water systems across the state. According to Minnesota IT Services (MNIT), most confirmed incidents involved technology used to remotely monitor and control equipment.
The impact varied by community. In Braham, the city’s well and water treatment plant temporarily went offline after attackers disrupted the computerized operating controls. In Plymouth, communications with water towers and lift stations were affected, requiring crews to rely on manual procedures while automated systems were unavailable. Other communities reported disruptions to automated controls as well. Officials reported no impact to water quality.
The incident is an important reminder of something organizations across industries need to understand: Cybersecurity and physical operations are no longer separate conversations.
When Digital Systems Control Physical Operations
Many organizations rely on operational technology, or OT, to monitor and control equipment and physical processes. Depending on the organization, those systems might manage pumps, manufacturing equipment, building controls, utilities, environmental systems or other critical operations. Connecting these systems can create enormous efficiencies. Employees can monitor equipment remotely, automate processes and identify problems faster. This type of connectivity can also create another path into the organization.
The Minnesota water-system attacks demonstrated what that can look like. In some affected communities, the issue wasn’t stolen customer information or a compromised email account. Technology responsible for monitoring or controlling physical equipment was disrupted.
The attacks weren’t limited to Minnesota. Since July 27, water and wastewater utilities in at least seven states have reported incidents involving malicious cyber activity targeting operational technology, according to the FBI and EPA. In response, federal authorities have urged critical infrastructure operators to remove unnecessary public internet exposure, secure remote access and maintain the ability to operate critical systems manually during an incident.
That last point is particularly important. When technology stops working, can your organization continue operating?
Critical Infrastructure Is Bigger Than Water Systems
Water utilities are an obvious example of critical infrastructure, but the underlying lesson applies much more broadly. Manufacturing facilities depend on connected production equipment. Healthcare organizations rely on building systems and medical technology. Commercial properties use connected access controls, HVAC systems, elevators, cameras and life-safety equipment. Transportation, energy and government operations increasingly rely on remotely accessible technology as well.
Even organizations that don’t consider themselves part of “critical infrastructure” may have systems where a cyber incident could quickly become an operational issue. That’s why cybersecurity assessments shouldn’t stop with email, laptops, servers and traditional IT networks. Organizations also need to understand what is connected, who can access it and what happens if it becomes unavailable.
Questions Every Organization Should Be Asking
You don’t need to operate a water treatment facility to learn from what happened in Minnesota. Start with some basic questions:
- What operational systems are connected to our network or accessible through the internet?
- Which systems can be accessed remotely, and by whom?
- Are default, shared or outdated credentials still being used anywhere?
- Are critical systems appropriately separated from the rest of the network?
- Do third-party vendors have remote access to any of these systems?
- How quickly would we know if someone gained unauthorized access?
- If an automated system stopped working tomorrow, could we continue operating manually?
- Does our incident-response plan address both the cybersecurity issue and the operational consequences?
The answers may involve multiple teams. IT may understand the network, facilities may understand the equipment, a third-party vendor may maintain the system, and leadership may own the emergency-response plan. The problem is that an attacker doesn’t care where one department’s responsibility ends and another begins.
Preparation Matters Before an Incident Happens
One of the more important lessons from the Minnesota attacks wasn’t simply that systems were targeted. It was what happened next. Affected communities isolated systems, shifted to manual procedures and coordinated with local, state and federal partners to keep essential services operating. Minnesota activated a statewide cybersecurity response to help communities contain the activity, investigate what happened and restore normal operations.
It’s a point 360 Security Services CTO Eric Ebner has emphasized when discussing cybersecurity resilience. Prevention matters, but organizations also need to plan for what happens if an attacker does get through. Can the affected systems be isolated quickly? Can the organization contain the incident? And can critical operations continue while systems are being restored? Those capabilities don’t appear overnight.
Organizations need to understand their vulnerabilities before an incident occurs, establish clear response procedures and determine how critical operations will continue if technology becomes unavailable. That can include vulnerability assessments, network segmentation, stronger access controls, monitoring, tested backups, incident-response planning and exercises that bring together the people responsible for both technology and physical operations.
The goal isn’t simply to prevent every possible attack. It’s to make sure one compromised system doesn’t have the ability to bring an entire operation to a halt.
Cybersecurity Doesn’t Always Stay Behind a Screen
The Minnesota water-system attacks provide a timely example of how interconnected our digital and physical environments have become. A compromised system can affect more than data. It can interrupt operations, disable equipment, require emergency procedures and potentially affect the people and communities that depend on those systems.
Organizations should be asking not only “How do we keep attackers out?” They should also be asking: “If someone gets in, what could they affect, and are we prepared to keep operating?” Understanding that answer before an incident occurs can make the difference between a cybersecurity event and a much larger operational crisis.
At 360 Security Services, we help organizations identify vulnerabilities before they become incidents and build plans to protect the systems, operations, and people they rely on. From cybersecurity and vulnerability assessments to penetration testing and incident response planning, out team can help you understand where your risks are and what to do about them. Not sure where your organization is most vulnerable? Let’s talk.
