WIRED reported on August 1, 2026 that cyberattacks against water and wastewater systems have now reached at least seven U.S. states. The underlying FBI and EPA public service announcement says water utilities have reported attacks since July 27 against internet-facing programmable logic controllers, including Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 devices, and that some activity degraded water operations.
For most private businesses, the immediate lesson is not that they run a water plant. The lesson is that remote control access has quietly become part of everyday operations. Building controls, pump systems, gates, HVAC equipment, security panels, manufacturing equipment, lab systems, refrigeration, and vendor-managed field devices can all create a similar ownership problem when nobody has a current list of what is reachable from outside the network.
The Business Issue Is Exposure
The FBI and EPA advisory describes attackers remotely accessing exposed devices, changing IP addresses and passwords, and causing a loss of monitoring or control. That is a technical sentence with a very practical business meaning: an outside party may be able to lock operators out of equipment that keeps a facility running.
For New Jersey business owners and operators, internet-facing PLC risk belongs in the same conversation as insurance, vendor contracts, emergency response, and business continuity. If a vendor, installer, maintenance company, or internal team says remote access is needed, the owner should understand what is exposed, why it is exposed, and what protects it.
What Owners Should Ask
- Which control devices are reachable from the internet? Ask for a plain inventory that includes PLCs, building controls, remote modems, gateways, HMIs, security panels, and vendor-managed devices.
- Who owns each remote-access path? Identify whether access is managed by the business, an MSP, a facilities vendor, an equipment installer, or a manufacturer support team.
- Are shared or default passwords still in use? Control systems often stay in place for years. Password practices that seemed acceptable during installation may not be acceptable now.
- Can remote access be brokered instead of directly exposed? The FBI and EPA recommend removing direct internet exposure and using controlled access paths such as secure gateways, monitored VPNs, or other mediated architectures.
- Can the business operate manually? If monitoring, automation, or remote control fails, the business needs a documented fallback that real staff have practiced.
- Which devices are unsupported or near end of life? Unsupported operational equipment can become a recurring target because patches and vendor support may no longer be available.
Vendor Answers Need Evidence
A reassuring answer is not the same as proof. If a provider says a control system is secure, ask for evidence that the device is not directly exposed, that access is logged, that unique credentials are enforced, and that backups or known-good configurations exist. For equipment that supports physical or software key switches, ask whether operating modes are documented and reviewed after maintenance.
This is also a contract issue. A service agreement for controls, facilities equipment, or specialized machinery should say who is responsible for remote access, incident notification, backups, firmware support, and recovery. If the agreement only says the vendor can connect remotely when needed, it may leave the owner holding the operational risk without enough visibility.
A Practical Next Step
Start with one meeting that includes IT, facilities, operations, and any outside provider that manages equipment. Build a short list of internet-connected control systems and rank them by business impact. A pump, door system, production controller, medical refrigerator, camera platform, or HVAC controller may deserve more attention than another dashboard license.
Then decide what can be removed from direct internet exposure, what needs stronger authentication, what requires logging, and what should be replaced or isolated because it is too old to support safely. The goal is not to turn every owner into a control-system engineer. The goal is to make sure someone can answer the basic business question before pressure builds: if this remote system stops responding, who knows how to keep the operation running?
Sources and further reading
- Security News This Week: 7 States' Water Systems Hit by Cyberattacks Likely Tied to Iran
- Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions
- US authorities see 'significant escalation' in attacks on water system devices