Locked out of your own control systems? 
How prepared is your production environment?

In just two days, more than 30 water utilities in Minnesota were attacked. The attackers changed the controllers' passwords and IP addresses, locking the operators out of their systems. What would a similar attack mean for a manufacturing operation?


What happens when access is suddenly lost?

In late July 2026, attackers gained access to remote monitoring and control systems at several Minnesota water utilities. The attackers targeted the programmable logic controllers (PLCs) used to monitor and control physical processes.

Some operators had to switch to manual procedures. In one community, both the water and wastewater treatment facilities temporarily ceased operations. According to authorities, the quality of drinking water in Minnesota was not affected.

However, similar attacks in other U.S. states resulted in loss of water pressure, flooding, extended manual operations, and boil-water advisories. In response, CISA warned the Water and Wastewater Systems Sector about attacks targeting internet-accessible controllers.
 

Four Questions Manufacturers Should Be Able to Answer

This incident is relevant not only to water utilities. Manufacturers also rely on PLCs, HMIs, robots, and SCADA systems to control their operations. If programs or configurations are manipulated, preparation determines how quickly an organization can respond.

Manufacturers should be able to answer the following four key questions:

  1. Do we know which OT components could be affected?
    Device type, manufacturer, firmware version, location, and known vulnerabilities must be visible. Unknown or outdated components make it more difficult to assess risk and respond to an attack.
  2. Can we identify what changed? 
    Operations teams need to determine when a change occurred, which programs or parameters were affected, and whether the change was authorized.
  3. Do we have a current backup for every critical device?
    A backup is only useful if it is current, was completed successfully, and can be clearly matched to the correct device.
  4. Can we quickly restore the last known good state? 
    In an incident, a validated version must be readily available. Without it, teams must search manually, which disrupts or stops production.

A robust recovery strategy does not begin after an attack. Manufacturers need visibility into their OT environments, the ability to identify risks early and trace changes, and a reliable process for regularly backing up critical programs and configurations.

The recent attacks in the United States provide a clear reason to assess your current readiness. How many of the following questions could your organization answer within minutes today?

Learn how to track changes across your OT environment and restore known good states.

Sources: CISA Alert Issued July 30, 2026 and Reuters Coverage of the Attacks on U.S. Water Utilities