OT / ICS · 2h ago
WaterISAC says this summer’s cyberattacks on water systems have clustered around the same weak points: internet-exposed operational technology, vulnerable programmable logic controllers (PLCs), insecure integrator connections, and weaker cyber hygiene at smaller utilities. Executive director Tom Dobbins told CyberScoop the pattern has pushed the center to speed up threat sharing across the sector.
The mechanism is straightforward: if attackers can reach an exposed OT system or slip in through a third-party integrator link, they can use that foothold to move into operational environments that were not built for internet exposure. WaterISAC is pairing that warning with a faster-sharing setup through Cyware and its National Rural Water Association reach to smaller utilities, because the exposure now looks shared rather than isolated.
For water and wastewater operators, the takeaway is that the risk sits in the connective tissue between sites and vendors, not just at any one plant. If a utility or its integrators keep remote access open to older control gear, one weak link can become a sector pivot.
2 sources covering this story
Cyware and WaterISAC announce partnership to deliver AI-powered threat intelligence to U.S.
WaterISAC reckons with range of threats after summer of cyberattacks
Tom Dobbins, executive director of the Water Information Sharing Analysis Center or WaterISAC, told CyberScoop, the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure connections through integrators and poor cyber hygiene at smaller utilities, which have pushed the center to make threat sharing faster across the sector.
Part of the PlainSec briefing for 2026-09-30