← All posts

The Equipment Nobody Wrote Down

Over two days in late July, someone went after the control systems at more than 30 community water utilities across Minnesota at once.

Not one utility. More than thirty, coordinated, on a Sunday and a Monday.

Operators in several towns lost automated control and fell back to running equipment by hand. In Braham, the intrusion briefly knocked out controls for the city's well and water treatment plant. Minnesota IT Services confirmed the attack on July 28 and activated a statewide response alongside the state Fusion Center, the Department of Health, CISA, the EPA, and the FBI. Four cities have spoken publicly — Braham, Plymouth, South St. Paul, and Maple Plain — and all of them told residents the drinking water remained safe.

No one has been formally blamed. Investigators suspect an Iran-aligned group, according to reporting in the New York Times and Wired, and researchers at Tenable have pointed to the group CyberAv3ngers based on the pattern of targeting. That attribution is unconfirmed, and for the purposes of this post it doesn't matter much.

What matters is a single sentence CISA published two days later.

The Sentence

On July 30, CISA issued an alert to the entire water sector warning of a significant increase in attackers targeting programmable logic controllers — the small computers that open valves, run pumps, and dose chemicals. Attackers were changing PLC passwords to lock operators out, and changing IP addresses to cut the devices off from the people who run them. Nationally, CISA said, this activity has produced boil water notices and long stretches of manual operation.

Then CISA said something aimed squarely at organizations that consider themselves mature.

Validate your external connections — because the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.

Translate that out of government English.

A vendor installed a modem. It has its own path to the internet through a cell carrier. It isn't on the network diagram. It isn't in the asset inventory. And when the security team ran their external scan, it didn't appear — because the scan looks at company IP space, and this device never touches company IP space.

The organization was scanning a map of a building it doesn't fully own.

This Is Not a Water Story

Every executive reading this should stop filing the water sector under somebody else's problem, because the pattern is industry-agnostic.

The equipment manufacturer that monitors your production line remotely. The mechanical contractor who dials into building HVAC. The vendor who supports your backup generators, your fuel monitoring, your cold storage, your elevators, your badge readers. Somewhere in a facility your company owns, a piece of equipment has a connection your CISO's tooling cannot see, installed by a third party during a project that closed years ago.

In my experience, this is the most common gap between what a board believes it has secured and what it has actually secured. Not a missed patch. An asset nobody knew existed.

The First Question Does the Most Work

In Cyber Risk Is Business Risk, I put three questions in front of executives: What do we have? How are we protecting it? What happens when something goes wrong?

Most organizations rush past the first one because it sounds administrative. It isn't. It's the question that determines whether the other two mean anything at all.

What do we have? If a vendor can install internet-connected equipment on your property without it ever appearing in an inventory, your asset management program has a hole shaped exactly like the attack CISA is describing. Contract language is part of the control here, not just technology. What does your standard vendor agreement say about connectivity installed on your premises?

How are we protecting it? CISA's guidance to water utilities is three steps, and they translate directly to a factory floor: take the controller off the public internet and route remote access through a VPN or gateway device; enable password protection and replace default credentials; allowlist the specific machines permitted to connect. CISA also advised keeping a known-clean backup of the controller image — because when an attacker changes the password, restoring from backup is the recovery path.

What happens when something goes wrong? Minnesota's answer was that operators ran the plants by hand, and it worked. It worked because water utilities still employ people who know how to do that. Ask whether your operation can run degraded, for how long, and whether anyone has practiced it in the past year. Two days after the Minnesota attacks, CISA joined counterparts in Australia, the UK, and Canada to publish CI Fortify — guidance built entirely around that question.

Four Days

CISA updated advisory AA26-097A on July 22. The update expanded the list of targeted control systems beyond Rockwell Automation's Allen-Bradley controllers to include Schneider Electric and Siemens equipment.

The Minnesota attacks began July 26.

Four days.

I don't raise that to blame anyone in Minnesota. I raise it because the interval between a public warning and a live attack keeps shrinking, and most organizations have no defined path for turning a government advisory into action inside a week. Advisories arrive, get forwarded, and wait for the next change window.

What to Ask Your CISO This Week

"Can we produce a list of every internet-connected device on our property that a vendor or contractor installed?" If the honest answer is no, that is the finding. Follow it with the only two questions that matter next: what would it take to build one, and by when.

"When CISA or a major vendor publishes an urgent advisory, what happens in the next 72 hours, and who decides?" You are listening for a named owner and a defined path — not a distribution list.

"If our operational systems went down tomorrow, could we run manually, and when did we last prove it?" Minnesota's utilities stayed in service on exactly that capability.

The Part That Should Stay With You

This attack involved no stolen data, no extortion note, and no payment demand. It involved changing passwords and IP addresses on equipment that should never have been reachable in the first place.

That is a cheap attack. It scales. And it worked against more than thirty organizations in a single weekend because the same blind spot existed in all of them.

Your asset inventory is a security control. Fund it like one.