(CS)²AI Seminar™: Comparing OT Security Perimeters in Defensible Architecture
4 attendees from 112 groups hosting
Details
In late July 2026, attackers reached into water and wastewater utilities in at least 12 US states. They exploited internet-exposed programmable logic controllers (PLCs), including Allen-Bradley MicroLogix 1100/1400, Schneider Modicon M340, and Siemens S7-1200 units. The attackers changed IP addresses and passwords to lock operators out of monitoring and control. In some cases they altered ladder logic in PLC project files. Utilities reported pressure loss and localized flooding, and operators had to fall back to manual operations. On July 30 the FBI and EPA issued a joint alert, and an Iran-linked group claimed responsibility.
The campaign follows a pattern that is years in the making. In 2023, CyberAv3ngers defaced Unitronics controllers at the Municipal Water Authority of Aliquippa. In 2024, American Water, the largest regulated U.S. water utility, was hit by a cyberattack, and Arkansas City switched to manual operations after an incident. In 2025, Poland reported ICS intrusions at five water treatment plants. The attack surface hasn't changed much in that time. It is still exposed PLCs and HMIs, default or shared credentials, integrator-managed remote access, and small utilities with few security staff.
This session looks at the technical side:
- How attackers find and take over exposed controllers
- What the attacks do at the logic and network layers
- Which defensive measures work: removing direct internet exposure, segmenting control networks behind secure gateways, strict access control lists, locking PLCs against unauthorized logic changes with key switches, verifying project file integrity, monitoring for configuration changes, and keeping manual operation ready
- How the federal response and the push for water-sector security standards may shape utility obligations in the months ahead.
Registration for this free event is open now!
---------------------------------------------------------
Becoming a paid member is quick and easy (and helps us keep offering free educational opportunities!). Please join now! https://www.cs2ai.org/plans-pricing
All past seminars and symposiums are available to paid CS2AI.ORG members. Check out the Resources area of our website in the Members Portal https://www.cs2ai.org/
Certificates for Professional Development/Continuing Education Units (PDUs/CEUs) are available for all registered individuals who attend at least one hour of the event. https://www.cs2ai.org/get-involved
*Please note that (CS)²AI Online™ events are provided free of charge as educational career development content through the support of our paid members and the generous contributions of our corporate Strategic Alliance Partners. Contact information used in registering for our directly supported seminars may be shared with sponsors funding those specific events. Unless noted on our Zoom Event registration page, all events are open for direct funding support.
© Control System Cyber Security Association International 2026




