A Technical Response from our CTO on the Recent Cybersecurity Attacks on Water Systems
Waterly supports the recommendations issued by the National Rural Water Association (NRWA) in its recent advisory on cyberattacks affecting U.S. water systems (https://content.nrwa.org/cybersecurity/news/15831227/recent-cyber-attacks-on-us-water-systems), as well as guidance from the FBI, EPA, CISA, and their federal partners to remove programmable logic controllers, cellular modems, and other operational technology devices from direct public internet exposure.
The recent attacks demonstrate the danger of configurations in which attackers can directly discover and communicate with PLCs or field devices over publicly accessible industrial protocols, management interfaces, or remote-access ports. The appropriate response is not to eliminate cellular or Ethernet connectivity altogether, but to deploy connectivity through properly isolated, hardened, and monitored architectures.
Waterly does not require a utility to expose its PLCs to the public internet, assign public IP addresses to control equipment, configure inbound port forwarding, or permit unsolicited inbound connections through its OT firewall.
Waterly-supported connectivity is designed around an outbound-initiated, brokered, or privately routed model depending on the deployment architecture:
In ethernet-based deployments, an on-premises industrial gateway establishes encrypted outbound connections to approved cloud services. The connection is initiated from inside the utility network, and no inbound internet connection is required to reach the OT environment. The on-premises device initiates an outbound encrypted tunnel to a trusted intermediary service. That service brokers connectivity between authorized users and the site without requiring direct public exposure of PLCs or inbound port forwarding at the utility. Access is established only through authenticated sessions over the brokered channel.
In cellular-based deployments, communications are carried over either a private, carrier-managed network segment that isolates traffic from the public internet, or a secured VPN protocol that creates a virtual private network segment that is also isolated from the public internet. This approach avoids placing field devices or control equipment on publicly addressable networks and instead routes traffic through a controlled cellular environment with defined security boundaries.
In sites choosing to use scripted operations without an on-site hardware device, the scripts operate purely in an outbound fashion, over a secured channel to deliver field telemetry directly to Waterly’s secured environment.
These approaches are consistent with current federal guidance. The FBI, EPA, CISA, and partner agencies specifically recommend eliminating inbound exposure, using secure gateways to broker access, and adopting isolated or segmented connectivity models such as private cellular networks, zero-trust access architectures, and VPN-based or SD-WAN-based segmentation.
Cellular and remote connectivity must nevertheless be treated as external connectivity and secured accordingly. A private cellular network or outbound-initiated tunnel is an important layer of protection, but it does not replace core security practices such as device hardening, authentication, network segmentation, monitoring, and lifecycle management.
Waterly recommends that every deployment incorporate the following controls:
Place connectivity gateways in a dedicated OT segment, industrial DMZ, or similarly controlled network zone, with access limited to only the PLCs, protocols, and endpoints required for the integration.
Restrict outbound communications to approved destinations, protocols, and ports. Disable unused services, management interfaces, industrial protocols, and remote-access capabilities that are not explicitly required.
Configure integrations for telemetry-only operation wherever remote control or remote programming is not operationally necessary.
Where remote maintenance is enabled, enforce least-privilege access, multifactor authentication, individually assigned user accounts, and full audit logging, with the ability to disable remote access when not in use.
Maintain current supported firmware on all gateways and connectivity devices, replace unsupported equipment, eliminate default credentials, and enforce unique credentials per installation.
Enable and retain logs from gateways, authentication systems, and connectivity services, and regularly review them for anomalous or unauthorized activity.
Maintain tested procedures for safely disconnecting external connectivity while preserving local operational control of treatment processes.
Waterly will continue working with utilities, integrators, and connectivity providers to ensure deployed architectures align with evolving federal cybersecurity guidance. Customers should contact Waterly or their control-system integrator if there is any uncertainty about whether a device, gateway, or remote-access pathway is externally reachable or properly segmented.