On July 26 and 27, a coordinated cyberattack targeted operational technology at more than 30 community water systems across Minnesota. Minnesota IT Services immediately activated the state’s cybersecurity incident-response capabilities and began collaborating with federal, state, local, Tribal, and private-sector partners.
No water-quality impacts were reported, and the incidents did not cause a sustained statewide disruption. But that does not mean they were harmless.
In Braham, attackers reportedly shut down operating controls associated with the city’s well and water treatment plant. The community temporarily depended on water already stored in its tower, and residents were asked to minimize water use while the city investigated.
The response worked. Essential services continued, and state and federal resources were mobilized. That is the outcome everyone wanted.
A Government Readiness Challenge
But a campaign capable of reaching dozens of water systems in 48 hours is not simply a utility security issue. It is a test of whether government can protect a basic public service when responsibility is distributed across small towns, counties, cities, state agencies, and private operators.
Water is unforgiving infrastructure. A payroll outage creates delays. A compromised water system can affect treatment, pumping, pressure, chemical processes, and public confidence.
Too many public-sector security programs still treat operational technology as a strange corner of IT: old equipment, difficult patching, unclear ownership, and risks documented during an annual assessment. That approach is failing.
OT Security is About What Attackers Can Control
OT controls physical processes. When an attacker reaches a human-machine interface, programmable logic controller, engineering workstation, or remote monitoring system, the concern is not merely what data can be stolen.
The concern is what the attacker can change, stop, or manipulate.
Zero Trust for OT Starts with Limiting What Attackers Can Touch
Government leaders must stop asking whether they can build a wall high enough to keep every attacker out. They cannot.
The better question is: After an attacker gets in, what are they allowed to touch?
That is the heart of zero trust in an OT environment. It is not a product purchase. It is a design choice.
A contractor entering a water facility would not receive a master key to every control room, electrical panel, chemical storage area, and office. The contractor’s identity would be verified, access would be limited to a specific location and task, and the organization would know what work was performed.
Every digital connection to an OT environment should follow the same principle. It should be verified, narrowly authorized, continuously observable, and removable without disrupting the physical process.
Yet many OT environments still provide the digital equivalent of a master key. Vendor accounts remain active after engagements end. Remote-access tools reach further than necessary. Shared credentials rarely change. Browser-based HMIs remain exposed to the internet.
EPA and CISA recommend inventorying exposed systems, removing HMIs from the public internet where possible, changing default credentials, requiring multifactor authentication, controlling remote access, logging activity, and monitoring unusual login attempts.
These recommendations are not theoretical. In October 2024, Censys identified nearly 400 internet-exposed web interfaces associated with U.S. water facilities. Forty were reportedly unauthenticated and capable of accepting control inputs.
Five Requirements for Government OT Resilience
Government leaders should require five things from organizations responsible for essential services:
- Continuous visibility into OT assets and internet exposure
- Controlled, identity-based remote access
- Tested manual operations and restoration procedures
- Clear escalation and mutual-aid arrangements
- Shared security services that smaller organizations can realistically use
A useful OT inventory must show more than device names. It should identify what each asset does, what process it supports, what it communicates with, who can access it, whether it is externally exposed, and what normal behavior looks like.
Recovery Has to Work Before an Incident Happens
Recovery is equally important. Organizations must know whether they can operate safely without automation, who can authorize a shift to manual operations, and whether controller logic, configurations, and engineering documentation can actually be restored.
A backup that has never been restored is a hope, not a recovery plan.
Smaller utilities cannot maintain the same cybersecurity staff and OT expertise as a large enterprise. They should not be expected to go it alone. Shared services, mutual-aid agreements, trusted response partners, and clear 2:00 a.m. escalation procedures are essential.
Minnesota’s water systems were the immediate targets. Government readiness was the larger test.
Cyber resilience is no longer separate from delivering safe and reliable public services. It is part of the service.



