CISA Urges Removal of Internet‑Exposed PLCs After Coordinated Attacks on 30+ Minnesota Water Utilities
What Happened — On July 26‑27, 2026 a coordinated cyber‑attack targeted the operational technology (OT) environments of more than 30 community water utilities in Minnesota. Attackers leveraged internet‑exposed programmable logic controllers (PLCs), changed passwords and IP addresses, and forced at least one plant offline, prompting boil‑water notices and manual‑operation fallback.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a control‑mapping gap: publicly reachable PLCs violate the “Logical Access” and “System Operations” criteria of SOC 2 CC6.2.
- Continuous evidence of OT asset inventory, network segmentation, and access‑control enforcement is essential to demonstrate due diligence during an audit.
- Verisq’s Control‑Mapping capability can automatically capture configuration changes and provide audit‑ready proof that critical OT assets are isolated from the internet.
Who Is Affected – Water and wastewater utilities (critical infrastructure), broader municipal services, and any organization that runs OT systems exposed to public networks.
Recommended Actions
- Conduct an immediate inventory of all PLCs and OT devices; verify that none have public IP addresses.
- Map the “Network Segmentation” and “Logical Access” SOC 2 controls to your OT environment and capture configuration snapshots as evidence.
- Deploy continuous monitoring to detect unauthorized changes to PLC credentials or network placement, and retain logs for audit review.
Technical Notes – The attackers exploited insecure exposure of PLCs (misconfiguration) rather than a software vulnerability. No CVE is cited; the impact was operational disruption and forced manual control of water treatment processes. Source: Security Affairs