Introduction
America's Water Infrastructure Act of 2018 (AWIA) requires all community water systems serving more than 3,300 people to conduct risk and resilience assessments that explicitly include cybersecurity evaluations of their operational technology (OT) systems. For instrumentation and SCADA teams, this means critically examining the security posture of field devices, communication protocols, remote access configurations, and vendor connections — many of which were designed and installed long before cybersecurity was a design consideration.
The water sector has become an increasingly attractive target for cyber threats. High-profile incidents — including the 2021 Oldsmar, Florida water treatment plant breach, where an attacker attempted to increase sodium hydroxide levels to dangerous concentrations — have demonstrated that OT cybersecurity in water utilities is not a theoretical concern but an operational imperative. CISA, the FBI, and EPA have issued joint advisories specifically addressing threats to water and wastewater systems.
For utilities and their engineering partners, the challenge is practical: how do you assess and improve the cybersecurity posture of instrumentation and SCADA systems without disrupting the real-time process control functions that keep water safe and treatment compliant?
Understanding the OT Attack Surface
The OT attack surface in a modern water utility extends far beyond the SCADA server room. Every network-connected device — PLCs, RTUs, flow meters with Ethernet ports, cellular modems, cloud-connected analyzers, remote access gateways, and even smart valve actuators — represents a potential entry point for attackers. The expansion of IoT-connected instrumentation and cloud-based analytics platforms has dramatically increased the number of network endpoints that must be secured.
Common attack vectors in water utility OT environments include phishing and social engineering attacks that compromise credentials used for remote SCADA access, exploitation of unpatched vulnerabilities in HMI software, operating systems, and PLC firmware, lateral movement from compromised IT networks into inadequately segmented OT networks, manipulation of unsecured communication protocols such as Modbus TCP and DNP3 that transmit data in plaintext, and supply chain attacks through compromised vendor remote access connections or software updates.
The Practical Cybersecurity Checklist
A structured OT cybersecurity assessment for instrumentation and SCADA systems should systematically evaluate several critical domains.
Network architecture and segmentation is foundational. OT networks should be physically or logically separated from business IT networks using firewalls and demilitarized zones (DMZs). Instrument networks carrying process data should be segmented from SCADA control networks. Network diagrams should be current and include all connected devices, communication paths, and access points.
Communication protocol security requires attention to legacy protocols. Modbus TCP, BACnet, and older DNP3 implementations transmit data without encryption or authentication. Where encrypted alternatives exist — such as Modbus/TCP over TLS, secure DNP3 (SA), or OPC-UA with certificate-based authentication — they should be implemented. Where legacy protocols must remain, network segmentation and monitoring provide compensating controls.
Remote access management is often the weakest link. Every remote access pathway — vendor VPN connections, operator mobile access, cellular modem dial-in — should require multi-factor authentication, session logging, and time-limited access grants. Default credentials on remote access gateways must be changed, and unused remote access services should be disabled.
Field device hardening includes changing default passwords on PLCs, RTUs, and smart instruments, disabling unused communication ports and services, implementing firmware update procedures that verify update integrity, and maintaining an inventory of all field devices with firmware versions and known vulnerabilities.
Vendor access management requires clear policies governing how instrumentation vendors connect to utility OT systems for support, configuration, and troubleshooting. Vendor access should be monitored, logged, and time-limited. Utilities should understand and document all vendor remote access pathways and ensure they meet the utility's security requirements.
Incident Response for Instrumentation Systems
Cybersecurity incidents affecting instrumentation systems require specialized response procedures that account for the real-time process control implications. Unlike IT incidents where systems can be taken offline for investigation and remediation, OT incidents must be managed while maintaining continuous water treatment and distribution operations.
Incident response plans should include procedures for identifying compromised instruments or controllers, isolating affected devices without disrupting process control, switching to manual operation modes for critical treatment processes, preserving forensic evidence from affected devices and network logs, and restoring systems from known-good configurations and firmware images.
How Emergent Energy Can Help
At Emergent Energy, cybersecurity is integral to our SCADA integration methodology. We design instrumentation networks with defense-in-depth principles from the outset — not as an afterthought. Our OT cybersecurity services include instrument network architecture review and segmentation recommendations, SCADA communication protocol security assessment, remote access configuration auditing and hardening, field device inventory and vulnerability assessment, secure SCADA integration design for new instrumentation projects, and documentation supporting AWIA compliance reporting.
We work with utilities and their IT/OT teams to ensure that new instrumentation installations strengthen — rather than compromise — the overall security posture of the OT environment. Contact us at 215-645-7141 or visit emergentenergy.us/contact to discuss OT cybersecurity assessment for your utility.
