TL;DR: A wave of suspected Iran-linked attacks on U.S. water utility OT systems exposed how internet-facing PLCs, weak segmentation, and slow manual response still turn routine compromise into operational disruption, according to Swimlane. The real control gap is not awareness but dwell time, because containment and proof of remediation often lag far behind attacker access.
At a glance
What this is: This analysis explains why recent water utility attacks succeeded against operational technology and why response speed now determines whether compromise stays limited or becomes an operational incident.
Why it matters: It matters to IAM and security teams because OT environments still depend on access controls, privilege boundaries, and response workflows that must be adapted for systems that cannot tolerate the same controls as IT.
👉 Read Swimlane's analysis of recent water utility OT attacks and response gaps
Context
Water utility OT attacks show how fragile legacy operational environments become once internet exposure, small security teams, and physical process control intersect. In OT, the security problem is not just unauthorized access, but how quickly a compromise can translate into loss of control over pumps, valves, and pressure systems. For practitioners, this is a classic access-control and response-governance problem, not only a monitoring problem.
The identity angle is real even when the article is about industrial systems. Default passwords, weak least privilege, and direct access paths all create the same governance failures seen in broader IAM and NHI programmes: too much standing access, too little segmentation, and no reliable way to prove who changed what before damage spreads. That pattern is now typical across critical infrastructure, not an edge case.
Key questions
Q: What breaks when PLCs are exposed directly to the Internet?
A: Direct exposure removes the safety margin that OT segmentation is supposed to provide. Attackers can probe controllers, identify common ports, and interact with engineering interfaces without first compromising an internal foothold. Once that happens, remote access, project-file theft, and logic manipulation become much easier to automate and hide.
Q: Why does slow OT incident response increase operational risk?
A: Slow OT response increases risk because every extra step between detection and containment gives the attacker more time to interfere with control systems, preserve access, or force manual workarounds. In OT, that can affect availability and physical stability, not just data confidentiality. The longer the dwell time, the harder it becomes to trust that the environment is clean.
Q: How should utilities harden remote access to legacy control systems?
A: Utilities should route remote access through jump boxes, segmented administrative paths, and gateways that can enforce authentication, logging, and approval. Direct connections to legacy systems create broad trust where the equipment cannot defend itself. If the system cannot support modern controls, the access path has to carry the security burden instead.
Q: What should teams do when OT and IT security ownership is split?
A: Teams should create a shared access and response model with named ownership for every path that can reach operational systems. OT, IAM, and incident response functions need the same visibility into sessions, approvals, and containment steps. Without that shared accountability, response gaps appear exactly when a fast decision is most needed.
Technical breakdown
Internet-facing PLCs create a direct control-plane exposure
Programmable logic controllers, or PLCs, are the industrial devices that execute physical commands in OT environments. When they are reachable from the public internet, the attacker does not need to defeat a user workstation first. They can target the device that actually opens valves, runs pumps, and holds pressure steady. In older environments, these systems were often deployed before modern authentication, segmentation, or logging expectations existed, which makes them hard to protect with standard IT controls.
Practical implication: keep PLCs off the public internet and force all remote access through controlled jump paths and firewalled gateways.
Manual incident response becomes the real bottleneck in OT
The article’s central operational point is that hygiene alone does not end an incident. In OT, response usually means isolation, failover decisions, evidence preservation, approval steps, and regulator-ready documentation. Those steps are slow even when the team is well staffed. In a live attack, long decision chains create dwell time, the period between initial compromise and actual removal, and that interval often determines how much damage the attacker can do.
Practical implication: pre-encode isolation and failover playbooks so containment can be executed consistently under pressure.
Least privilege must be adapted to equipment that predates it
The article shows why legacy OT systems rarely map cleanly to modern access models. Multi-factor authentication, least privilege, and configuration review are still relevant, but they must be applied through the gateways, firewalls, and administrative paths that the equipment can support. Where direct connections remain, the security model effectively grants broad trust to any operator or remote session with reach into the control plane, which is exactly the condition adversaries exploit.
Practical implication: treat OT access as a privilege boundary problem and review every path that bypasses segmentation or shared access controls.
Threat narrative
Attacker objective: The objective is to interrupt or manipulate water utility operations by taking control of exposed industrial systems and degrading operator response.
- Entry occurred through internet-facing PLCs that were reachable from outside the utility environment.
- Escalation followed once operators were locked out or forced onto manual control, giving the attacker control over the operational workflow.
- Impact was limited in most cases, but the campaign still disrupted utilities and exposed how quickly OT access can become physical operational risk.
NHI Mgmt Group analysis
Legacy OT identity is a governance gap, not just an engineering inconvenience. Water utilities are seeing the same access-control failure modes that have long affected NHI programmes: exposed credentials, direct trust paths, and little visibility into who can reach critical systems. The article shows that older PLC environments still rely on access assumptions that no modern security model would tolerate. Practitioners should treat OT access as privileged identity governance, not as a separate exception.
The 52 NHI breaches Report helps explain why standing access is so dangerous. The pattern across identity incidents is consistent: the longer access persists, the more likely an attacker can exploit it before controls respond. In OT, the same logic applies to remote sessions, engineering accounts, and administrative pathways that remain valid long after the immediate task is done. The conclusion is straightforward for practitioners: shorten exposure windows wherever OT architecture allows it.
Dwell time is the named concept this campaign sharpens for critical infrastructure teams. Security leaders often focus on prevention, but the article makes clear that the time between compromise and removal is what determines whether a utility stays resilient. OT teams need to measure how long it takes to isolate, fail over, and verify cleanup, because those steps are now part of the security control stack. For practitioners, incident speed is a control, not just an outcome.
Automation is becoming a compensating control for slow human response. The article does not argue that automation replaces segmentation or password hygiene. It argues that manual incident handling is too slow for contested OT environments with small teams. That is a governance signal as much as a tooling one: if your response process cannot be executed consistently at 2 a.m., the environment is already under-protected. Practitioners should evaluate where automation can enforce playbooks, preserve evidence, and compress containment time.
Critical infrastructure security is converging with identity discipline. Even when the asset is a PLC, the attack succeeds through trust, access, and control boundaries. That means OT, IAM, and PAM teams need shared visibility into who can reach what, under what conditions, and with what approval trail. For practitioners, the future state is not separate OT and identity governance, but a single access model that understands operational risk.
What this signals
Legacy OT programmes are now being judged by identity-era standards. The practical question is no longer whether a device is old, but whether its access paths can be governed, reviewed, and revoked with enough speed to matter. That is the same governance pressure driving NHI programmes, just applied to physical operations. For readers running mixed IT and OT estates, the planning assumption should be that every exposed control path will eventually be tested.
Response automation is becoming part of the security architecture, not a convenience layer. When the article describes thirty-step response processes, it is really describing a control that humans cannot reliably execute under stress. Utilities and other critical infrastructure teams should prepare for automation that enforces playbooks, logs actions, and accelerates remediation verification. That shift matters because dwell time is now a measurable resilience variable, not an abstract SOC metric.
For practitioners
- Remove public internet exposure from control systems Inventory every PLC and remote management path, then eliminate direct external reachability. Where remote access is unavoidable, force it through jump boxes, gateways, and tightly monitored administrative paths.
- Codify OT containment and failover playbooks Predefine the exact sequence for isolation, backup activation, evidence capture, and approval routing so the team is not improvising during a live incident.
- Enforce least privilege on operator and engineering access Review every account and session that can alter OT devices, then remove default credentials, shared admin access, and unnecessary standing permissions. Map each access path to a named owner and expiry condition.
- Measure dwell time as an operational control Track how long it takes to detect, isolate, and verify removal of an attacker from OT environments. Use those metrics to identify where approvals, tooling, or manual handoffs are slowing containment.
- Test for configuration drift on PLCs regularly Review configurations for unauthorized changes and compare them against approved baselines. In OT, silent drift can be as dangerous as an obvious compromise because it signals that someone can still alter control logic.
Key takeaways
- The article shows that OT compromise becomes dangerous when exposed control systems, not just endpoints, are reachable from outside the network.
- The strongest evidence of risk is not the breach itself but the slow path from detection to verified containment in a resource-constrained environment.
- Practitioners should focus on access path reduction, playbook automation, and measurable dwell-time improvement to limit future impact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | OT remote access and privilege boundaries map to access-control governance. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to the article's OT hardening guidance. |
| MITRE ATT&CK | TA0001 , Initial Access; TA0004 , Privilege Escalation; TA0040 , Impact | The campaign pattern centers on internet exposure, control gain, and operational disruption. |
| ISO/IEC 27001:2022 | A.8.20 | Network segregation and controlled access are relevant to legacy OT isolation. |
| CIS Controls v8 | CIS-5 , Account Management | Default passwords and privileged account hygiene are explicit gaps in the article. |
Map exposed PLC scenarios to ATT&CK and prioritise controls that reduce initial access and impact.
Key terms
- Programmable Logic Controller: A Programmable Logic Controller is an industrial device that executes control logic for machinery and processes. PLCs are often trusted to run continuously, so unauthorized access can alter physical behaviour quickly. In modern SCADA governance, PLC access must be tightly scoped and traceable.
- Dwell Time: Dwell time is the period between an attacker gaining access and defenders detecting or removing them. Shortening dwell time matters because most damage happens while the attacker remains unnoticed. In identity-led environments, reducing dwell time depends on visibility into access paths, privileges, and session behaviour.
- Operational Technology: Operational Technology is the hardware and software that monitors or controls physical processes such as manufacturing lines, utilities, and transportation systems. Unlike standard IT, OT prioritises uptime and safety, so identity controls must be precise enough to reduce risk without interrupting essential operations.
- Jump Box: A jump box is a controlled intermediate system used to reach sensitive assets that should not be accessed directly. In OT, it reduces exposure by forcing administration through a monitored path that can enforce authentication, logging, and segmentation before a user or tool reaches the control environment.
What's in the full article
Swimlane's full article covers the operational detail this post intentionally leaves for the source:
- Nick Tausek's full breakdown of why water utilities keep ending up on adversary target lists
- The five OT hardening steps discussed in the source, including jump boxes, MFA, least privilege, and firewalling PLCs
- The response-process and case-management detail behind dwell time reduction and faster remediation verification
- The AI SOC workflow that Swimlane says can turn unstructured findings into a prioritised remediation backlog
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect access control discipline to the broader identity programme their environments depend on.
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org