TL;DR: A wave of suspected Iran-linked attacks on U.S. water utility OT systems exposed how internet-facing PLCs, weak segmentation, and slow manual response still turn routine compromise into operational disruption, according to Swimlane. The real control gap is not awareness but dwell time, because containment and proof of remediation often lag far behind attacker access.
NHIMG editorial — based on content published by Swimlane: Recent Water Sector Attacks Show Why OT Security Can’t Wait
Questions worth separating out
Q: What breaks when PLCs are exposed directly to the Internet?
A: Direct exposure removes the safety margin that OT segmentation is supposed to provide.
Q: Why does slow OT incident response increase operational risk?
A: Slow OT response increases risk because every extra step between detection and containment gives the attacker more time to interfere with control systems, preserve access, or force manual workarounds.
Q: How should utilities harden remote access to legacy control systems?
A: Utilities should route remote access through jump boxes, segmented administrative paths, and gateways that can enforce authentication, logging, and approval.
Practitioner guidance
- Remove public internet exposure from control systems Inventory every PLC and remote management path, then eliminate direct external reachability.
- Codify OT containment and failover playbooks Predefine the exact sequence for isolation, backup activation, evidence capture, and approval routing so the team is not improvising during a live incident.
- Enforce least privilege on operator and engineering access Review every account and session that can alter OT devices, then remove default credentials, shared admin access, and unnecessary standing permissions.
What's in the full article
Swimlane's full article covers the operational detail this post intentionally leaves for the source:
- Nick Tausek's full breakdown of why water utilities keep ending up on adversary target lists
- The five OT hardening steps discussed in the source, including jump boxes, MFA, least privilege, and firewalling PLCs
- The response-process and case-management detail behind dwell time reduction and faster remediation verification
- The AI SOC workflow that Swimlane says can turn unstructured findings into a prioritised remediation backlog
👉 Read Swimlane's analysis of recent water utility OT attacks and response gaps →
Water utility OT attacks: are your response controls keeping up?
Explore further
Legacy OT identity is a governance gap, not just an engineering inconvenience. Water utilities are seeing the same access-control failure modes that have long affected NHI programmes: exposed credentials, direct trust paths, and little visibility into who can reach critical systems. The article shows that older PLC environments still rely on access assumptions that no modern security model would tolerate. Practitioners should treat OT access as privileged identity governance, not as a separate exception.
A question worth separating out:
Q: What should teams do when OT and IT security ownership is split?
A: Teams should create a shared access and response model with named ownership for every path that can reach operational systems. OT, IAM, and incident response functions need the same visibility into sessions, approvals, and containment steps. Without that shared accountability, response gaps appear exactly when a fast decision is most needed.
👉 Read our full editorial: Water utility OT attacks expose the response gap in critical infrastructure