A Single Partner for Everything You Need With more than 450 technology partners in its ecosystem, Optiv provides clients with best-in-class security technology and solutions that equip organizations to detect and manage cyber threats effectively and efficiently in today's growing attack surface. Optiv's Partner of the Year Awards recognize forward-thinking innovation, performance and growth, and unparalleled technology solutions.
We Are Optiv Security Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner. However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Operational Resilience Starts with OT Fundamentals Breadcrumb Home Insights Blog Prevent OT Incidents with Strong Security Fundamentals August 27, 2026 In July, more than 30 community water systems across Minnesota were hit by a coordinated intrusion into their operational technology (OT) environments. Four utilities went public. One took its treatment plant offline for two to three hours and asked residents to cut back on water use. Two others lost remote cellular communications to two water towers and several lift stations and fell back to manual operation. The fourth declared a local state of emergency. What feels new about this incident is the target, not the mechanism. Municipal water utilities have been warned about exposed industrial control systems for years; this is that warning arriving in the form of an actual event. The positive takeaway is that manual fallback procedures worked as intended, preventing the disruption from becoming a public health emergency. But a successful response should not overshadow the larger lesson: resilience limits the impact of an incident, while foundational OT security controls reduce the likelihood that one occurs in the first place. What the Incident Demonstrates About OT Risk For utilities and critical infrastructure operators, the most important lesson is not the specific attack path. It is how quickly internet-accessible OT assets can become operational liabilities. One city’s own statement identifies the affected equipment, two water towers and multiple lift stations, as cellular connected. That lines up with independent OT research finding the attack surface was PLCs reachable directly from the public internet through cellular gateways. Officials haven't confirmed which specific vulnerability was used at any Minnesota site, or even which vendor's equipment was hit at most of the 30-plus affected systems. One technical writeup on the incident is blunt about the tradecraft required: none. Reach an exposed controller, change its IP and password and operators lose visibility into what it's doing. The reported activity underscores how exposed systems and configuration weaknesses can increase operational risk. The reported activity highlights the risk associated with internet-exposed programmable logic controllers (PLCs) and cellular OT connections that rely on weak or absent authentication. That holds true whether the actor behind the keyboard was a state-sponsored operator or an opportunistic attacker. Attribution may influence response activities, but it does not change the security fundamentals organizations should prioritize. Why the Unpatched CVE Matters Anyway "Get it off the internet" isn't a throwaway line, and CVE-2021-22681 is why. It's a 9.8-severity authentication bypass in Rockwell Automation's Logix controller family: CompactLogix, ControlLogix, GuardLogix and related lines. Disclosed in 2021, added to Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog this past March, and tied to the broader PLC exploitation campaign CISA has tracked under advisory AA26-097A. The flaw sits in the protocol design itself: an insufficiently protected cryptographic key means any client presenting Studio 5000 Logix Designer, the standard engineering software, looks like a trusted operator. There's no complete vendor patch, because this isn't a bug to fix. It's an assumption baked into how the authentication works. Whether this specific common vulnerabilities and exposures (CVE) was used against the state's utilities hasn't been confirmed. The FBI and EPA's joint advisory on the broader campaign actually names a different, older product line, Rockwell's MicroLogix 1100/1400 series, as the targeted devices in some reported incidents. What CVE-2021-22681 does confirm is the stakes of exposure. Even where a flaw is publicly known, actively exploited and has no patch coming, the only real defense is architectural. Segmentation, allowlisting and isolating engineering workstations aren't best practices in the abstract here. They're load-bearing. Emerging Industry Efforts and Resources Two efforts have launched in the two weeks since the attack, and they're solving different problems. The Water Watch Center (WWC), announced August 7 at DEFCON, pairs the National Rural Water Association (NRWA) with DEFCON Franklin, a hacker-conference-adjacent nonprofit, not a government body. It formalizes a two-year pilot that placed roughly 450 volunteer security researchers with small utilities across seven states and now adds a group of managed detection and response providers sharing threat intel through NRWA as a hub. A research partnership with Vanderbilt, using DARPA's CASTLE program, will build digital twins of a handful of WWC utility environments for red and blue team testing. It's aimed at the roughly 91% of U.S. water systems serving fewer than 10,000 people with no in-house security staff at all. The Water Cyber Shield Act, introduced August 10 by Senators Schiff and Klobuchar, would give the EPA explicit authority to run cybersecurity assessments on water and wastewater systems and require corrective action when it finds problems, working alongside CISA and NIST to set baseline standards. It authorizes $300 million a year through the Drinking Water and Clean Water State Revolving Funds, framed deliberately as funding rather than an unfunded mandate, the sticking point that sank a similar Biden-era EPA effort after industry and Republican-state pushback. It's a bill, not yet law, and Schiff's office has said they may try to attach it to a larger vehicle rather than pass it standalone. Key Security Controls Utilities Should Prioritize None of the actual fix requires federal legislation, and none of it requires knowing who's behind the attack. It requires doing the boring things: Get PLCs off the public internet, including anything reachable through cellular gateways Physically set controllers to RUN mode, reserving PROGRAM mode for authorized on-site maintenance only Diff current logic against a known-good baseline to catch unauthorized changes to ladder logic or add-on instructions Actually test manual override procedures, not just document them. Minnesota's utilities avoided a public health incident because their manual fallbacks worked Block traffic from foreign hosting providers on ports 44818, 2222, 102 and 502, and lock down remote access ports like 22 on cellular modems Segment the network using a zone-and-conduit model, with MFA enforced at every VPN and remote-access gateway CISA and EPA both offer free vulnerability assessments for utilities that haven't had one. The Water Watch Center is a real, funded option for utilities too small to have any of this in-house. Neither requires Congress to act first. The through-line to this isn't a foreign adversary story, even if that's the version that travels furthest. Reportedly exposed PLCs and weak authentication controls illustrate how unnecessary internet exposure can increase risk to operational environments. The systems that kept water flowing did so because operators could still run the plant by hand when the automation failed. The incident serves as a reminder that cybersecurity and operational resilience are complementary disciplines. Organizations that reduce unnecessary exposure, validate recovery procedures and regularly test operational contingencies are better positioned to maintain essential services during disruptive events. Reach out to learn how our experts can help assess your organization's exposure risk and develop strategic OT security programs. By: Nate Johnson Since passing his CCNA at age 17, Nate Johnson has been fascinated with technology and its impact on organizations. With over 20 years of experience, Nate has worked with organizations of all sizes and verticals, to help make informed decisions on their technology roadmaps as well as showing how cybersecurity can be a business enabler for them. Nate's passion for security drives his desire to educate the community in an effort to make technology safer for all. As Director of R&D at Optiv, he works closely with clients and vendors to analyze market and industry trends and advises organizations on where to focus their time, energy and investments for maximum impact. Share: Optiv OT Security About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.
About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.