What Recent Operational Technology Cyber Incidents Mean for Critical Infrastructure Resilience

What Recent Operational Technology Cyber Incidents Mean for Critical Infrastructure Resilience
August 20, 2026 5 mins

What Recent Operational Technology Cyber Incidents Mean for Critical Infrastructure Resilience

From Control Room to Crisis: What Recent Operational Technology Cyber Incidents Mean for Critical Infrastructure Resilience

Recent attacks on water systems across multiple states in the U.S. highlight the potential for real operational disruptions, requiring organizations to reevaluate their operational exposure, implement targeted controls and build cyber resilience strategies.

Key Takeaways
  1. Poor network design and segregation are exposing operational technology to the internet, leaving critical infrastructure vulnerable to cyber attacks.
  2. Compromised programmable logic controllers and human-machine interfaces can quickly translate into real-world service disruptions.
  3. The severity of the threat underscores the need for critical infrastructure entities to treat operational technology cyber security as a strategic risk, supported by targeted controls and tailored risk management strategies.

Cyber Attacks on Water Systems

In late July, multiple cyber attacks targeting operational technology (OT) were reported across the United States. Confirmed intrusions generally involved technology that water systems used to remotely monitor and control equipment, such as programmable logic controllers (PLCs) and human-machine interfaces (HMIs).

According to the Federal Bureau of Investigation and Environmental Protection Agency, several of these cyber incidents led to operational disruptions, including loss of water pressure and flooding. After gaining remote access to internet-facing devices, malicious cyber actors changed their IP address and passwords. This resulted in a loss of monitoring and control functionality and, ultimately, degraded water system performance.

The investigation remains ongoing, and no formal attribution has been announced. Some public reporting1 has discussed possible links to external threat actors.

Similar cyber attacks against OT systems in the water sector were reported2 across multiple locations in the U.S. and Israel throughout 2023 and 2024 and in Europe3 in 2025. While the water sector has made the headlines, government authorities continue to warn4 of cyber threats targeting internet-connected OT used across all critical infrastructure sectors.

Recommended Actions

Safeguard and Stabilize

To strengthen resilience against cyber threats to operational technology, organizations should harden their control environments and strengthen their oversight.

  • 1. Inventory and Restrict Direct Internet Exposures

    Take inventory and identify all internet connected PLCs, HMIs and related devices, and restrict direct internet exposure by removing public access where possible and routing any necessary remote access through managed gateways or jump hosts with multi-factor authentication (MFA). Organizations should also audit remote access pathways, validate that safety systems and alarms are functioning as intended, and maintain offline backups and “known good” baselines of PLC logic so that configurations can be quickly verified and restored.

  • 2. Strengthen Separation and Oversight

    Once the immediate risks are addressed, organizations should focus on medium-term improvements that strengthen the separation and oversight of their OT environment. This includes segregating IT and OT networks with strict communication controls and firewalls and monitoring engineering workstations so that only authorized personnel can modify PLC code, with all activity logged and alerts generated for unauthorized change, including anomalies targeted to indicate intentional or non-intentional insider threat risk. Organizations should also maintain a comprehensive OT asset inventory, identify unsupported or unpatched systems, develop vulnerability and patch management processes, and tighten vendor access controls through MFA.

Strengthen and Strategize

In the long term, organizations should focus on strategic review and resilience planning.

  • 1. Review Risk and Resilience Posture

    Conduct a holistic review of the organization’s OT risk profile, including the current control environment, governance model, incident response arrangements and communication frameworks. This review should assess not only technical security posture, but also the potential financial, reputational, operational and public service impacts of an OT cyber incident.

  • 2. Model Realistic OT Loss Scenarios

    Reviewing OT controls through the lens of realistic loss scenarios can help move the conversation from technical vulnerability to enterprise exposure. Scenarios such as loss of operational visibility, unauthorized changes to control logic, forced manual operations, service interruption, equipment damage or downstream impacts to customers can reveal where existing controls may fall short under stress. This approach enables leadership to prioritize investment based on material risk, quantify potential financial and operational impacts and test the adequacy of response plans.

  • 3. Review Insurance Alignment

    Work with your insurance broker and insurers to review cyber policy language and confirm that coverage aligns with the organization’s specific OT risk profile. Closely assess coverage for cyber event management, data recovery, hardware replacement (including OT systems), business interruption and relevant exclusions, including war and public utility exclusions. For public entities, understand available coverage at the municipality, county or state level, and evaluate alternative insurance structures such as pooling agreements to negotiate stronger terms.

    Given the potential for disruptive impacts on public services, organizations should also develop and rehearse an incident response playbook for OT events that covers rapid isolation of affected devices, manual operations and clear communication protocols. Cyber insurance policies offer a variety of services that can help organizations prepare for and respond to a cyber incident.

Let’s Connect

Engage With Your Broker

Speak to your Aon contact to activate support or request more information.

Contact Us

General Disclaimer

This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.

Terms of Use

The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.

More Like This

View All
  • SMRs: Advancing Energy Security and Decarbonization

    Article 5 mins

    SMRs: Advancing Energy Security and Decarbonization

    As investment in small modular reactors accelerates, project success will depend on more than technology. Early attention to risk, insurance and regulatory certainty can help improve insurability, support financing and accelerate deployment.

  • Managing Data Center Accumulation Risk

    Article 10 mins

    Managing Accumulation Risk in Data Centers

    Data centers today, driven by growth and scale, concentrate enough value for a single event to create a portfolio-level loss. Re/insurers and captives that understand and manage aggregation exposure will be better positioned to sustain capacity and support long-term sector growth.