30+ Water Systems Attacked in One Weekend.
Is Yours Exposed?
In late July, attackers disrupted municipal water systems across at least 12 states — using nothing more than internet-exposed control devices and passwords that were never changed. Join our 60-minute briefing to see where your district actually stands.
More than 30 municipal water systems in Minnesota and nine in Michigan were hit by coordinated cyberattacks in late July 2026. The FBI has confirmed activity in at least 12 states, and CISA's July 30 alert found thousands of similarly exposed control devices at water utilities nationwide — "of all sizes… including some with mature cybersecurity programs." None of it required sophisticated hacking. It required an exposed device and a password that was never changed.
Read the full breakdown: Coordinated Cyberattacks Hit 30+ Water Systems →
30+
Water systems and utilities hit
12
States FBI confirmed
Critical Infrastructure Under Attack
A practical, no-jargon briefing for water district and local government leaders.
Date Thursday, August 20, 2026
Time 9:00 AM PT | 12:00 PM ET · 60 minutes
Built for Water district executives, city managers, administrators, and the IT/OT teams who support them
What you'll walk away knowing
-
What's actually happening on U.S. water systems right now, and what CISA is warning
-
Why this pattern has been building since the 2021 Oldsmar attack
-
The short list of immediate steps that close the doors attackers are using — none of which require a big budget
-
How to build lasting resilience using CISA's recommended principles
-
Where to get help if you don't have cybersecurity expertise in-house
Two Checklists to Find Out If Your Water System Is Exposed
Our checklists walk through the ten areas CISA and the FBI have flagged — written in two levels of detail, so your leadership team and your technical team can each assess readiness in their own language.
For Water Utility Leaders · Non-Technical
Water Systems Cyber Readiness Checklist
"Is your leadership confident you could withstand a cyberattack on essential water systems?"
What's inside
- Are critical systems exposed more than they should be?
- Do we know who can access critical systems?
- Is our support model actually proactive?
- Could we detect a problem quickly enough?
- Could we recover if a critical system was disrupted?
- Do leadership and technical teams agree on next steps?
For IT & OT Teams · Technical Edition
Technical Water Systems OT/PLC Gap Checklist
"Is your OT/PLC environment holding up against active, CISA-flagged exposure risks?"
What's inside
Ten areas mapped to CISA's OT and PLC guidance:
- Internet exposure & remote access
- Device hardening & controller protection
- Credentials & privileged access
- Monitoring & detection
- Network architecture & segmentation
- Backup, recovery & incident response
- Patch & attack-surface management
- Third-party & validation controls
- Governance & prioritization
- Integrity & change validation
