
Recent cyberattacks targeting U.S. water and wastewater utilities serve as another reminder that operational technology (OT) systems remain a prime target for malicious actors. According to a July 2026 public service announcement from the FBI and EPA, attackers compromised internet-facing programmable logic controllers (PLCs), causing operational disruptions that included flooding and pressure loss within water systems.
While these incidents affected specific PLC models, the underlying lesson extends well beyond any single vendor or industry: critical infrastructure operators must eliminate direct internet exposure of OT assets and adopt secure remote access architectures.
The growing risk to operational technology
For many utilities and industrial organizations, operational technology environments were never designed with today's cybersecurity threat landscape in mind. Remote monitoring and management capabilities, often bolted on over time rather than built in from day one, have sometimes resulted in PLCs and other OT devices being directly accessible from the public internet.
In the recent attacks, threat actors reportedly gained access to exposed PLCs, modified configurations, changed passwords, and disrupted monitoring and control functions. The FBI and EPA specifically warned that internet-facing OT devices create unnecessary risk and recommended that organizations rethink how remote connectivity is implemented.
This trend is not limited to water utilities. Manufacturing plants, energy providers, transportation systems, and other critical infrastructure operators face similar challenges as they modernize operations and connect systems that were designed to be isolated.
Secure connectivity is no longer optional
One of the most notable aspects of the FBI and EPA guidance is its emphasis on secure cellular architectures, strong authentication, and controlled remote access.
Among the recommended approaches are:
- Private APNs
- Site-to-site VPNs
- Cellular SD-WAN
- Zero Trust Network Access (ZTNA)
The common theme is simple: critical OT systems should never be directly exposed to the internet. Instead, all remote access should be authenticated, monitored, and managed through a secure connectivity platform that enforces least-privilege access and provides visibility into user activity.
Building a zero trust approach for critical infrastructure
The recent attacks also highlight why Zero Trust principles have become increasingly important for OT environments.
Traditional perimeter-based security assumes that users and devices inside a network can be trusted. Modern threat actors have repeatedly proven otherwise.
A Zero Trust approach focuses on:
- Verifying each user before connecting
- Providing only the minimum required access
- Continuously monitoring activity
- Segmenting networks to limit lateral movement
For critical infrastructure operators, these controls can mitigate the impact of a successful compromise and improve overall resilience.
Modern cellular networks with integrated zero-trust can strengthen OT security
Historically, organizations often treated network connectivity and cybersecurity separately. Today, the two need to be closely intertwined.
Modern 4G and 5G wireless networks provide opportunities to improve both operational flexibility and security when implemented correctly. Among the options:
- Private APNs:Reduces cyber risk by preventing OT devices from being directly exposed to the internet and ensuring communications travel through a private, controlled cellular network.
- Traditional VPNs:A traditional site-to-site VPN securely connects remote OT sites to central operations, reducing the need for direct internet exposure of critical control systems.
- Zero-trust network services: A modern alternative to Private APNs or traditional VPNs that creates a zero-trust WAN based service that provides better inherent security for critical OT devices by cloaking all public IP addresses, providing no implicit trust and governing all access by policy.
- Zero-trust access policies for securing OT/IoT assets: Minimize the network attack surface by granting authenticated, least-privilege access to OT systems rather than extending broad network-level connectivity like traditional VPNs.Clientless remote access solutions can further reduce the risks associated with unpatched VPN clients.
For organizations managing thousands of remote sites, pumping stations, substations, or industrial facilities, the right secure cellular architecture can eliminate device public internet exposure while also simplifying deployment and management.
Beyond technology: Operational resilience matters
The FBI and EPA recommendations go beyond cybersecurity technologies. They also emphasize operational preparedness, including:
- Maintaining the ability to operate critical systems manually
- Reviewing PLC logic and configurations for unauthorized changes
- Validating backups before restoration
- Regularly testing business continuity and disaster recovery plans
- Tracking end-of-life equipment and planning replacements
- Cellular-centric SD-WAN strengthens operational resilience by automatically leveraging the best available WAN connection to keep remote OT sites online and productive under any network condition.
These measures acknowledge an important reality: cybersecurity is not merely about preventing attacks. It is about ensuring organizations can continue operating safely when incidents occur.
A call for critical infrastructure modernization
The latest attacks should serve as a wake-up call for organizations that continue to expose OT assets directly to the internet or rely on legacy remote-access methods.
The guidance from the FBI and EPA aligns closely with cybersecurity best practices that many organizations are already adopting: Zero Trust access, network segmentation, private wireless connectivity, and continuous monitoring.
For utilities, industrial organizations, and other operators of critical infrastructure, the question is no longer whether these controls are necessary. The question is how quickly they can be implemented.
As threat actors increasingly target operational technology environments, organizations that modernize their connectivity and security architectures will be better positioned to protect essential services, maintain operational continuity, and strengthen resilience against future attacks.
Contact Ericsson to discuss strategies for reducing internet exposure and improving operational resilience.


