
S³ Brief August 2026

Water utilities have reported disruptive cyberattacks against operational technology (OT), specifically the programmable logic controllers (PLCs) that run plant, pumps, and values, in the United States since late July. The vulnerability is reported to have been under active exploitation since March. For boards and executives accountable for essential services or critical infrastructure, this is worth noting.
Signal Scan
Australia: Australia's Australian Signals Directorate (ASD), through its Australian Cyber Security Centre (ACSC), published its "CI Fortify" framework in October 2025. In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the United Kingdom's National Cyber Security Centre and Canada's Cyber Centre joined the ACSC to publish an expanded version, "CI Fortify: Advice for Isolating Vital Systems," for isolating OT during extended disruption.
APAC: No distinct APAC development has surfaced this cycle.
Global: CISA's advisory scope has widened twice in a month, expanding from the single PLC vendor first observed to two further leading industrial control system manufacturers. Confirmed incidents span three states, Minnesota, Michigan, and New Jersey, with total reports across the campaign growing from seven states to twelve, and more than thirty systems affected in Minnesota alone.
The U.S. legal protection that lets private utilities share threat intelligence with federal agencies expires on 30 September 2026. Its current text does not explicitly cover the OT now under attack, and it has lapsed twice in the past year.
Shock Watch
Braham, a Minnesota water treatment plant, was forced offline after its PLCs were compromised. Importantly, no water safety issues have been reported. The scenario that is of note for leaders, is the next incident landing at a plant with less redundancy, an older or legacy control system, or one already running degraded.
The attack technique itself has two elements that arguably matter more than the outage duration. First, the flaw being exploited sits in a widely used controller line, under active exploitation months before the first reported outage. Second, CISA's July update documents attackers manipulating what shows on the control room's screens, so the display reads normal while the underlying process is not and records the first confirmed cases of attackers taking a plant's engineering files for use in future, more targeted attacks.
The method itself, targeting internet-exposed controllers with weak or default authentication, extends readily beyond the water sector. The same class of controller runs pumps, chemical dosing and process automation across energy, manufacturing and food production. A tested approach against one sector converts quickly to a template for the next.
Sensemaking
Three things are evident. The attack methodology is getting more sophisticated: the July advisory update documents attackers manipulating what the control room sees while a plant continues to run. The confirmed impact remains contained; one plant offline, no water-safety compromise reported anywhere, noting that detail relies on instrumentation the same advisory says can be made to mis-represent.
A "normal" dashboard reading is a claim that still needs verifying. Trust in what a control system reports needs to be earned through independent validation. The question is how often.
"No incident reported" and "no incident occurred" might read the same way on a board pack but actually depend on different things: the first on detection working as designed, the second on nothing happening at all. An attack campaign built to manipulate the operator's picture of reality is built to exploit that gap.
The actors behind this campaign against U.S. water utilities have not been confirmed, and confirmation will take time regardless of suspicion. Waiting for it before responding, communicating, or reassuring means waiting for intelligence that may never come. Braham's operators didn't have it, they made decisions and took action anyway - moving to manual operations, communicating the outage, and maintaining continuity - without waiting to learn who was responsible.
Interdependencies
"CI Fortify: Advice for Isolating Vital Systems" applies beyond the U.S. and the water sector. Boards and executive teams relying on a single-sector continuity plan are assuming a boundary the interdependency map doesn't respect: the guidance covers OT generally, across water, energy, and manufacturing, because the vulnerability isn't sector specific.
The guidance also surfaces a dependency easily missed. Isolation plans that look complete on paper often assume Active Directory and Domain Name System (DNS) keep functioning during isolation, when IT convergence has embedded both inside the OT itself. A hidden dependency of this nature may cause an otherwise well-designed continuity plan to fail, right when it's needed most.
There is an interesting contrast in the 2 regulatory systems. The U.S. model removes a disincentive: providing a liability shield making is legally safer for a private utility to volunteer threat intelligence to CISA and the Federal Bureau of Investigation. Australia's Security of Critical Infrastructure Act works on compliance: positive security obligations and mandatory incident reporting. Both have potential to support efficient, cross-agency advisory updates - when in effect.
Questions for Leaders
Which controllers, and which vendors, run the physical processes the organisation depends on, and is that list known and accessible without asking IT to go looking?
What might signal an incident had occurred if the bad actors' objective was to avoid detection rather than cause visible damage?
How might sustained uncertainty over who instigated an attack, and why, affect organisational and leadership credibility if it lasted months rather than days?
What Matters Next
30 days: Confirm which PLC and OT vendors sit inside operating systems, and cross-check that list against updated advisory scope. Test isolation plans against the CI Fortify guidance's checklist, specifically whether the Active Directory or DNS dependencies could cause silent failure.
90 days: Track the 30 September expiry of the U.S. information-sharing protection as a live test of whether a liability-shield model sustains coordination speed under pressure and consider what that implies for a compliance-based model.
12 months: Test whether incident response protocols assume attribution will arrive in time to inform decisions. Ensure response paths assume it won't.
Sources
CI Fortify – Advice for Isolating Vital Systems – Australian Cyber Security Centre
CISA Advisory AA26-097A – Cybersecurity and Infrastructure Security Agency
Coordinated Cyberattack on Minnesota Water Utilities: What You Need to Know – Tenable
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks – Dark Reading
Sweeping Cyberattack on Water Systems in Multiple States Has US Officials on Edge – CNN
This post is the full S³ Brief. A snapshot runs as a LinkedIn Newsletter. Subscribe to receive the full S³ Brief direct to your inbox. [subscribe here]
Working through complexity in your organisation? reach out [enquiry form]

