What the Minnesota Water Hack Reveals About OT Security Assessments
On July 26 and 27, a coordinated cyberattack hit more than 30 community water systems across Minnesota. Our team is trained in running penetration tests against OT and ICS environments, and when we read the reporting on this one, nothing about it was surprising. That's the part that should worry people.
The attackers didn't go after billing databases or customer records. They went after the valves, pumps, and automated controls that physically move and treat water. Braham's water plant went offline. Plymouth lost cellular communications at two water towers and multiple lift stations and fell back to manual operations. Maple Plain declared a local state of emergency. The FBI is now heavily involved.
Thirty plus utilities in one state, in one weekend, is not a random run of bad luck. That is a scan and exploit campaign that found the same gaps over and over, at plant after plant, town after town. Anyone who has spent time doing OT security assessments already knows why. Small municipal utilities tend to look almost identical to each other from the outside. Same vendors, same remote access tools, same shortcuts taken by IT teams that are really one or two overworked people trying to keep the water running and the lights on.
Water Quality Was Never the Point
Officials stressed that water quality was never affected. That's true, but read it carefully. A plant went dark. Automated controls were compromised badly enough that a city declared an emergency. The systems held because operators caught it and switched to manual, not because the attackers couldn't reach the equipment. They reached the equipment. That's the whole story.
On assessments, our team has sat in control rooms and shown an operator a path from a laptop on the corporate network straight to a PLC controlling a physical process. The reaction is always the same. The gap between catching it in time and finding out when something breaks is usually not a technical control. It is a person paying close attention at the right moment. That is not a strategy any utility or manufacturer can plan around forever.
A Familiar Pattern Behind Every ICS Penetration Testing Engagement
This is the same pattern that shows up behind years of water sector attacks: internet-exposed HMIs, forgotten vendor remote access, cellular-connected field devices, and default credentials at utilities running lean on IT staff. None of it is exotic. It's the boring stuff that never got cleaned up.
And it isn't just a water problem. If you have PLCs, HMIs, or field devices sitting behind a remote access appliance, whether you're in manufacturing, energy, food processing, or building automation, you have the same attack surface these utilities did.
Across our assessments, the same handful of issues shows up almost every time. An HMI that some integrator exposed to the internet years ago for troubleshooting and nobody ever locked back down. A vendor's remote access box sitting on the network with a login nobody has changed since commissioning. A cellular gateway on a lift station or a remote pump house that was never meant to be internet facing but ended up reachable anyway. And credentials. Always credentials. Default admin logins on HMIs and engineering workstations, the same password shared across a dozen sites because rotating it means a truck roll nobody wants to schedule.
None of that requires a nation state actor with a zero day. It requires patience, a scanner, and a list of default credentials that is public knowledge. The attacker does not need to be clever. They just need targets that never got looked at.
Questions Worth Asking Before Someone Else Answers Them for You
So ask a few plain questions. Can anyone on the internet reach your control systems? If an attacker landed on your business network, could they pivot into OT? Would you detect it early, or would you find out when a pump stopped working?
If you can't answer those with evidence, you're guessing. Minnesota's utilities were guessing too, right up until now.
A gut feeling that things are probably fine is not evidence. Neither is the fact that nothing bad has happened yet. Our team has walked into environments where the IT staff was confident their OT network was segmented, only to trace a live path from a guest Wi-Fi VLAN to a historian server sitting one hop from the control network. Confidence and reality are two different things, and the only way to know which one you are dealing with is to test it.
What CISA's Guidance Actually Amounts To
In the wake of these attacks, CISA, working with the Australian Cyber Security Center, shared guidance on protecting critical infrastructure, which ultimately amounts to isolation. Isolate critical OT systems. They can't be attacked if they can't be reached.
Of course, everyone would already be doing this if it were so straightforward. OT facilities and their networks are complex, and uptime is non-negotiable. You can't just unplug a remote access path a vendor has relied on for ten years without a plan. Ripping out a connection that a control system integrator uses for support, without a replacement in place, can cause its own outage, and in a water plant an outage is not an abstraction. It is a real problem for real people served by that plant.
Isolation is the right long term goal, but it is a project, not a switch you flip. It starts with knowing what is connected to what, which is where most organizations get surprised. Asset inventories are frequently missing devices that have been live on the network for years. You cannot isolate what you do not know exists.
How Compass Approaches OT Security Assessments
At Compass, we can help you get started. Our team is trained in running security assessments and penetration tests against the environments adversaries stand to gain the most from attacking: external and internal networks, and OT/ICS systems including SCADA, PLCs, and industrial protocols. We find the exposed remote access and the flat networks bridging IT and OT, then show you exactly how to close those paths.
Most importantly, we do it safely. No massive scans, no blindly firing off exploits. We want the OT operators with us every step of the way, because uptime matters to us too. A penetration test that trips a plant offline defeats the purpose. Our job is to show you the same paths an attacker would use, without ever putting the process at risk.
That usually starts with an OT security assessment. We map what is actually connected to your network, identify where IT and OT blend together, and look for the exposed remote access, default credentials, and flat network segments that show up in incident after incident like this one. From there we can move into hands on ICS penetration testing, carefully scoped with your operators, to prove or disprove whether those gaps are actually exploitable in your environment. You get a clear, prioritized list of what to fix first, not a two hundred page report that sits in a drawer.
The utilities in Minnesota found out where they stood from the attackers. Find out from us instead. Contact us to schedule a penetration test before an adversary runs one for free.
Contact Us
Share this
You May Also Like
These Related Stories

Internal vs External Penetration Testing: What's The Difference?
.jpg)
Are You Protecting Your Attack Surface?

.webp?width=2169&height=526&name=Compass%20white%20blue%20transparent%202%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
No Comments Yet
Let us know what you think