Cybersecurity has become an increasingly important issue for PLC, SCADA, and industrial control systems following a series of cyber incidents affecting water and wastewater infrastructure in the United States.

In July and August 2026, U.S. authorities reported multiple cyber incidents involving water and wastewater facilities. The incidents highlighted vulnerabilities associated with internet-connected operational technology devices and programmable logic controllers.
The issue is particularly important for industrial automation professionals because PLCs are directly involved in controlling physical processes. In water treatment facilities, PLC-based systems may control pumps, valves, monitoring equipment, chemical dosing systems, and other critical infrastructure.
According to U.S. authorities, attackers were able to remotely access exposed control devices in some incidents and make changes that affected monitoring and control functions. Reported techniques included changing passwords and modifying network-related settings, which could prevent operators from accessing or controlling equipment normally.
A separate cyberattack against Micro-Comm, a Kansas-based supplier of water utility technology, also drew attention from the FBI in August. The company provides programmable logic controllers and control technology used in water and wastewater applications.
These incidents demonstrate why industrial cybersecurity cannot be treated as only an IT problem. In a traditional IT environment, a cyberattack may primarily affect data or computer systems. In an OT environment, unauthorized access can potentially affect real-world equipment and industrial processes.
Modern factories and infrastructure facilities are becoming increasingly connected. PLCs communicate with HMIs, SCADA servers, engineering workstations, remote-access platforms, cloud systems, and industrial networks. This connectivity improves monitoring and maintenance but can also create additional cybersecurity risks.
Legacy automation systems present an additional challenge. Many older PLCs and control devices were designed when industrial networks were relatively isolated. Replacing these systems completely may be expensive and difficult, especially in facilities that operate continuously.
Industrial organizations therefore need a practical cybersecurity strategy that considers the entire automation lifecycle.
Basic measures include removing unnecessary direct internet exposure, using secure remote-access methods, implementing network segmentation, protecting engineering workstations, applying strong and unique credentials, controlling communication between industrial devices, and regularly reviewing access permissions.
For PLC and DCS engineers, cybersecurity should increasingly be considered during system design, commissioning, maintenance, and modernization projects.
The recent water-sector incidents also show that even relatively small automation technology suppliers can become part of the cybersecurity chain supporting critical infrastructure.

As industrial systems become more connected and intelligent, the role of OT cybersecurity will continue to grow. Future PLC, DCS, SCADA, and industrial networking projects will need to balance connectivity and remote monitoring with process safety, reliability, availability, and cybersecurity.
For automation companies and system integrators, secure-by-design control architectures are therefore becoming an increasingly important part of modern industrial automation.
AI-Powered Robots Demonstrate The Future Of Industrial Automation In Europe
ABB Appoints New B&R President To Drive Machine Automation And Industrial Innovation
Schneider Electric Invests €150 Million In France To Strengthen Industrial Automation And Manufacturing
Rockwell Automation Reports Rapid Growth In AI Adoption Across Smart Manufacturing