Blog
Aug 2, 2026
4 min read

What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure

Cyberattacks on critical infrastructure don't require advanced exploits. Using the recent Minnesota water attacks as an example, this article explains why strong access controls remain the first line of defense for operational technology and reveals how organizations can reduce their exposure to common attack paths.

Written By

Almog Apirion

When headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading.

As a “recovering CISO” who spent years managing operational risk and building cyber defense units, I’ve learned an uncomfortable truth: many attackers targeting critical infrastructure don't break in—they log in. 

In the case of the Minnesota attacks, public reporting and guidance from CISA, the FBI, and industry researchers indicate this wasn't a zero-day exploit, a complex supply-chain compromise, or an AI-assisted intrusion. Instead, attackers took advantage of fundamental weaknesses in remote access controls, including poor credential hygiene and internet-exposed operational technology.

That's precisely what makes these attacks so concerning: the perpetrators didn't rely on novel techniques, but on security gaps that remain surprisingly common. And, unfortunately, this isn't a localized problem. It is a systemic issue across the entire landscape of operational technology and critical infrastructure.

The Hidden Cost of Operational Convenience

Why do remote wellheads, lift stations, and other industrial assets remain exposed to the open internet?

The answer usually lies in the realities of operating critical infrastructure. Small municipal districts and industrial operators face lean budgets, geographically dispersed assets, and an acute shortage of specialized IT/OT talent. To keep pumps running and water flowing 24/7, field engineers and third-party integrators often deploy cellular gateways or remote access devices to restore visibility while simplifying maintenance.

Over time, these remote access paths accumulate: 

  • Unmonitored Cellular Modems: Devices connected directly to cellular networks can bypass corporate security controls, leaving remote assets exposed without centralized monitoring or oversight.

  • Shared or Default Credentials: Standardized deployments and unchanged default passwords, especially among third-party vendors, make it possible for a single technique to work across many sites.

  • Lack of Identity-Based Access: When access is tied to a network connection rather than an authenticated user and session, a single exposed access point can provide broad access to operational systems.

When bad actors scan for exposed interfaces, they don't need a custom exploit payload. They simply use valid or default admin credentials to gain direct control of HMIs and PLCs. This is how practical decisions made in the interest of uptime and efficiency can unintentionally create security gaps that attackers are quick to exploit.

3 Non-Negotiable Controls for Secure OT Access 

To most effectively protect critical infrastructure—whether it's water systems, energy grids, or manufacturing plants—we have to stop treating remote access as simply a network connectivity problem. It must be managed as a security function built on identity, visibility, and control.

To close common attack paths, organizations need to adhere to three core principles.

1. Eliminate Direct Internet Exposure 

No PLC, HMI, or cellular router should ever be directly reachable via a public IP address. Air-gapping is often impossible in today's connected world, but exposing management interfaces directly to the internet is a recipe for disaster. Remote connections must be brokered through a secure access layer that hides the underlying infrastructure from public scanning while enforcing authentication and authorization before access is granted.

2. Enforce Identity-Bound, Zero-Trust Access 

Moving away from network-level access such as legacy VPNs or open port forwarding to identity-bound access is vital. Every connection—whether by an internal operator or a third-party contractor—must require multi-factor authentication (MFA) and explicit, least-privilege authorization. Even if an attacker discovers an exposed access path, identity verification and least-privilege controls should prevent direct access to control systems.

3. Ensure Full Visibility & Session Monitoring 

When a third-party vendor or remote operator connects to a sensitive control device, security teams need real-time visibility into that session. Granular session logging and the ability to terminate unauthorized actions instantly turn passive monitoring into active operational defense

Secure Remote Access Is the First Line of Defense

The Minnesota attacks are a reminder that many OT incidents don't begin with advanced malware or novel exploits. More often, they start with exposed access paths and weak authentication. Fortunately, these are problems organizations can solve with proper remote access controls.

We do not need to rewrite the laws of physics or rip and replace existing industrial control hardware to stay safe. By eliminating direct internet exposure, enforcing identity-based access, and enabling visibility into every remote session, critical infrastructure operators can support remote operations without unnecessarily increasing operational risk.

Almog Apirion

Author

Almog Apirion is CEO and co-founder of Cyolo. He is an experienced technology executive, a "recovering CISO," and the founder of the Israeli Navy Cyber Unit. Almog has a long history of leading the cybersecurity and IT technologies domain, with a background that includes building and securing critical infrastructures at large organizations, and leading teams to success.

Subscribe to Our Newsletter