|
|

|
|

|
|
Security Advisory
Who: CISA What: Follow-up advisory about Iranian-affiliated cyber actors When: July 22, 2026
|
|
The Cybersecurity and Infrastructure Security Agency (CISA) issued an update to an April 7 advisory that urgently warned U.S. organizations of ongoing cyber exploitation of internet-connected operational technology devices.
This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured programmable logic controllers (PLC), emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.
Utilities are encouraged to implement mitigation measures as soon as possible as described in the advisory, including the following:
- Install PLCs consistent with manufacturers' guidelines and security best practices.
- Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.
- Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.
- For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.
AWWA’s cybersecurity resources offer guidance on best practices focusing on utility action to support implementation of controls that maximize near-term risk reduction to build cyber resilience.
Among AWWA’s cybersecurity resources is the Getting Started Guide, which advises systems to remove all nonessential devices from public internet connectivity. For devices that must have public internet connectivity, periodic, (e.g. monthly) vulnerability scanning of internet-connected devices/services and results are reviewed, and mitigation actions are implemented. Water systems of all types are encouraged to enroll in CISA’s vulnerability scanning service to help identify weaknesses that an attacker may exploit due to devices being publicly accessible via the internet.
AWWA’s cybersecurity guidance and assessment tool are aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and associated standards.
Questions can be directed to Kevin Morley, AWWA federal relations manager.
|
|
|
|
|
Get AWWA Insider news every other week when you become an AWWA Water Utility or Organizational member!