Minnesota’s 30+ Water Systems Show Why a CISA OT Mandate Alone Won’t Protect Utilities

Water treatment plant control room with industrial controllers, illustrating OT cybersecurity attacks on US water utilities

TL;DR · 30-second read

The Short Version

Hackers have tampered with the computers that run water and sewage plants in at least seven American states. In Minnesota alone, more than 30 local water systems were targeted, allegedly by attackers working for Iran.

A group of industrial security firms and plant operators wants the federal government to stop issuing warnings and start requiring basic protections. The catch: the rule they want would only cover federal government sites. Small-town water utilities would still rely on a federal grant program that Congress has not yet renewed.

The Operational Technology Cybersecurity Coalition (OTCC) has called on the Cybersecurity and Infrastructure Security Agency (CISA) to issue a Binding Operational Directive setting baseline security controls for operational technology, the systems that run physical equipment, across federal civilian facilities. Industrial Cyber reported the statement on August 3, 2026. It follows the FBI’s confirmation, as of July 30, that water and wastewater utilities in at least seven states had reported cyber incidents, some of which disrupted operations. The worst impact was in Minnesota, where alleged Iranian-affiliated state actors targeted more than 30 water systems.

The coalition also asked Congress to reauthorize and fund the State and Local Cybersecurity Grant Program, support Andrew McClure as director of the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), and pass long-term authority for the Cybersecurity Information Sharing Act of 2015, which is set to expire at the end of September.

Executive Summary

The OTCC is asking Washington to move from advisories to requirements on industrial cybersecurity. Its headline request, an OT-focused Binding Operational Directive from CISA, would oblige federal civilian agencies to put fundamental controls on the systems that operate pumps, valves, power equipment and building infrastructure.

The detail that matters most is one the coalition states itself: such a directive would not have applied to the Minnesota water utilities. OTCC executive director Tatyana Bolton argues its value lies in the demand signal it sends to the private sector. The coalition’s three requests to Congress are the measures that actually reach local utilities. They cover grant money for state and local defenders, energy-sector security leadership, and the legal basis for companies to share threat data with the government.

For anyone who owns or depends on critical infrastructure, including energy, water and the data centers that draw on both, the practical question is whether those congressional levers move before the information-sharing law lapses at the end of September.

A Mandate That Stops at the Federal Fence Line

A Binding Operational Directive is a compulsory instruction from CISA to federal civilian executive branch agencies. It is not a regulation on industry. Bolton says so plainly: an OT directive “only applies to FCEB entities, and the water utilities in Minnesota would not have been required to implement the requirements.” The incident that prompted the call therefore sits outside the reach of the call’s headline remedy. More than 30 targeted water systems in one state, and reported incidents in at least seven, all involve utilities that are mostly local, not federal.

The coalition’s argument for the directive is indirect. Federal requirements tend to become the reference point that vendors build to, insurers ask about and state regulators borrow. Bolton cites a 2024 National Security Agency directive covering OT on National Security Systems, which required security, reporting and inventory measures, as evidence that such a baseline is “not a novel or unimplementable idea.” That precedent supports the feasibility claim. Whether a federal-only directive changes behaviour at a small municipal water plant is a separate claim, and the coalition presents it as a signal rather than a mechanism.

Who is affected, then? Federal civilian agencies would carry the direct compliance burden. The operators under active attack, small utilities with limited security staff, would see change only if the signal travels. That is why the coalition itself describes the directive as insufficient on its own.

The Levers That Reach Local Utilities

The requests aimed at Congress do more of the work for the actual victims. The State and Local Cybersecurity Grant Program funds state and local governments, and the coalition frames it bluntly: without it, Congress is “leaving small towns to protect themselves from nation-state actors like Iran.” For a utility serving a few thousand customers, the constraint is usually money and staff, not awareness of best practice. A grant program addresses that constraint. A federal directive does not.

The Cybersecurity Information Sharing Act of 2015 matters for a different reason. It lets private companies pass technical threat data to the government. That flow is how agencies spot a campaign moving across sectors and warn the next target before it is hit, which is exactly the pattern of an attack wave that reached at least seven states. The coalition warns the US “can no longer rely on short-term extensions” with the authority due to expire at the end of September. A lapse would thin the evidence that the FBI and EPA warnings are built on.

The request to back Andrew McClure at CESER extends the argument to energy. The Environmental Protection Agency leads on water, but the coalition notes that energy underpins all 16 critical infrastructure sectors, and CESER is responsible for protecting the OT that runs the grid.

Internet-Exposed Controllers Are Everyone’s Problem

The FBI and EPA warning centred on hackers targeting internet-connected industrial controllers. These are the small computers that open valves, run pumps and dose treatment chemicals. The same class of equipment runs substations, backup generation, and the chillers and power distribution inside commercial buildings and data centers. Bolton points to “increasing convergence between IT and OT,” meaning office-style networking reaching equipment that was once isolated. That convergence is why a technique proven against water plants is relevant well beyond water.

For infrastructure operators outside the water sector, the lesson is not that their own facility was hit; nothing reported suggests that. The lesson is that their upstream dependencies, municipal water and the grid, run on controllers of this kind, often operated by organisations with far smaller security budgets than their largest customers.

Weighing the Coalition’s Case

The OTCC describes itself as a coalition of OT cybersecurity organizations and owners and operators. Firms that sell OT security stand to benefit from mandates, and readers can weigh the call with that in mind. The substance of the requests is modest, however. The directive covers only the government’s own systems, and the congressional items reauthorize or fund existing programs rather than create new regulatory regimes.

The assertion that deserves the closest scrutiny is the demand-signal effect, which is plausible but not demonstrated in the statement. The strongest parts of the case are the concrete, dated items: an information-sharing authority with a known expiry, and a grant program whose absence falls hardest on the smallest operators.

Background

The Operational Technology Cybersecurity Coalition is an advocacy group of OT cybersecurity organizations and infrastructure owners and operators, led by executive director Tatyana Bolton. CISA, part of the Department of Homeland Security, coordinates national cyber defense and can issue binding directives to federal civilian agencies. For most privately and locally run infrastructure, however, it relies on advisories and voluntary guidance, alongside sector agencies such as the EPA for water and the Department of Energy for power.

US water and wastewater service is delivered largely by local utilities, many of them small, which operate industrial control systems with limited security staff. Bolton points to repeated warnings that Chinese and Iranian actors have pre-positioned inside critical infrastructure, and to growing IT and OT convergence, as the backdrop to what the coalition calls years of guidance without enough action.

Sources

Source: OTCC urges CISA to issue binding OT cybersecurity directive after cyberattacks disrupt water utilities (Industrial Cyber). The OT Cybersecurity Coalition calls for a CISA OT directive and congressional action after attacks on water utilities in at least seven states.