Thousands of Water System Controllers Still Visible Online

New research has identified more than 4,000 Rockwell Automation industrial controllers connected directly to the internet, many of them tied to U.S. water utilities. Among the exposed devices, 22 were traced to cities that have already experienced cyberattacks targeting water infrastructure. The findings raise an uncomfortable question for the water sector: why, after years of federal warnings, are so many critical systems still visible to anyone scanning the internet?

The exposed equipment includes programmable logic controllers (PLCs), the small industrial computers that manage physical processes like water pressure, chemical dosing, and pump operations. These aren't consumer devices sitting behind a home router. They're supposed to be isolated on protected internal networks, accessible only to authorized operators. When a PLC is reachable from the open internet, it becomes a potential entry point for anyone with the right tools and motivation, from opportunistic scanners to state-linked threat actors.

Why Exposed Industrial Controllers Are a Privacy and Safety Problem

It's tempting to file this under "industrial cybersecurity" and move on, but exposed industrial controllers carry consequences that reach well beyond IT departments. Water utilities hold operational data, customer account information, and infrastructure details that, if exposed or manipulated, affect entire communities. A compromised controller isn't just a data privacy risk; it's a public safety risk, since attackers who gain access to a PLC can, in theory, alter treatment processes or disrupt service.

This is also fundamentally a privacy story in a broader sense. Utility customers have no visibility into whether the infrastructure delivering their water is secure, and no meaningful way to opt out if it isn't. Unlike a breached retailer or social media platform, there's no changing providers when your municipal water system is the one running exposed equipment. The privacy and safety burden falls entirely on operators who, according to this research, have not consistently followed federal guidance to take these systems offline or properly segment them from the public internet.

A Pattern of Warnings That Haven't Closed the Gap

Federal agencies have repeatedly urged water utilities and other critical infrastructure operators to remove internet-facing industrial control systems, enforce strong authentication, and segment operational technology networks from corporate IT. Despite that guidance, the scan behind this research shows the problem persisting at scale, with thousands of controllers still discoverable using basic internet scanning tools that require no special access or sophistication.

The fact that 22 of the exposed devices sit in cities that have already been targeted by attacks on water systems is particularly notable. It suggests that even after an incident draws attention to a specific utility or region, the underlying exposure isn't necessarily remediated. Awareness alone isn't translating into action, whether because of budget constraints, staffing shortages, or the sheer complexity of retrofitting security onto infrastructure that was never designed with internet connectivity in mind.

This mirrors a broader pattern seen across sectors under strain from cyber threats. In healthcare, for instance, agencies have had to actively urge organizations to share ransomware threat data because operators have historically been reluctant to disclose incidents, slowing down collective defense efforts. Water utilities appear to face a similar gap between guidance issued and guidance followed, and in both cases the result is that vulnerabilities linger longer than they should.

What This Means For You

Most readers aren't water system operators, but this research still matters to anyone who relies on municipal infrastructure, which is nearly everyone. Exposed industrial controllers represent a systemic risk that individual consumers can't directly fix through personal security habits like using a VPN or strong passwords. That said, awareness has value. Understanding that critical infrastructure security gaps exist can inform how you engage with local officials, utility boards, and public comment periods where infrastructure investment decisions get made.

If you work in or around municipal utilities, water treatment, or any operational technology environment, this research is a direct call to action. Federal warnings about exposed PLCs and control systems aren't hypothetical; they describe a documented, ongoing exposure that attackers can and do exploit.

Takeaways for Readers and Operators

For utility operators and OT teams, the immediate priorities are clear: audit which devices are reachable from the public internet, remove unnecessary exposure, and implement network segmentation between control systems and everything else. For everyday readers, the best steps are civic ones: ask local water authorities about their cybersecurity posture, support funding for infrastructure security upgrades, and stay informed as more research like this continues to surface. The exposure of thousands of industrial controllers won't close on its own, and closing it requires sustained pressure from both regulators and the communities these systems serve.