Operational Technology Security
OT security services for municipalities
CyNtell provides operational technology (OT) security services to municipalities: the cities, counties, towns, utility districts, and public power utilities that own the industrial control systems (ICS) running water treatment, electric distribution, traffic signals, and public buildings.
Our municipal OT security services cover three things: OT asset inventory and network monitoring, OT risk assessment against IEC 62443 and NIST SP 800-82, and OT incident response with tabletop exercises. All three are built for supervisory control and data acquisition (SCADA) environments and plant floors rather than office networks.
Threat status · September 2026
Municipal water systems are under active, coordinated attack through internet-exposed PLCs.
CISA reported malicious activity against more than 100 internet-exposed systems in the Water and Wastewater Systems Sector during July 2026 alone. An FBI alert dated July 30, 2026 states that actors changed programmable logic controller (PLC) IP addresses and passwords, "resulting in a loss of monitoring and control functionality," with incidents reported in at least seven states since July 27, 2026.
Sources: CISA/FBI joint advisory AA26-097A (published April 7, 2026; updated July 2026) and the FBI Cyber alert of July 30, 2026.
Schedule an OT scoping call
Tell us which systems you run and a CyNtell consultant will follow up. No cost and no obligation.
CyNtell municipal OT security at a glance
- Service name
- CyNtell OT Security Services for Municipalities
- Also called
- OT cybersecurity, ICS security, SCADA security, industrial control system security, critical infrastructure cybersecurity
- Who it is for
- Cities, counties, towns, utility districts, public power utilities, water and sewer authorities, and public authorities
- Environments covered
- Water and wastewater SCADA; electric distribution; traffic, transit, and ITS; buildings, facilities, and public safety
- Core services
- OT asset inventory and network monitoring; OT risk assessment; OT incident response and tabletop exercises
- Standards applied
- IEC 62443, NIST SP 800-82 Rev. 3, NIST Cybersecurity Framework (CSF) 2.0, CISA Cross-Sector Cybersecurity Performance Goals
- Regulatory drivers
- SDWA §1433 as amended by AWIA §2013; NERC CIP-003-9 for low-impact BES cyber systems; state law, grant conditions, and cyber insurance
- Pricing model
- Fixed fee scoped by size: sites, controllers, networks, and OT domains in scope
- First step
- A no-cost OT scoping call to size the environment and the engagement
- Delivered from
- Washington, DC area: Maryland, Virginia, and DC on site, and nationwide on site and remotely
What is OT security for a municipality?
Operational technology (OT) security is the protection of the hardware and software that monitor and control physical processes (pumps, valves, breakers, signals, and sensors) rather than the protection of data. In a municipality, OT is what keeps water flowing at pressure, wastewater treated, streetlights and signals timed, power distributed, and public buildings conditioned and locked. OT security is also called ICS security, SCADA security, or industrial cybersecurity; the terms describe the same work from different angles.
CyNtell approaches municipal OT security as an engineering problem with a security overlay, not the reverse. A programmable logic controller (PLC) cannot be patched on Tuesday, a human-machine interface (HMI) cannot be rebooted during a storm event, and a supervisory control and data acquisition (SCADA) system often runs software older than the staff operating it. CyNtell works inside those constraints: passive discovery before active scanning, compensating controls where patching is impossible, and a written path back to manual operation for every process that can be run by hand.
CyNtell serves municipalities specifically because the constraints are different from private industry. A city has an elected body that must approve spending in public, a public works department that answers to residents the same day a service is disrupted, staff who split their time across information technology (IT) and plant duties, and procurement rules that decide how fast anything can happen. CyNtell scopes and writes its municipal OT security work for that reality.
What happened to U.S. water utilities in July 2026?
In late July 2026, coordinated attacks reached internet-exposed programmable logic controllers at water and wastewater systems in at least a dozen states. Attackers changed device passwords and IP addresses to lock operators out, altered control logic, and in some cases disabled alarms, producing pressure loss, flooding, and boil-water advisories rather than stolen data.
internet-exposed water and wastewater systems targeted in July 2026 alone
Reported by CISA, July 2026
states reporting loss of monitoring and control since July 27, 2026
FBI Cyber alert, July 30, 2026
of water systems EPA inspected were in violation of basic SDWA §1433 requirements
EPA enforcement alert, May 2024, covering inspections since September 2023
people served by the 97 drinking water systems rated critical or high cybersecurity risk
EPA Office of Inspector General, November 2024, as cited by the Congressional Research Service
Why are municipal PLCs the target?
CISA advisory AA26-097A, first published April 7, 2026 and updated in July 2026, names Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers and, in the update, Schneider Electric Modicon M340/BMX P34 and Siemens S7-1200 controllers. The exposure route is ordinary industrial protocol ports left reachable from the public internet, such as 44818 (EtherNet/IP), 102 (S7comm), and 502 (Modbus), often with vendor default or shared credentials. One of the flaws in play, CVE-2021-22681, is an authentication bypass in Rockwell Logix controllers rated CVSS 9.8 for which no vendor patch is available.
None of this required a sophisticated intrusion into a city network. It required a controller with a public IP address. CyNtell's first job on most municipal OT engagements is establishing whether any such controller exists in the environment, and that answer is rarely known with confidence before the work starts.
Which municipal systems does CyNtell secure?
CyNtell secures four municipal OT domains: water and wastewater SCADA, electric distribution for public power utilities, traffic and transit control, and building, facility, and public-safety systems. Most cities own all four and hold an accurate inventory of none of them, because each was procured by a different department in a different decade.
Water and wastewater SCADA security
Treatment plant and lift station control, pump and valve logic, chemical dosing setpoints, tank level and pressure telemetry, radio and cellular remote terminal unit (RTU) links, and the historian and reporting systems tied to permit compliance. Water is the domain named in the July 2026 advisories and the one carrying an explicit federal assessment requirement under Safe Drinking Water Act §1433.
Public power and electric distribution
Municipally owned utilities running distribution SCADA, substation automation, protective relays, reclosers, capacitor bank controls, advanced metering infrastructure (AMI) head-end systems, and outage management. Utilities with low-impact bulk electric system (BES) cyber assets also carry NERC CIP-003-9 obligations, whose supply chain revisions became enforceable April 1, 2026, requirements smaller public power utilities frequently discover late.
Traffic, transit, and intelligent transportation systems
Signal controllers and cabinets, advanced traffic management systems, transit signal priority, emergency vehicle preemption, dynamic message signs, cameras and detection, and the fiber and wireless backhaul connecting them. Intelligent transportation systems (ITS) are rarely inventoried alongside plant OT because they sit with transportation rather than public works, which is exactly why they are missed.
Buildings, facilities, and public safety
Building automation systems (BAS) and HVAC controls, physical access control and door hardware, video surveillance, generators and transfer switches, fire and life-safety panels, and the environmental and power systems supporting 911 centers, jails, courthouses, and emergency operations centers. These systems are often vendor-managed with standing remote access nobody in the city can enumerate.
What OT security services does CyNtell provide to municipalities?
CyNtell provides three municipal OT security services: OT asset inventory and network monitoring, OT risk assessment against IEC 62443 and NIST SP 800-82, and OT incident response with tabletop exercises. They are sold separately and run in that order, because a city cannot assess risk in an environment it has not inventoried or rehearse a response for systems it cannot see.
OT asset inventory and network monitoring
Typical first engagement. Establishes what exists before anything is changed.
CyNtell builds a verified OT asset inventory of every controller, HMI, engineering workstation, historian, RTU, radio, and remote-access path in the municipal environment, then establishes continuous network monitoring over the traffic between them. Discovery is passive by default: CyNtell collects from span ports and network taps rather than scanning live control networks, because an active scan is a known way to fault an older PLC.
- Passive asset discovery across plant, substation, signal, and facility networks
- Make, model, firmware, and end-of-support status for every controller found
- Internet-exposure check against the ports and controllers named in AA26-097A
- Enumeration of every vendor and integrator remote-access path into the environment
- IT/OT boundary mapping, including flat-network and dual-homed-workstation findings
- Baseline of normal OT traffic, then alerting on deviation from it
- Offline backup and change-detection for PLC project files and ladder logic
- An asset register the city keeps, in a format its staff can maintain
OT risk assessment against IEC 62443 and NIST SP 800-82
Produces the findings, the priorities, and the document a council or board can act on.
CyNtell's OT risk assessment measures the municipal environment against IEC 62443 and NIST SP 800-82 Rev. 3, the two standards purpose-written for industrial control systems, and maps the results to the NIST Cybersecurity Framework 2.0 functions a city's leadership already reports against. IEC 62443-3-2 supplies the method: divide the environment into zones and conduits, assign each zone a target security level, and measure the gap between the target and what is actually installed.
For water and wastewater clients, CyNtell aligns the assessment with the cybersecurity element of the risk and resilience assessment required by Safe Drinking Water Act §1433, which directs community water systems serving more than 3,300 people to evaluate "electronic, computer, or other automated systems (including the security of such systems)" and certify completion to EPA. For public power clients, CyNtell maps findings to the NERC CIP-003-9 requirements applying to low-impact BES cyber systems.
- Zone and conduit model of the environment per IEC 62443-3-2
- Target security level (SL 1–4) set per zone with the city, not assumed
- Consequence-driven analysis: what physically happens if a zone is lost
- Findings mapped to NIST SP 800-82 Rev. 3 and NIST CSF 2.0
- CISA Cross-Sector Cybersecurity Performance Goals scored as a baseline
- Compensating controls where patching or replacement is not possible
- A prioritized remediation roadmap costed by budget cycle, not by quarter
- A findings summary written for a council or utility board, not for engineers
OT incident response and tabletop exercises
Rehearsed before it is needed, retained for when it is.
CyNtell prepares municipalities for OT incidents and responds when they occur. An OT incident is not an IT incident with different equipment: the first decision is whether the process can be run manually, the second is whether the public is at risk, and the third is who notifies whom, a chain that on a bad day runs through the plant operator, the public works director, the city manager, the mayor, the state primacy agency, CISA, and the local press within the same hour.
CyNtell's OT tabletop exercises put those people in one room and run the scenario that actually happened in July 2026: operators locked out of a PLC, setpoints no longer trustworthy, and no certainty about what the controller is doing. The output is not a score. It is a revised call list, a decision tree for reverting to manual operation, and a written list of what the city could not answer under pressure.
- An OT-specific incident response plan, separate from the city's IT plan
- Manual-operation runbooks per process, validated with the operators
- Tabletop exercises for public works, IT, utilities, and emergency management together
- Notification matrix covering state primacy agencies, CISA, and cyber insurance
- Controller and project-file integrity checks after a suspected compromise
- Post-incident report suitable for a public meeting and for the insurer
How is OT security different from IT security?
IT security protects information and can trade availability for confidentiality; OT security protects a physical process where availability and safety come first and a reboot can mean a spill, an outage, or a signal going dark. CyNtell runs the two disciplines under one program but never with one playbook.
Table 1. How CyNtell's approach differs between municipal IT and municipal OT
| Dimension | Municipal IT | Municipal OT |
|---|---|---|
| Primary objective | Confidentiality of records and resident data | Availability and safety of a physical process |
| Consequence of failure | Breach notification, downtime, recovery cost | Loss of pressure, flooding, outage, signal failure, boil-water advisory |
| Asset lifespan | 3 to 5 years, refreshed on a schedule | 15 to 25 years, replaced only during capital projects |
| Patching | Routine, largely automated | Rare, vendor-gated, often impossible; compensating controls instead |
| Discovery method | Active scanning and agents | Passive collection; active scanning can fault a controller |
| Containment move | Isolate the host, restore from backup | Revert to manual operation, then restore verified logic |
| Who owns it | City IT department | Public works, utilities, transportation, and facilities, frequently with no single owner |
| Governing standards | NIST SP 800-53, CIS Controls, state records rules | IEC 62443, NIST SP 800-82 Rev. 3, NERC CIP, SDWA §1433 |
What cybersecurity rules apply to municipal OT?
There is no single federal OT security mandate for municipalities. Obligations arrive by sector: drinking water systems above a population threshold carry a statutory assessment duty, public power utilities carry NERC CIP obligations, and everything else is governed by grant conditions, insurance requirements, state law, and standards of care. CyNtell maps which of these apply before proposing any work.
Table 2. Cybersecurity obligations most often reaching municipal OT environments
| Authority | Who it reaches | What it requires | Status |
|---|---|---|---|
| SDWA §1433, as amended by AWIA §2013 | Community water systems serving more than 3,300 people | A risk and resilience assessment covering "electronic, computer, or other automated systems (including the security of such systems)," an emergency response plan, and certification to EPA on a recurring cycle | Statutory and in force |
| NERC CIP-003-9 | Municipally owned utilities, public power, and cooperatives with low-impact BES cyber systems | Cyber security policies, electronic access controls, and supply chain risk management for low-impact assets, with supporting evidence | Supply chain revisions enforceable April 1, 2026 |
| NIST SP 800-82 Rev. 3 | Any OT owner; referenced by grantors, insurers, and auditors | Guidance, not a mandate: OT-specific control overlays, risk management, and architecture practices for ICS, SCADA, distributed control systems (DCS), and building control systems | Guidance; published September 2023 |
| IEC 62443 series | Asset owners, integrators, and product suppliers | A consensus standard: zones and conduits, target security levels SL 1 to 4, and requirements allocated across owner, integrator, and vendor | Voluntary; increasingly in procurement |
| CISA Cross-Sector Cybersecurity Performance Goals | All critical infrastructure owners, including local government | A voluntary baseline set of IT and OT practices, commonly used by cities as the floor they measure against first | Voluntary baseline |
| State law, grant conditions, and cyber insurance | Varies by jurisdiction and funding source | Increasingly specific: segmentation, multifactor authentication on remote access, tested backups, and incident reporting timelines as conditions of coverage or funding | Varies; verify locally |
CyNtell provides assessment and advisory services and does not provide legal advice. Municipalities should confirm applicability of any requirement with counsel and with their state primacy or regulatory agency.
How does a CyNtell municipal OT engagement run?
CyNtell runs municipal OT security work in four stages: a scoping call at no cost, a scoped fixed-fee proposal the city can take to procurement, field work performed without interrupting operations, and a handover that leaves the city able to maintain what CyNtell built.
Stage 01
Scoping call
A working conversation with the people who run the systems. CyNtell establishes which OT domains the city owns, roughly how many sites and controllers are involved, who the integrators are, and what has already been assessed. No cost, no obligation.
Stage 02
Scoped proposal
A fixed fee scoped by size: sites, controllers, networks, and domains in scope, written so it can be attached to a purchase requisition or a council agenda item without translation, with the deliverables named.
Stage 03
Field work
On-site and remote work scheduled around plant operations and peak demand. Passive collection first. Every action that could touch a live process is agreed in writing with the operator beforehand and has a defined back-out.
Stage 04
Handover
Findings briefed twice: once to the engineers who will act on them and once to the leadership who will fund them. The city keeps the asset register, the roadmap, and the runbooks in editable form, not as a locked PDF.
Why do municipalities choose CyNtell for OT security?
Municipalities choose CyNtell because CyNtell does not sell the control systems it assesses, covers all four municipal OT domains rather than water alone, and writes its findings for two audiences at once: the engineers who will fix them and the elected officials who must fund them.
No commercial interest in the findings
CyNtell does not sell, install, or maintain municipal SCADA or control systems. Nothing in a CyNtell report creates a hardware sale, so a finding about an integrator's remote access is written the same way whether or not the city keeps that integrator.
All four OT domains, one assessment
Most OT firms serving local government sell water only. CyNtell assesses water, power, traffic, and facilities in a single engagement, which is the only way a city sees its whole OT attack surface instead of one department's quarter of it.
Assessment discipline from C3PAO work
CyNtell is an Authorized C3PAO conducting CMMC certification assessments against a federal standard. The same evidence discipline, a documented basis for every finding, repeatable by another assessor, is what CyNtell brings to municipal OT work.
Written for the council, not just the plant
Every CyNtell municipal OT deliverable includes a version a city manager can take to a public meeting: what the risk is, what it costs to close, and what happens if it is deferred another budget cycle.
Public-sector contracting fluency
CyNtell works in federal and public-sector contracting every day and writes scopes, fees, and deliverables to survive a procurement review rather than requiring the city to rewrite them first.
The city keeps what CyNtell builds
Asset registers, zone diagrams, runbooks, and the remediation roadmap are handed over in editable form. A CyNtell engagement is meant to leave the city more capable, not more dependent.
Where does CyNtell provide municipal OT security services?
CyNtell is based in the Washington, DC area and provides municipal OT security services nationwide. CyNtell works on site throughout Maryland, Virginia, and the District of Columbia, and travels to municipal clients across the United States, with the remote portions of each engagement handled from the DC-area office.
The DC region concentrates an unusual density of small water and sewer authorities, municipal utilities, and county public works departments operating industrial control systems within a short drive of one another, and CyNtell's proximity means site visits do not carry national-firm travel costs. For municipalities outside the region, CyNtell scopes the on-site portion tightly: the walkdowns, cabinet inspections, and operator interviews that genuinely require presence, and performs the rest remotely, which keeps a small city's engagement affordable without thinning the work.
Municipal OT security questions, answered
What is OT security?
OT security is the protection of operational technology: the controllers, sensors, and supervisory systems that run physical processes such as water treatment, power distribution, and traffic signals. Unlike IT security, OT security prioritizes availability and safety over confidentiality, because a failure changes what happens in the physical world rather than who can read a file.
What is SCADA security?
SCADA security is OT security applied to supervisory control and data acquisition systems: the servers, HMIs, historians, and telemetry links operators use to watch and control a plant or a distribution network from a central location. In a municipality, SCADA security usually means the water or wastewater plant first, since that is where a city's SCADA system is largest.
Does a small town really need OT security?
Small systems are the ones being hit. The July 2026 attacks reported by CISA reached more than 100 internet-exposed water and wastewater systems, including roughly 30 community water systems in Minnesota. The attackers were not selecting targets by population; they were selecting by exposure, and small systems are the most likely to have a controller reachable from the internet.
Who is responsible for OT security in a city?
Usually nobody, formally. City IT owns the network, public works owns the plant, transportation owns the signals, and facilities owns the buildings, and municipal OT sits in the gaps between them. CyNtell's assessments name an owner for every finding, which is frequently the most useful thing a city gets out of the engagement.
Will CyNtell's assessment disrupt plant operations?
CyNtell's OT discovery is passive by default, collecting from span ports and taps rather than scanning live control networks, because active scanning is a documented way to fault an older controller. Any step that could touch a running process is agreed in writing with the operator in advance, scheduled around plant operations, and carries a defined back-out.
Does an AWIA risk and resilience assessment cover cybersecurity?
Yes. Safe Drinking Water Act §1433, as amended by AWIA §2013, requires community water systems serving more than 3,300 people to assess "electronic, computer, or other automated systems (including the security of such systems)" and certify completion to EPA. CyNtell's OT risk assessment is built to satisfy that cybersecurity element and to stand on its own technically.
What is the difference between IEC 62443 and NIST SP 800-82?
IEC 62443 is an international consensus standard that divides responsibility between asset owners, integrators, and product vendors and uses zones, conduits, and security levels as its method. NIST SP 800-82 Rev. 3 is U.S. federal guidance that overlays OT-specific practice onto NIST's control catalog. CyNtell uses IEC 62443 for structure and NIST SP 800-82 for control detail.
Does cyber insurance require OT security controls?
Increasingly, yes: municipal cyber policies and renewal questionnaires now commonly ask about network segmentation, multifactor authentication on remote access, and tested backups, and some ask specifically about control system exposure. CyNtell's assessment findings are written so a city can answer those questions with evidence rather than estimates. Confirm your own policy's terms with your broker.
Our SCADA vendor says the system is secure. Is a third-party assessment still worth it?
A SCADA integrator is assessing its own work, and its remote-access path into the city's environment is one of the things an assessment examines. CyNtell does not sell, install, or maintain municipal control systems, so its findings carry no commercial interest in the outcome, including findings about the integrator's own connectivity and credentials.
Does CyNtell work with our existing IT department and MSP?
Yes. Municipal OT almost always sits between departments, so CyNtell expects to work alongside city IT, the utilities or public works staff who own the process, and any managed service provider already under contract. CyNtell's deliverables name who owns each remediation item, which is usually the part that has never been written down.
What should a city do first if it suspects an OT compromise right now?
Move the affected process to manual operation if it can be run by hand, preserve the controller state rather than power-cycling it, disconnect the controller from any internet-reachable path, and notify CISA and the state primacy agency. Then call CyNtell. Do not restore PLC logic from a backup until the backup itself has been verified as unmodified.
How much do OT security services cost for a municipality?
CyNtell prices municipal OT security engagements as a fixed fee scoped by the size of the environment: the number of sites, controllers, networks, and OT domains in scope, rather than by the hour, so a city knows the number before it goes to procurement. Schedule a scoping call to get a scoped number for your environment.
Start with an OT scoping call
Bring the people who run the plant, the signals, or the substation. In one conversation CyNtell will tell you which OT domains are in scope, what an engagement would cover, and what it would cost, at no charge and with no obligation.
or call 1 (833) CYNTELL, +1-833-296-8355
References
- CISA, FBI, and partners. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure, advisory AA26-097A, published April 7, 2026 and updated July 2026.
- Federal Bureau of Investigation. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions, July 30, 2026.
- Congressional Research Service. July 2026 Water System Cyber Incidents: Considerations for Congress, IF13298.
- U.S. Environmental Protection Agency. Cybersecurity Assessments for Water and Wastewater Systems.
- National Institute of Standards and Technology. SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, September 2023.
- Cybersecurity and Infrastructure Security Agency. Cross-Sector Cybersecurity Performance Goals.
- North American Electric Reliability Corporation. CIP-003-9, Cyber Security: Security Management Controls; supply chain revisions for low-impact BES cyber systems enforceable April 1, 2026.
- International Electrotechnical Commission. IEC 62443 series, Security for industrial automation and control systems, including IEC 62443-3-2 on zone and conduit risk assessment.
Page reviewed September 2026. CyNtell updates this page when the underlying advisories or requirements change.