Minnesota Water-System Cyberattacks: Lessons for Utility Readiness
Executive Readiness RoomTurn your ACRA Snapshot into governance priorities, ownership decisions, and a readiness roadmapAugust 19, 2026Apply for Your Seat → Executive Readiness RoomTurn your ACRA Snapshot into governance priorities, ownership decisions, and a readiness roadmapAugust 19, 2026Apply for Your Seat → Executive Readiness RoomTurn your ACRA Snapshot into governance priorities, ownership decisions, and a readiness roadmapAugust 19, 2026Apply for Your Seat → Executive Readiness RoomTurn your ACRA Snapshot into governance priorities, ownership decisions, and a readiness roadmapAugust 19, 2026Apply for Your Seat →
Water utility operational readiness, Direnzic Technology analysis
Direnzic Insights

The Minnesota Water-System Cyberattacks: A Lesson in Readiness, Not Fear

Editor's note: This analysis reflects information publicly available as of July 31, 2026. Direnzic will update this article if material official findings change the operational assessment.

On July 26 and 27, 2026, a coordinated cyberattack targeted operational technology supporting more than 30 Minnesota community water systems. Minnesota IT Services activated the state's cybersecurity incident-response capabilities and began coordinating with federal, state, local, Tribal, and private-sector partners.

Separately, public reporting describes operational disruptions at several utilities, including interruptions affecting automated controls and remote communications. At least one community experienced a temporary interruption involving its water-treatment operations. Officials have reported no evidence that drinking-water safety was affected, and investigators have not yet publicly disclosed the complete initial-access method, all affected technologies, or a final attribution.

Those are the central facts publicly confirmed by Minnesota officials. Other technical and attribution details remain incomplete, preliminary, or under investigation. After 18 years working in cybersecurity and critical-infrastructure risk, here is what I believe this event teaches, and what every utility leader should do with it.

The part of the story worth studying

Public reporting indicates that some affected utilities maintained or restored operations through manual or alternate procedures while responders investigated.

That detail deserves attention because it points to a capability utility leaders can control. A utility cannot guarantee that an adversary will never reach its systems. It can determine whether personnel know how to maintain safe conditions when normal automation, telemetry, or communications become unavailable or unreliable.

Trained personnel, usable contingency procedures, and practiced alternate operations can reduce the operational consequences of a cyber incident. Minnesota does not suggest that technology defenses are unimportant. It reinforces why resilience must extend beyond prevention.

Certified is not rehearsed

Most water-sector leaders reading this have completed significant compliance work in recent years. Community drinking-water systems serving more than 3,300 people are required under AWIA to develop or update a Risk and Resilience Assessment and Emergency Response Plan and certify completion to EPA. These assessments and plans must be reviewed and, where necessary, revised at least once every five years.

That work matters. But certification confirms completion of the required work. It is not an EPA approval of the document's quality, and it does not, by itself, demonstrate that personnel can execute the procedures during a live cyber-physical disruption, at 2 a.m., with uncertainty about whether they are facing a malfunction or an attack.

This is the gap Minnesota has brought back into focus for the entire sector: the distance between documentation that satisfies a requirement and procedures a team has actually rehearsed. Your ERP should work when your SCADA system does not. The first time your team follows its cyber-response procedures should not be during the event itself.

Your ERP should work when your SCADA system does not.

Direnzic Technology

Three questions every utility should answer with evidence

Direnzic readiness framework showing three pillars: Visibility, know every system, connection, vendor pathway, and operational dependency; Resilience, maintain safe operations when telemetry, remote access, or automation is unavailable; Response, recognize, contain, escalate, communicate, and recover under pressure.

Whenever I sit down with a utility's leadership, whether a small community system or a large regional operation, readiness comes down to three questions. Not answered with confidence or assumption, but with evidence.

Visibility. Do we know every device, system, communication pathway, vendor connection, and dependency touching our operational services? Utilities sometimes discover connections that were not reflected in their current inventory: an integrator's remote-support account, a cellular modem installed during an earlier project, or a cloud service creating an overlooked dependency between business and operational systems.

Resilience. If normal telemetry, remote access, or automation became unavailable or unreliable tonight, could our operators maintain safe conditions using approved alternate procedures? Do they know the staffing requirements, safety limits, decision authority, and communication channels for operating that way, and when did they last practice it?

Response. Does our team know how to recognize a potential cyber event, distinguish it from an equipment failure, preserve evidence, restrict affected access while preserving safe operating conditions, and coordinate with leadership, vendors, state authorities, CISA, the FBI, and EPA?

Utilities that can answer these three questions are better positioned to contain disruption, maintain essential services, and make defensible decisions under pressure. Where those answers are uncertain, the utility has a measurable readiness gap that can be addressed before an incident occurs.

Five actions to take now

Consistent with current joint CISA, EPA, and FBI guidance, these are five actions I would prioritize at a community water system now:

  1. Inventory operational technology and connectivity. Document IT and OT assets, cellular communications, remote-access tools, vendor and integrator pathways, cloud services, and IT-to-OT dependencies. Confirm who owns each connection and whether it remains necessary.
  2. Reduce and harden remote exposure. Disable unnecessary access, remove default and shared credentials, use multifactor authentication where technically supported, restrict access by user, source, and time, and review all vendor accounts.
  3. Validate alternate and manual operations. Confirm that personnel understand approved procedures, staffing requirements, safety limits, decision authority, and communications when normal telemetry or automation is unavailable.
  4. Operationalize the ERP and cyber-response procedures. Confirm that the plan addresses detection, containment, notification, evidence preservation, continuity, protected backups, restoration priorities, recovery validation, and coordination with the agencies and vendors who will participate in a real response.
  5. Exercise the first operational period. Conduct a tabletop scenario involving loss of SCADA visibility or control, uncertain cause, degraded communications, public pressure, vendor coordination, and leadership decisions. Nothing surfaces the gap between paper and practice faster.

Not every action requires a major capital project. Several begin with governance decisions, accurate inventories, access reviews, documented procedures, and a structured exercise. Together, they move a utility from assuming readiness to building evidence of it.

A closing thought on attribution

Public reporting has raised the possibility of nation-state involvement in the Minnesota campaign, and federal investigators may release additional findings as the investigation develops. For utility planning purposes, I would encourage leaders not to wait on that answer and not to over-index on it when it arrives. Whoever is ultimately named, the operational questions above remain the same, and they are worth answering regardless of which adversary the news cycle features next.

Small and mid-sized systems are not outside the threat landscape. Limited staffing and cybersecurity resources can make community systems harder to defend and recover, but attackers do not need a nationally prominent target to create meaningful disruption. Readiness is not a big-utility luxury. It is an operational requirement, and it is within reach.


About the author

Ieshea Hollins, Founder, CEO and CISO of Direnzic Technology Consulting Group, a critical-infrastructure cybersecurity and AI-governance firm founded in 2008. Her work focuses on helping water utilities, municipalities and other essential-service organizations move from documented compliance to defensible operational readiness.

Water Utility Cyber-Operational Readiness Review

A practical next step

Direnzic's Water Utility Cyber-Operational Readiness Review is a focused, non-disruptive engagement that evaluates:

  • RRA and ERP cyber-readiness
  • Operational connectivity and remote-access exposure
  • Manual and alternate operating readiness
  • Incident notification and escalation procedures
  • Leadership decisions during the first operational period

The engagement concludes with a leadership scenario walkthrough and a prioritized 30-, 60-, and 90-day action plan.

Schedule a Readiness Discussion

Sources and official resources

>