This Week in Cyber: September 17 - 23, 2026
Attackers reached operational controls at U.S. water systems this week as new research exposed persistent gaps in OT visibility and segmentation. NIST expanded its operational technology security guidance, federal agencies turned their attention to third party ICS integrators, and AI moved another step closer to frontline critical infrastructure defense.
Foreign actors manipulate controls at Colorado water utilities
On September 18, Colorado officials disclosed that foreign actors breached two small drinking water providers in late August. The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. Both utilities serve fewer than 200 people, and officials said treatment processes, water quality and public safety were not affected. The incidents follow a larger wave of attacks against U.S. water and wastewater systems. Earlier this summer, federal officials reported cyber activity affecting roughly 100 water entities across about a dozen states, including attempts to manipulate internet facing programmable logic controllers (PLCs).
Why it matters: This isn't an isolated access problem anymore. Attackers reached equipment controlling a physical process and changed how it operated. Then, only days after the Colorado disclosure, new research found active infostealer exposure tied to 1,787 U.S. water and wastewater organizations, including hundreds with credentials associated with OT or remote access systems. One compromised device at a metering technology provider contained saved logins tied to roughly 167 utility customers. There’s no evidence that stolen credentials were used in the Colorado incidents, but the signals point in the same direction. Water operators are dealing with multiple paths into the environment at once: exposed controllers, weak or default credentials, remote access and compromised third parties. Know what's reachable, remove control systems from the public internet where possible, restrict and monitor remote access, and make sure operators can still see and control the process when remote systems or alarms fail.
NIST expands its operational technology security guidance
On September 21, NIST released the initial public draft of SP 800 82 Revision 4, its updated Guide to Operational Technology Security. The revision expands its treatment of OT beyond traditional industrial control systems to include water and wastewater, maritime vessels, freight rail, building automation, food and agriculture, IIoT and cloud connected environments. The update also places more emphasis on asset management, network monitoring and detection, OT security architecture and protecting system management functions, while restructuring the guidance around the NIST Cybersecurity Framework 2.0.
Why it matters: This is part of a larger shift in how NIST is approaching OT security. In June, NIST published a practical architecture for secure remote access into water and wastewater OT. It also released OT backup guidance focused on recovery from cyber incidents and system failures. Now the core OT security guide is putting more weight behind asset visibility, monitoring, architecture and recovery. For operators, the direction is clear. OT cybersecurity is moving beyond perimeter protection and compliance checklists. Teams need to know what's in the environment, understand what those systems are communicating with, control the paths used to reach them and maintain the evidence and recovery capability needed when something gets through.
New research shows the gap between OT maturity and actual visibility
On September 22, Honeywell released its 2026 OT Cybersecurity Benchmark Report. Eighty eight percent of surveyed industrial cybersecurity leaders described their OT cybersecurity programs as mature, but only 21 percent reported having a complete inventory of their OT assets. Organizations also reported an average of 16.2 hours of downtime from their most significant cyber incidents. Another analysis released the same day found a similar gap underneath the network architecture. Forescout researchers examined 47,700 network segments containing more than 2.5 million devices across 209 organizations. Only 13 percent of segments containing OT devices contained OT devices alone, with most sharing network space with IT or IoT assets.
Why it matters: Put those findings next to this week's NIST guidance. Organizations overwhelmingly say their OT programs are mature while many still can't completely inventory their environments or consistently isolate operational systems from other devices. You can't quickly determine blast radius if you don't know what's connected, and segmentation on paper doesn't help if a compromised IT or IoT device can still reach operational equipment. Before adding another security product, operators should be able to answer three basic questions: What’s here? What’s it communicating with? What can it reach if it's compromised?
FBI and CISA put third party ICS integrators in the spotlight
On September 23, the FBI and CISA issued new guidance for critical infrastructure organizations working with third party ICS integrators. The warning is based on an actual compromise, not a hypothetical supply chain scenario. According to FBI technical analysis, foreign cyber actors gained access to a U.S. industrial automation company in 2025 that provided system integration, engineering and SCADA programming to industrial customers, including power and transportation organizations. The actors searched the compromised network for terms including "customers" and "SCADA" and staged approximately 800 files containing customer SCADA information, ICS device details and schematics for presumed exfiltration. The agencies are telling operators to evaluate internet exposure, monitor and log integrator remote access, maintain inventories of hardware and software supplied by integrators, include cybersecurity requirements in service agreements and retain the ability to operate independently if the integrator is compromised.
Why it matters: The Colorado incidents show attackers reaching operational controls. The water credential research shows how one compromised vendor device can expose access associated with scores of separate utilities. Now the FBI and CISA are explicitly telling critical infrastructure operators to treat the ICS integrator itself as part of the attack surface. For small utilities, manufacturers and municipal operators, outside engineering and controls firms are often necessary. That also means the organization protecting the PLCs may not be the only organization with a pathway to them. Operators need to know who can remotely reach the environment, what data those third parties hold, when that access is being used and whether the facility can continue operating if the third party disappears or is compromised.
Ukraine brings frontier AI into critical infrastructure cyber defense
Also on September 23, OpenAI announced that Ukraine will receive access to its Daybreak cyber defense program through a partnership with the country's Ministry of Digital Transformation. Verified Ukrainian teams will receive cyber tools, training and technical support to identify vulnerabilities and develop and test fixes faster across civilian critical infrastructure. The tools are intended to support authorized defensive work including reviewing software, investigating suspicious activity, validating vulnerabilities and testing remediation. Ukraine's CERT handled nearly 6,000 cyber incidents in 2025, including activity affecting energy, telecommunications and hospitals.
Why it matters: This isn't the only place AI is moving into critical infrastructure defense. DOE's CESER has been building its AI FORTS program around defending infrastructure from AI enabled attacks, using AI for threat detection, threat hunting, OT and ICS visibility and incident response, and securing the AI systems being introduced into energy environments. CESER and Lawrence Livermore also launched Stormbreaker to test LLMs and agentic AI inside power and OT environments. And CESER and Sandia recently demonstrated AI being used to identify and locate grid cyber threats in near real time. Those are separate programs, but they're pointing in the same direction. AI assisted cyber defense is moving from research into operational use. The value to an operator isn't handing control of the plant to an autonomous model. It's reducing the time spent working through telemetry, vulnerabilities and incident evidence so defenders can understand what happened and act while the information still matters.
That’s it for this week.
We’ll be back next Thursday with the next Weekly Roundup.