On July 30, CISA issued an urgent alert to the Water and Wastewater Systems Sector: remove publicly exposed programmable logic controllers and other operational technology from the internet, as soon as possible. The agency reported a significant increase in threat actors targeting PLCs in the sector — changing device passwords to lock operators out, altering IP addresses to sever devices from their control networks, and leaving utilities running in sustained manual operation. Some issued boil water notices. CISA was explicit that entities of all sizes are being targeted.
The alert did not arrive in a vacuum. Days earlier, on July 26 and 27, a coordinated attack disrupted operational technology at more than 30 community water and wastewater utilities across Minnesota. Braham’s water plant went offline. Plymouth lost cellular communications to two water towers and multiple lift stations and reverted to manual control. Maple Plain declared a local state of emergency. Federal agencies have since reported similar internet-facing PLC activity across at least seven states, and the timing follows an updated CISA advisory warning that state-affiliated actors were compromising internet-connected PLCs from Rockwell Automation, Siemens, and Schneider Electric across water, energy, and government sectors.
Here is the detail that should grab the attention of every OT engineer: none of this required a novel exploit. No custom malware, no zero-day, no sophisticated tradecraft. The controllers were reachable from the public internet. That was the vulnerability. CISA specifically called out cellular modems installed by operators, vendors, or system integrators — connections that are frequently undocumented and absent from routine attack surface scans. Many utilities did not know the door existed, let alone that it was unlocked.
The window between “known” and “fixed” is where OT lives
CISA’s recommended mitigations are sound: disconnect the PLC from the internet, route remote access through a VPN or gateway, enable password protection, allowlist known engineering assets, and maintain a clean PLC image backup. Every operator should do all of it today.
But each of those controls is a configuration. Configurations drift. Integrators add modems. Firewall rules get relaxed for a Friday-night troubleshooting session and never get restored. VPN concentrators develop CVEs of their own. A software control is a promise that something should not happen; it is only as durable as the last person who touched it, and the security of the software itself.
That fragility has been somewhat survivable because attackers operated at human speed. That assumption is now expiring.
AI changes the tempo, not just the toolkit
Three shifts matter for critical infrastructure operators.
Machine-scale discovery. Frontier models have moved from assisting with vulnerability research to conducting it. In May, Google’s Threat Intelligence Group disclosed the first verified case of threat actors using AI to discover and weaponize a previously unknown flaw, producing a working exploit for a mass-exploitation campaign. Security researchers now describe autonomous vulnerability discovery and exploitation as compressing the window between disclosure and working exploit from months to minutes.
Machine speed. Documented autonomous intrusions have chained credential theft, lateral movement through a bastion host, and database exfiltration inside a single hour — adapting to an unfamiliar network without pre-written scripts. In July, OpenAI disclosed that models under evaluation escaped a sandboxed test environment and compromised a third party’s production infrastructure on their own initiative.
Machine scale with a human-sized crew. Palo Alto Unit 42 has documented a threat actor running an offensive campaign through an agent framework in which the model handled target selection, asset enumeration, vulnerability assessment, and exploit generation — orchestrated over a chat interface by a single operator. Reconnaissance against every internet-exposed MicroLogix in North America is no longer a research project. It is an afternoon.
Yes, defenders are deploying the same technology, and it is genuinely useful. But the defensive half of this race is bounded by things AI cannot compress. A water utility cannot patch a PLC without an OEM-validated firmware release, a maintenance window, a process outage, and often a control system integrator on site. Much of the installed base is end-of-life and will never receive a patch at all. Small utilities — the ones being hit — typically have no dedicated OT security staff at all. Attack automation scales with compute. Remediation scales with truck rolls, budget cycles, and regulatory sign-off. The gap is structural, and AI widens it.
Isolation you cannot misconfigure
This is why hardware-enforced unidirectional security remains the only control in the OT stack that does not degrade under this pressure. A data diode is not a policy or a rule set. It is a physical layer with a transmit-only path on one side and a receive-only path on the other. There is no return channel to exploit, no credential to steal, no rule to misconfigure, and no software logic for an adversary — human or autonomous — to reason its way around. An AI agent that can find a novel flaw in any device on the network still cannot send even a single packet into the OT.
Critically, isolation does not mean going dark. Owl’s data diode and cross domain solutions replicate historian data, SCADA telemetry, alarms, and compliance reporting out of the OT enclave to enterprise, cloud analytics, and vendor monitoring platforms — with full fidelity and no route back in. Utilities get the operational visibility that pushed them to connect these systems in the first place, without the exposure that CISA is now asking them to eliminate.
CISA’s guidance is to get PLCs off the internet. A data diode is how you stay off it — enforced by physics rather than by the last configuration change nobody documented.


