Minnesota Water Cyberattacks: Why SCADA Architecture Matters
How cloud-based SCADA can reduce exposed infrastructure, replace fragile remote-access workarounds, and help utilities move beyond the illusion of an air gap.

A warning for every municipal utility
In late July 2026, more than 30 municipal water systems in Minnesota were targeted in coordinated cyberattacks. Public reporting indicated that some communities temporarily lost access to operating controls or experienced service disruptions, while operators relied on manual procedures to maintain service. Investigators had not publicly confirmed the responsible actor at the time of publication.
The immediate lesson is not simply that utilities need stronger passwords or another security appliance. The deeper lesson is that the architecture surrounding operational technology determines how many opportunities an attacker has to reach it.
Many water systems were built when remote access was rare, staffing was local, and controllers were assumed to be isolated. Over time, however, utilities added practical conveniences: remote alarm notifications, vendor support, cellular routers, business-network reporting, VPN access, remote desktop, and Internet-connected computers. Each addition may be reasonable by itself. Together, they can create a chain of trust that reaches all the way to the control network.
Manual operating procedures, local control capability, accurate documentation, and trained staff remain essential. Cloud connectivity should supplement resilient local control - never replace it.
Most systems are less isolated than operators think
An air gap means there is no electronic path between the protected control environment and outside networks. In practice, truly air-gapped municipal SCADA systems are uncommon because modern operations require information to move in and out.
A system may be described as air gapped even while one or more of the following are present:
These connections do not automatically make a system insecure. They do mean the system is not truly air gapped, and each pathway must be identified, managed, monitored, and maintained.
The question is not whether the PLC has an Internet connection. The question is whether anything that can reach the PLC has an Internet connection.
More components create more doors to defend
Traditional SCADA remote access often depends on a collection of independently managed technologies. A utility may need a server, VPN concentrator, firewall rules, public IP addresses, remote desktop gateway, alarm dialer, database, backup process, antivirus software, domain accounts, and third-party applications. Each component adds value, but each also adds configuration, credentials, patches, logs, and failure modes.
The result can be an architecture that is difficult for a small utility to inventory and defend consistently. Even a well-configured system can become vulnerable when passwords are reused, contractors retain access, operating systems age, firewall rules accumulate, or temporary troubleshooting connections become permanent.
Reduce the infrastructure that must be exposed and maintained
A well-designed cloud SCADA platform does not make cybersecurity automatic, but it can simplify the security problem. SimpliScada is designed to eliminate the need for local SCADA servers, traditional VPN access, Remote Desktop, and several third-party software layers commonly used to deliver remote visibility and alarms.
Instead of requiring users to enter the plant network to reach a local SCADA computer, authorized operators use secure web and mobile applications. The on-site communication link connects the controller to the hosted platform, allowing the utility to centralize monitoring, reporting, alarming, and authorized control without publishing the local HMI or PLC directly to the Internet.

Cloud-based SCADA should not expose industrial protocols directly to the Internet. The safer design is to keep PLC communications local, minimize inbound connectivity, authenticate users through the hosted platform, and preserve local autonomous control.
Do not ask only whether the SCADA system is connected
Ask how many systems, people, credentials, and devices can become a bridge to it. Ask whether remote access requires entry into the plant network. Ask whether operators can maintain safe control when communications fail. Ask whether the utility can quickly identify and disable every external pathway during an incident.
Cloud-native SCADA can help by replacing a collection of exposed and locally maintained remote-access tools with a purpose-built platform. The security benefit comes not from the word “cloud,” but from a simpler architecture: fewer servers, fewer inbound pathways, centralized access control, encrypted communications, site isolation, and resilient local operation.
The strongest “air gap” is not a label. It is a verified architecture with no hidden bridges, no forgotten remote tools, and no unnecessary pathways into operational technology.
Cloud SCADA for municipal water operations
SimpliScada provides cloud-based monitoring, alarming, reporting, visualization, and authorized control for municipal water, wastewater, oil and gas, and other industrial applications. Its public materials describe an end-to-end platform designed to reduce reliance on VPNs, on-premises servers, Remote Desktop, and separate third-party alarm and reporting tools.
Learn more: simpliscada.com | Phone: 833-561-0025
Ready to simplify your SCADA operations?
Connect with SimpliScada to discuss secure cloud SCADA for your water or wastewater system.
Sources and notes
- Associated Press, July 30, 2026. Reporting on attacks affecting more than 30 Minnesota water systems and the ongoing investigation.
- The Wall Street Journal, July 31, 2026. Reporting on a broader wave of attacks against U.S. water and wastewater facilities.
- SimpliScada public website, accessed August 2026. Product descriptions regarding cloud SCADA, mobile and web access, elimination of traditional VPN/server dependencies, alarms, reporting, and municipal-water applications.
- General cybersecurity guidance. The recommended practices in this brief align with commonly accepted OT security principles: minimize Internet exposure, segment networks, control remote access, maintain asset inventories and backups, and preserve manual operating capability.
Important
This document is educational and does not constitute a guarantee of security, a site-specific risk assessment, or legal or regulatory advice. Security capabilities and deployment details should be confirmed for each project. Utilities should coordinate with qualified integrators, IT/OT security professionals, state authorities, CISA, EPA, and WaterISAC as appropriate.

