Minnesota Water Cyberattacks: Why SCADA Architecture Matters

Security brief for water operators & system integrators

Minnesota Water Cyberattacks: Why SCADA Architecture Matters

How cloud-based SCADA can reduce exposed infrastructure, replace fragile remote-access workarounds, and help utilities move beyond the illusion of an air gap.

Prepared for: Municipal water and wastewater operators, managers, engineers, and system integrators Prepared by: SimpliScada August 2026
SimpliScada web and mobile SCADA interface
The central question
A PLC may not be directly connected to the public Internet - but can anything that reaches the PLC connect outward, receive a message, accept a remote session, or bridge to another network?
What happened

A warning for every municipal utility

In late July 2026, more than 30 municipal water systems in Minnesota were targeted in coordinated cyberattacks. Public reporting indicated that some communities temporarily lost access to operating controls or experienced service disruptions, while operators relied on manual procedures to maintain service. Investigators had not publicly confirmed the responsible actor at the time of publication.

The immediate lesson is not simply that utilities need stronger passwords or another security appliance. The deeper lesson is that the architecture surrounding operational technology determines how many opportunities an attacker has to reach it.

Many water systems were built when remote access was rare, staffing was local, and controllers were assumed to be isolated. Over time, however, utilities added practical conveniences: remote alarm notifications, vendor support, cellular routers, business-network reporting, VPN access, remote desktop, and Internet-connected computers. Each addition may be reasonable by itself. Together, they can create a chain of trust that reaches all the way to the control network.

Operational resilience mattered
Manual operating procedures, local control capability, accurate documentation, and trained staff remain essential. Cloud connectivity should supplement resilient local control - never replace it.
The air-gap illusion

Most systems are less isolated than operators think

An air gap means there is no electronic path between the protected control environment and outside networks. In practice, truly air-gapped municipal SCADA systems are uncommon because modern operations require information to move in and out.

A system may be described as air gapped even while one or more of the following are present:

V
A VPN used by operators, integrators, vendors, or support technicians
R
Remote Desktop, remote support software, or an exposed web interface
A
A text-message, email, or voice-call alarm service connected to the SCADA computer
C
A cellular modem or radio gateway that provides an alternate route into the site
L
An engineering laptop that moves between the plant, office, home, and customer sites
D
A historian, reporting server, or shared database connected to both OT and IT networks
W
A Windows workstation that browses the Internet or receives software updates
U
USB drives, removable media, or contractor equipment introduced into the control environment

These connections do not automatically make a system insecure. They do mean the system is not truly air gapped, and each pathway must be identified, managed, monitored, and maintained.

A practical test for the air gap

The question is not whether the PLC has an Internet connection. The question is whether anything that can reach the PLC has an Internet connection.

Why traditional remote access expands risk

More components create more doors to defend

Traditional SCADA remote access often depends on a collection of independently managed technologies. A utility may need a server, VPN concentrator, firewall rules, public IP addresses, remote desktop gateway, alarm dialer, database, backup process, antivirus software, domain accounts, and third-party applications. Each component adds value, but each also adds configuration, credentials, patches, logs, and failure modes.

Common component
Operational purpose
Security burden
VPN
Remote operator or vendor access
Credentials, MFA, patching, exposed gateway, account lifecycle
SCADA server
HMI, alarming, history, reporting
OS hardening, backups, antivirus, patch testing, local admin control
Remote desktop
Access to local applications
Brute-force risk, session security, exposed services, shared accounts
Alarm software
Text, email, or voice notifications
External integrations, service credentials, network access
Engineering laptop
Programming and troubleshooting
Portable bridge between trusted and untrusted networks

The result can be an architecture that is difficult for a small utility to inventory and defend consistently. Even a well-configured system can become vulnerable when passwords are reused, contractors retain access, operating systems age, firewall rules accumulate, or temporary troubleshooting connections become permanent.

How cloud SCADA can help

Reduce the infrastructure that must be exposed and maintained

A well-designed cloud SCADA platform does not make cybersecurity automatic, but it can simplify the security problem. SimpliScada is designed to eliminate the need for local SCADA servers, traditional VPN access, Remote Desktop, and several third-party software layers commonly used to deliver remote visibility and alarms.

Instead of requiring users to enter the plant network to reach a local SCADA computer, authorized operators use secure web and mobile applications. The on-site communication link connects the controller to the hosted platform, allowing the utility to centralize monitoring, reporting, alarming, and authorized control without publishing the local HMI or PLC directly to the Internet.

SimpliScada mobile and web monitoring
Fewer exposed servicesReducing reliance on public-facing VPNs, Remote Desktop, and local web servers removes common remote-access targets.
Less infrastructure to patchEliminating local servers and third-party applications reduces the number of operating systems, databases, licenses, and backup jobs the utility must maintain.
ID
Centralized identity and accessCloud applications can support managed user accounts, role-based access, stronger authentication, and faster removal of former employees or contractors.
Built-in remote visibilityOperators can receive alarms and access authorized dashboards without opening a general-purpose pathway into the control network.
S
Site-by-site separationIndependent site connections can limit the need for a broad shared network spanning wells, lift stations, tanks, and treatment facilities.
Important distinction

Cloud-based SCADA should not expose industrial protocols directly to the Internet. The safer design is to keep PLC communications local, minimize inbound connectivity, authenticate users through the hosted platform, and preserve local autonomous control.

Security is a shared responsibility

Architecture helps, but disciplined operations still matter

No SCADA platform can compensate for every weakness in field wiring, controller logic, user practices, or physical security. Utilities and integrators should treat cloud SCADA as one layer in a defense-in-depth program.

1
Inventory every connectionDocument every route into or out of the control environment, including cellular, radio, vendor, alarm, IT, and maintenance connections.
2
Remove unnecessary accessDisable unused accounts, ports, remote tools, and vendor connections. Avoid leaving temporary troubleshooting access in place.
3
Separate OT from business ITUse clear network boundaries and avoid dual-homed computers that connect simultaneously to control and office networks.
4
Use strong identity controlsRequire unique accounts, strong passwords, MFA where supported, least privilege, and prompt offboarding.
5
Protect controller logicMaintain verified backups of PLC programs and configurations. Restrict programming access and track changes.
6
Maintain local fallbackEnsure pumps, wells, tanks, and treatment processes can operate safely when Internet, cloud, or communications services are unavailable.
7
Practice incident responseDefine who disconnects remote access, who contacts state and federal partners, and how the utility switches to manual operation.
8
Review the design annuallyNetworks change. Reassess firewall rules, remote pathways, third-party access, and undocumented exceptions on a regular schedule.
A better question for every utility

Do not ask only whether the SCADA system is connected

Ask how many systems, people, credentials, and devices can become a bridge to it. Ask whether remote access requires entry into the plant network. Ask whether operators can maintain safe control when communications fail. Ask whether the utility can quickly identify and disable every external pathway during an incident.

Cloud-native SCADA can help by replacing a collection of exposed and locally maintained remote-access tools with a purpose-built platform. The security benefit comes not from the word “cloud,” but from a simpler architecture: fewer servers, fewer inbound pathways, centralized access control, encrypted communications, site isolation, and resilient local operation.

Bottom line
The strongest “air gap” is not a label. It is a verified architecture with no hidden bridges, no forgotten remote tools, and no unnecessary pathways into operational technology.
SimpliScada
About SimpliScada

Cloud SCADA for municipal water operations

SimpliScada provides cloud-based monitoring, alarming, reporting, visualization, and authorized control for municipal water, wastewater, oil and gas, and other industrial applications. Its public materials describe an end-to-end platform designed to reduce reliance on VPNs, on-premises servers, Remote Desktop, and separate third-party alarm and reporting tools.

Learn more: simpliscada.com | Phone: 833-561-0025

Take the next step

Ready to simplify your SCADA operations?

Connect with SimpliScada to discuss secure cloud SCADA for your water or wastewater system.

Sources and notes

  • Associated Press, July 30, 2026. Reporting on attacks affecting more than 30 Minnesota water systems and the ongoing investigation.
  • The Wall Street Journal, July 31, 2026. Reporting on a broader wave of attacks against U.S. water and wastewater facilities.
  • SimpliScada public website, accessed August 2026. Product descriptions regarding cloud SCADA, mobile and web access, elimination of traditional VPN/server dependencies, alarms, reporting, and municipal-water applications.
  • General cybersecurity guidance. The recommended practices in this brief align with commonly accepted OT security principles: minimize Internet exposure, segment networks, control remote access, maintain asset inventories and backups, and preserve manual operating capability.

Important

This document is educational and does not constitute a guarantee of security, a site-specific risk assessment, or legal or regulatory advice. Security capabilities and deployment details should be confirmed for each project. Utilities should coordinate with qualified integrators, IT/OT security professionals, state authorities, CISA, EPA, and WaterISAC as appropriate.