Podcast/Episode 2026-6

Attackers Are Targeting The Equipment That Runs Your City

Episode 2026-6

Full Transcript

Give It To Me Straight — Episode 6

Attackers Are Targeting the Equipment That Runs Your City

Host: Shane Naugher, Dazzee IT Guest: Logan Willson, Rapid Response Team Manager & Team Lead

Edward (Intro): Welcome to Give It To Me Straight, the podcast from Dazzee IT. Each week, we break down technology, cybersecurity, AI, and business IT into practical insights you can actually use. Now, here's your host, Shane Naugher.

Shane: Hey guys, and welcome back to another edition of Give It To Me Straight, where we dive into real-world IT questions and issues that come from our clients. We want to bring some of this to you for your general knowledge and cover these topics in detail. I'm thrilled to have Logan Willson join us again. Logan, welcome back — appreciate you hopping on with us. Excited to talk today about a topic I think is of huge importance in our local areas.

Logan: Absolutely. It's great to be back, Shane.

Shane: Fantastic. Logan, this is topical — we're seeing it in the news quite a bit. We work with a lot of local government, city municipalities, and other organizations in that municipal realm, and the topic that keeps coming up is SCADA networks.

What Is a SCADA Network, and Why Does It Matter to Cities?

Logan: SCADA — IT loves its acronyms — stands for Supervisory Control And Data Acquisition. In layman's terms, that just means equipment that monitors other equipment. In a water SCADA environment, your SCADA system keeps track of things like how full a water tank is, or the quality of a line. It's very critical to a lot of cities, especially when it comes to their wastewater and water treatment plants.

Shane: Got it. So if you're a city municipality, you've most likely got a water department and a sewer department. In the old-school way of doing things, there were physical valves and controls that someone had to go physically touch to monitor and maintain. The SCADA component brings that into a connectivity perspective, where it can connect to the network?

How Are SCADA Systems Connected to the Network?

Logan: Absolutely. It utilizes two different types of equipment — PLCs and RTUs. These are electronic components that communicate back to a computer or workstation, so you can manipulate the system remotely without having to physically go check a gauge or valve.

Shane: So there's still that physical component — a valve, a measurement instrument — but we're making it smarter by allowing remote control and by collecting and storing that data digitally. A lot of cities have moved to this in recent years. Not every city has it in place yet, but quite a few do — is that right?

Logan: Yeah, that's correct.

Why Is CISA Issuing Advisories About SCADA Networks Right Now?

Shane: Here's why I think this matters: a large portion of our client base is local cities, and we've had this conversation for years. Connecting these devices to the network is genuinely useful — people can work remotely, control things remotely, and respond to issues without physically driving to the water plant at midnight. That convenience comes with inherent risk.

Something that's hit the news in the last week or two, and really brought this to a head, is a set of advisories issued by the federal government through CISA, specifically around SCADA networks. Can you walk through what that involves?

Logan: What we're seeing a lot of are reports of PLC equipment — those electronic components managing the physical gauges — getting breached. Attackers are modifying passwords, adjusting IP addresses associated with the equipment, and in some cases even causing actual water quality degradation.

What's the Real-World Risk If a SCADA System Is Compromised?

Shane: That's exactly why the federal government is issuing these advisories. If a threat actor gets access to these systems — say, the mechanism controlling fluoride dosage in drinking water — and that mechanism is connected to the network, a bad actor could potentially increase that dosage.

Logan: They could even decrease it and cause further problems.

Shane: It's serious enough that the federal government is telling municipal organizations maintaining connectivity to these systems that they need to be hyper-aware and take real protective measures. They've seen a noticeable uptick in attacks over the last several weeks, and they believe it's likely driven by foreign state actors probing for these vulnerabilities. So if you're a city municipality or a water district connecting your systems to the network and the internet, there are some things that really need to happen. Can you walk us through the basics of what a municipality or water district should be doing?

How Are Attackers Actually Breaching These Systems?

Logan: Pulling back a bit — this isn't some magic network worm making its way in. Realistically, what's happening is that a lot of places just aren't implementing basic security practices. Many of these systems are getting breached because someone's been using the same password on the system for the last 20 years.

In a lot of cases, the PLCs or the SCADA web interface itself — often reachable over a cellular connection — are just open to the public internet. They're easily findable online, with nothing blocking someone from seeing them and getting to them. Once a system is exposed like that, it becomes a lot easier for an attacker to jump in and start adjusting passwords, rotating in a weak password of their own, or changing an IP address.

All of that is easily preventable. Ultimately, the best method is to keep those systems off the internet entirely — but then you lose the remote functionality that makes SCADA useful in the first place. The next best step is making sure those systems sit behind a firewall with proper security measures in place, limiting access to only trusted entities and network paths, and keeping it locked down.

What Security Basics Should Municipalities Have in Place?

Shane: You hit on a few key points worth digging into, because these security protocols aren't really different from anything else you need to secure in a city environment: following a real password policy, restricting and updating VPN access, keeping firmware patched on these devices, and segmenting the SCADA network so it's not sitting on the same general network as everything else. These are fairly typical security approaches you'd apply across an entire network.

Where I think we've seen real concerns is that these environments — a treatment facility, a rugged industrial setting — don't get treated the same way people would treat a standard office environment. People think, "I just need connectivity, I don't need all that fancy security stuff." That's exactly where things go wrong.

Why Do Water Treatment Facilities Need More Protection, Not Less?

Logan: Absolutely. Realistically, those locations need more protection than a standard business environment, not less. We're talking about business-critical, mission-critical systems that affect way more than a typical office worker. Water systems affect everybody in a city, and if that gets compromised in any way, it's a big mess to clean up.

Shane: We've even seen instances where, because the folks working in these environments aren't technical by nature — that's not what they spend their day doing — they make decisions without the technical context in mind, including plugging directly into the internet without a firewall. If you've got a wastewater or any SCADA network without a genuine business-grade firewall in front of it — not a Best Buy-type box — that's a basic security practice being skipped. Sometimes it happens because people aren't in a technology environment day to day; sometimes it happens because they just want to get the job done, and plugging straight into the internet is the easy path. Either way, it's a huge risk being exposed.

Logan: And nowadays it's so easy for a well-managed, well-maintained IT department to give people the access they need while keeping the right security in place. Modern VPNs are far more sophisticated and can provide secured access to your SCADA system and PLCs without putting the entire system at risk.

Shane: Exactly. And I think because people don't think of it this way — "it's just one computer sitting here, it's not that big a deal" — they miss that the computer and the network are what's actually at risk. So it comes down to the basics: firewalls in place, user accounts cleaned up so former employees no longer have access, passwords rotated, and that user list audited on a set schedule. If that's not happening today, it needs to be.

How Should You Work With a Third-Party SCADA Vendor?

Shane: The other thing we notice is that a lot of cities use a third-party management company that handles the SCADA network specifically. Can you talk about that?

Logan: We work with several very reputable SCADA companies. The biggest thing is making sure your IT department and your SCADA vendor are on the same page. Some vendors draw a hard line — "this is our equipment, we manage it" — and you have to let them own that while confirming everything is protected. If you're confident in that vendor, we'll back that arrangement 100%. The key is keeping open communication with them.

In a lot of our cases — going through and auditing existing clients who had SCADA scares — a simple phone call to the vendor and a quick discussion was all it took. They already had things locked down, and there was nothing more to worry about. As long as you're working with somebody reputable, there's really not much concern.

Key Takeaway

The biggest takeaway: get it documented, and have someone on record saying, "we're responsible for this, and we're taking care of it." If you're a city listening to this, step one is identifying who owns this responsibility and documenting what's already in place.

We've covered the basics around network security here, and we're happy to provide a template for managing this to anyone who wants one — just reach out. If you have specific questions about SCADA or city networks, or cybersecurity for municipalities, we can connect you with Logan and his team for the technical or operational specifics.

Shane: Logan, as always, I appreciate the conversation — you're the one in the trenches with this stuff day in and day out, and I always value your insight.

Logan: Shane, I always have a good time coming on the podcast. Good chance to flex what I know and make sure I'm not just talking out of my rear end — always a good time.

Shane: Absolutely. Logan, appreciate you hopping on with me — thank you for your time and your wisdom.

Logan: Absolutely.

Give It To Me Straight is a production of Dazzee IT, your loyal, fiercely protective IT solutions partner. New episodes weekly.

Ready to Stop Worrying About IT?

Join hundreds of Missouri organizations who trust DaZZee IT as their technology partner. 25+ years, 80% same-day resolution.

60-day trial
100% satisfaction guarantee
No setup fees