Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Water Cybersecurity topic

No spam. Unsubscribe anytime.

Massachusetts officials warn water utilities of rising cyber threats; $2 million grant and free resources offered

Massachusetts Department of Environmental Protection (Drinking Water Program) webinar · May 21, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

State police and MassDEP speakers told water-utility operators that internet‑exposed PLCs and credential theft are major attack vectors, cited CISA/Censys findings of exposed Rockwell/Allen‑Bradley devices, and highlighted a $2 million MassDEP cybersecurity grant and free assessment resources.

Detective Lieutenant Edward Keith of the Massachusetts State Police’s Commonwealth Fusion Center told water‑utility operators in a webinar that state and federal partners are tracking increased targeting of industrial control systems and operational technology used by water systems. He described a landscape in which initial‑access brokers, credential theft and internet‑exposed devices give adversaries footholds into SCADA and PLC environments.

Keith outlined several recent trends: threat‑intelligence firms identify roughly two dozen groups that target ICS/OT systems, many of which use stolen credentials rather than brute‑force techniques; adversaries exploit unpatched edge routers and remote‑access services such as RDP and VNC; and legacy OT protocols (for example, Modbus) lack modern encryption and therefore rely on network mitigations. He said vendors and researchers assign names to groups (for example, names used by Dragos such as “Sylvanite” and “Proxine”) but emphasized that tactics, techniques and procedures matter more than labels.

The Fusion Center speaker showed how simple internet searches can find operational devices. He gave an example of fuel‑tank monitors that appear on public search engines and are addressable via port 10001; he said 54 such assets appeared in a Massachusetts search. Keith also described a 2017 intrusion at a private wastewater site in which attackers manipulated SCADA screens and pump controls; investigators found default configurations, open ports and a lack of multi‑factor authentication.

Andrew Hildick‑Smith, a presenter working with the Massachusetts Department of Environmental Protection, summarized a March–April advisory about activity that targeted Rockwell Automation/Allen‑Bradley PLCs. Hildick‑Smith cited a Censys search that found nearly 4,000 Rockwell/Allen‑Bradley PLCs connected to the internet in the United States and said MassDEP’s subsequent checks identified 21 exposed PLCs in Massachusetts on April 23 that later declined to 16 after outreach. He warned that exposed devices often reveal firmware and version numbers—information attackers can use to identify unpatched vulnerabilities—and described honeypots and TightVNC as examples of remote‑access exposures.

Both speakers urged practical mitigations: restrict remote access, apply network segmentation, use VPNs and multi‑factor authentication where possible, wrap legacy protocols in TLS when appropriate, maintain logging and auditing for root‑cause analysis, and regularly check for exposed devices using services such as Shodan or Censys or CISA vulnerability‑scanning resources.

Gufran Bulbul, cybersecurity coordinator for MassDEP’s Drinking Water Program, described state resources to help water systems. MassDEP and the Clean Water Trust launched a cybersecurity improvement grant program totaling $2 million; officials said about 36 water systems have used the grant and that the program pays up to $50,000 depending on system size. Eligibility is open to systems serving fewer than 10,000 people, and larger systems may qualify if they are located in a designated disadvantaged community. Bulbul also promoted a MassDEP cybersecurity resource hub, a self‑paced cybersecurity course (offers 1 TCH), the EPA’s free cybersecurity assessment, and CISA vulnerability scanning as ways for operators to identify and reduce exposure.

Organizers ran audience polls that showed roughly half of attendees had done an assessment in the past year and a range of preparedness on incident response plans. Bulbul said MassDEP can assign cybersecurity technical‑assistance providers to help with grant applications; the presenters emphasized that the grant requires no local match. Webinar organizers said a template incident‑response plan and other follow‑up links would be distributed after the event.

The presenters repeatedly encouraged operators to report suspected incidents to their local police and to the Commonwealth Fusion Center. Keith clarified that calling law enforcement does not trigger public announcements or press activity by the Fusion Center; it is a discreet way to aggregate intelligence and mobilize assistance when needed. The webinar closed with promises to share slides and resource links by email.

The webinar did not record any formal votes or regulatory actions; speakers offered operational guidance, technical resources and grant funding to reduce exposure and improve incident readiness.