H2 Innovations
Insights
Water Sector Note · August 2026

You took your control system off the internet.The reasons it was on are still there.

The connection into your plant was the boring part of the job for years. Somebody put it in so a number could be read without driving out at two in the morning, and it worked.

Then this summer attackers reached that equipment, changed the passwords and the network addresses, and locked operators out of hardware they own. Monitoring and control went with it, boil-water notices went out, and plants went back to being run by hand. A federal alert dated 2026-07-30 told water and wastewater utilities to get internet-exposed control equipment off public networks promptly, and that advice is right.

So say you took it. The cable is out, the finding is closed, and the regulator still wants the monthly numbers. I have sat on the far side of that disconnection with utilities, and the gap it leaves is smaller than it looks. Most of the work is a spreadsheet.

  • Every path you just closed was installed to serve something, and that something still needs an answer on Monday morning.

  • Most of those paths exist so somebody can read a number, and a read-only need can be served by a connection your plant opens outward.

  • What is left after that is a short list of real exceptions you can defend one at a time, which is what makes a disconnection hold.

01 · The need

The need does not leave when the path does

Start with the scale, because it is easy to hear it wrong. Public reporting describes more than thirty community water systems affected in a single US state over two days at the end of July, and a separate federal announcement counts utilities reporting incidents in at least seven states. Those are two counts of two different things, one a cluster inside one state and the other a national tally, so adding them together would misstate both. The answer Washington has proposed, and what that money would have to buy, is in Water cybersecurity funding.

The alert itself asks for a short and familiar list, and none of it is controversial. It asks you to take control equipment off the internet. Where remote access is genuinely needed, it asks you to put that access behind a gateway or a virtual private network rather than exposing the device itself. It asks you to turn on password protection and replace default credentials everywhere, including on the unit somebody swapped in last year. It asks you to restrict engineering access to known devices rather than to whoever can reach the port. And it asks you to keep known-good configuration backups and to know that you can restore from them, because a backup nobody has ever restored from is an assumption rather than a backup. If your choice today is between working that list and reading the rest of this page, work the list first, because nothing below argues with any of it. A second advisory in August carried the same list to five more industries, which is in PLC internet exposure: two advisories, one answer.

Here is what happens to a need with no path left to serve it. Your people absorb it. Somebody drives out at night instead of checking a screen. Somebody reconstructs a month of data out of a binder for the capacity study. A chemical feed total gets transcribed off a screen onto a form by hand at the end of a shift. And on some Friday afternoon, under deadline pressure, somebody quietly restores the old path, not because anybody made an architecture decision, but because a report was due and that was the only way anyone knew to get the number.

None of that is a criticism of the alert. A reachability checklist is meant to answer a reachability question, and it does that well. But the checklist and the data need land on the same desk, and at a small utility the operator, the maintenance department and the IT person who share that desk are usually one person. When you take away the path but leave the need behind it, your people carry that need until somebody quietly puts the path back.

02 · The list

Name the consumer behind every path

The alert’s own instruction already implies an inventory, because you cannot remove what is internet-exposed without first establishing what is exposed. So that list is getting written either way. While you are writing it, I would add two more columns, and none of the three passes below requires buying anything.

  • Write down every path that can currently reach your control layer and why it exists, because a list held in one person’s head is not an inventory.

  • Against each path, name the data consumer it actually serves, because a path whose consumer nobody can name is a finding in itself and the cheapest one on the list to act on.

  • Mark the consumers that only ever need to read, because most of them do, and reading is the need a connection your plant opens outward can serve.

The first pass runs longer than everyone expects. It is the forwarded ports and the remote access endpoints, and it is also the cellular modem on a skid, the outstation radio, the support tool somebody installed for a commissioning trip and never removed, the historian with its own published endpoint, and the laptop that dials in from a truck. None of this is a project. It is a spreadsheet with three columns, and the first column is one the alert already asks you to build.

The third pass is the one that changes what you can do, because there is an arrangement in which data leaves a plant without the plant side of that path listening for anything at all. The process inside the plant opens the connection outward, the stateful firewall permits the return traffic as part of the flow it already allowed out, and the plant end holds no listening socket: there is nothing waiting for a call, nothing to forward a port to, and nothing left behind after commissioning. Buffering at the sending end means an hour with the link down produces a backfill rather than an hour-shaped hole in your trends. If you want the longer argument for why that property is worth designing toward, along with an honest account of what it does not buy you, it is in What can reach your control layer?

I want to be clear about what kind of claim that is. It describes what exists in a configuration, it is not a claim about what anyone can or cannot do to your network, and every other control you have still matters exactly as much as it did before. Name the consumer behind every path, because the ones that only ever read can be served by a connection your plant opens outward.

03 · What is left

What you are left holding

Work those three passes and you end up holding two lists instead of one. The long one is the paths that exist only to move data outward, which is exactly where the direction a connection gets opened in is a choice rather than a constraint. The short one is the work that genuinely requires reaching into the plant, meaning a live download, or a supplier session inside a commissioning window.

Treat every item on that short list as a deliberate, dated exception, with a name against it and a stated way it gets closed, rather than as a standing rule that outlives the reason for it. A handful of exceptions you can each defend on their own terms is a far better position than one standing rule nobody remembers approving, and it is the position that survives a staff change, an audit, and the next Friday afternoon. A short list of dated exceptions, each with a name against it, is what keeps a disconnection from quietly undoing itself.

04 · How we help

How can we help?

Everything above is work you can do without us, and it is the work that decides most of the outcome. Where a purchase earns its place is narrower than people expect: moving the read-only half of your list out of the plant on a path the plant opens itself, so the report still gets written and nobody has to reopen a door to write it.

Flowgate is where we built that arrangement. Relay nodes inside the plant open every connection outward to the node above them, so the plant side of that path carries no inbound rule. Readings buffer at the sending end while a link is down, which turns a dropped connection into late data instead of missing data. Sign-in binds to the Active Directory you already run, so an action on the path carries a name rather than a shared login. And changes land in a timestamped, hash-chained record. Where your readings are stranded in a protocol from an earlier decade before any of that can begin, RetroBridge reads them locally and serves them onward.

I would rather set out the limits myself than leave you to find them later. None of this undoes an intrusion, and if credentials or addresses on your equipment have already been changed, what you need is recovery, which belongs to your responders, your regulator and your restoration procedure. None of it is detection either, because removing a category of mistake is not the same as knowing when something has happened. And it is one path rather than all paths, so every modem, appliance and published endpoint stays its own decision, made on its own day.

Three more limits are worth stating plainly. The direction a connection gets opened in is not the direction data moves, because once a session exists bytes travel both ways, so whether that session can write back into your control layer is a separate decision that should be taken, scoped and recorded separately. Running a plant by hand, and then coming back off manual operation cleanly, is operator work with its own procedures and its own drills, and a data architecture has nothing useful to contribute there. And nothing here has been measured, scored or assessed against a standard, so none of it is a rating or a certification. What I have described is how a path is put together, which is a narrower claim than most, and it is one you can check for yourself. The questions at the end of What can reach your control layer? are the ones we would want asked of us.

05 · Sources

Sources

06 · Take with you

The three things to take with you

When you take away the path but leave the need behind it, your people carry that need until somebody quietly puts the path back. Name the consumer behind every path, because the ones that only ever read can be served by a connection your plant opens outward. And a short list of dated exceptions, each with a name against it, is what keeps a disconnection from quietly undoing itself.

If you want one next step this week, take ten minutes and write down every path into your control layer you can name from memory, then ask one other person on your team to do the same without seeing your list. The two lists will not match, and the difference between them is the first honest measure of the problem you are holding.

If you are working with equipment that is already in the ground, the brownfield version of this is in Reaching your plant data without a rip-and-replace. And if you would rather describe your own boundary and ask us what we would do with it, write to us at info@h2innovations.ca.