In the world of municipal water and wastewater management, "out of sight, out of mind" used to be the operational mantra. As long as the pumps were running and the effluent met permit standards, the control systems tucked away in the back rooms were doing their jobs. But the landscape has shifted. Today, your Operational Technology (OT) is no longer just a set of local switches and relays; it is a networked environment that is increasingly being targeted by sophisticated external threats.
Recent EPA and CISA joint guidance has made one thing clear: the security of our nation's water infrastructure is a top priority. Whether you are managing a small rural utility or a sprawling metropolitan treatment plant, the vulnerabilities within your SCADA (Supervisory Control and Data Acquisition) and PLC (Programmable Logic Controller) networks can have real-world consequences: from service disruptions to environmental hazards. That reality is especially relevant for municipalities across the Mid-Atlantic, including water and wastewater utilities in Central Pennsylvania and throughout Pennsylvania, Maryland, Delaware, and New Jersey.
At Complete Control Solutions (CCS), we partner with municipal leaders to bridge the gap between legacy operations and modern security standards. We have identified seven of the most common OT security mistakes currently facing the water sector and, more importantly, how we can help you fix them.
1. Leaving PLCs and HMIs Exposed to the Open Internet
One of the most significant risks we see involves Human-Machine Interfaces (HMIs) and PLCs that are directly reachable via a public IP address. Often, this is done for the sake of "convenience": allowing an on-call operator to check tank levels from a home computer without a secure tunnel.
The "Aliquippa incident" served as a wake-up call for the entire industry when an internet-exposed controller was compromised by an international threat group. If you can "Google" your way into your lift station’s control screen, so can an adversary.
The Fix: We recommend a thorough inventory of all publicly reachable OT assets. Any device with a direct internet connection should be moved behind a secure firewall. We initiate this by implementing a robust consulting strategy to map your external-facing devices and eliminate direct exposure immediately.
2. Unsecured Remote Access for Remote Lift Stations

Many municipal systems rely on remote pump and lift stations spread across a wide geographic area. To manage these, utilities often use cellular modems or radio links that provide always-on vendor tunnels or "convenient" remote desktop tools like TeamViewer without multi-factor authentication (MFA). We see this challenge often in distributed municipal systems, where smaller satellite sites have to stay connected back to a main plant without creating unnecessary exposure.
These unsecured entry points are the "open windows" of your utility. Once an intruder gains access to a single remote site, they can often pivot into your main treatment plant’s network.
The Fix: Every remote access point must be secured with MFA. We equip our clients with secure "jump hosts" and VPN solutions that require identity verification before any connection to the OT environment is allowed. This ensures that only authorized personnel: and only at authorized times: can access your critical controls.
3. Operating on a "Flat" Network
A common legacy setup in municipal utilities is the "flat network," where the office computers, the billing department, the plant SCADA servers, and the field PLCs are all on the same subnet. In this scenario, a single phishing email opened by a clerk in the front office can give a ransomware virus a direct path to your chemical dosing pumps.
The Fix: Network segmentation is non-negotiable in the modern era. We use the ISA/IEC 62443 standard to design a clear separation between your IT (Business) and OT (Operations) networks. By creating a "Demilitarized Zone" (DMZ) with a dedicated firewall, we ensure that a breach in the office stays in the office, protecting your critical water processes from lateral movement.
4. Default, Shared, or "Sticky Note" Credentials
In a busy treatment plant, it’s common to see a single "Operator" account shared by ten different people, or worse, the default factory password still active on a brand-new PLC. When everyone uses the same login, there is no accountability, and if one person’s credentials are leaked, the entire system is at risk.
The Fix: Implement Individual Account Accountability and Role-Based Access Control (RBAC). We help utilities configure their SCADA systems: like Ignition by Inductive Automation: to integrate with secure identity providers. This ensures that an operator has different permissions than an engineer, and every action taken is logged to a specific user.
5. Ignoring Firmware Updates and Legacy Hardware

It is tempting to leave a 20-year-old PLC alone if it’s "working fine." However, legacy hardware often lacks the processing power to support modern encryption and is frequently riddled with known vulnerabilities that will never be patched by the manufacturer. Furthermore, even modern hardware is often left running outdated firmware because of the "if it ain't broke, don't touch it" mentality.
The Fix: We specialize in Control System Upgrades that transition you from vulnerable legacy systems (like the SLC 500) to modern, secure control hardware that is well suited for municipal water and wastewater environments. These updated platforms are designed with "security-by-design" principles, making them far more resilient to modern exploits.
6. Zero Visibility into OT Network Traffic
Most water utilities have great visibility into their water quality: you know exactly what your pH and chlorine levels are. But do you have the same visibility into your network? Many managers have no idea what devices are actually plugged into their switches or if a new, unauthorized laptop has suddenly appeared on the plant floor.
The Fix: You cannot protect what you cannot see. We help you deploy OT-specific monitoring tools that provide a real-time inventory of every asset on your network. These tools analyze "normal" traffic patterns and alert our on-site service teams if they detect unusual communication: such as a PLC suddenly trying to talk to a server in a foreign country.
7. Lack of a Formal Incident Response Plan
The worst time to figure out your cybersecurity protocol is at 2:00 AM on a Sunday when your HMI screens go black. Many municipal utilities lack a written, practiced Incident Response (IR) plan that specifically addresses OT scenarios like a pump override or a SCADA lockout.
The Fix: A robust defense requires a proactive plan. We corroborate with your team to develop an OT-aware incident response strategy. This includes everything from manual override procedures (ensuring you can still run the plant by hand if the computers fail) to clear communication chains with the EPA and CISA. We believe in being a trusted partner that doesn't just build the system but stays by your side to ensure its long-term upkeep and reliability.
Partnering for a Secure Future
The challenges facing the water and wastewater sector are significant, but they are not insurmountable. By moving away from these seven common mistakes, you can significantly reduce your risk profile and ensure the safety of the community you serve.
At Complete Control Solutions, we provide the resources of a large integrator with a highly personalized experience. Whether you support a borough authority in Central Pennsylvania or a larger municipal utility elsewhere in the broader Pennsylvania, Maryland, Delaware, and New Jersey region, our engineers are ready to analyze your unique needs and initiate the state-of-the-art solutions your utility requires.
Are you ready to secure your utility? Contact our team today for a comprehensive OT security assessment and let’s build a more resilient infrastructure together.



