Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems

Author photo: Chantal Polsonetti
ByChantal Polsonetti
Category:
Technology Trends

Human-machine Interface systems (HMIs) enable operational technology (OT) owners and operators to read Supervisory Control and Data Acquisition (SCADA) systems connected to programmable logic controllers (PLCs). In the absence of cybersecurity controls, unauthorized users can exploit exposed HMIs in Water and Wastewater Systems to:

  • View the contents of the HMI (including the graphical user interface, distribution system maps, event logs, and security settings), and

  • Make unauthorized changes and potentially disrupt the facility’s water and/or wastewater treatment process.

The US Environmental Protection Agency (EPA) and Cybersecurity and Infrastructure Security Agency (CISA) often identify internet-exposed HMIs through scanning via publicly available web-based search platforms. According to the agencies, threat actors have demonstrated the ability to easily find and exploit internet-exposed HMIs with cybersecurity weaknesses. For example, in 2024, pro-Russia hacktivists manipulated HMIs at Water and Wastewater Systems, causing water pumps and blower equipment to exceed their normal operating parameters. In each case, the hacktivists maxed out set points, altered other settings, turned off alarm mechanisms, and changed administrative passwords to lock out the water utility operators. These instances resulted in operational impacts on water systems and forced victims to revert to manual operations.

EPA and CISA strongly encourage Water and Wastewater Systems to implement the following mitigations to harden remote access to HMIs. Organizations may need to consult with their system integrators and request implementation of these mitigations.

  • Conduct an inventory of all internet-exposed devices. 

  • If possible, disconnect HMIs and all other accessible and unprotected systems from the public-facing internet.

  • If it is not possible to disconnect the device, secure it by creating a username and strong password to prevent a threat actor from easily viewing and accessing the devices. 

  • Change factory default passwords.

  • Implement a strong password and multifactor authentication (MFA) for all access to the HMI and OT network.

  • Implement network segmentation by enabling a demilitarized zone (DMZ) or a bastion host at the OT network boundary.

  • Implement geo-fencing across the entire network and enforce network segmentation based on specific locations.

  • Keep all systems and software up to date with patches and necessary security updates.

  • Establish an allowlist that permits only authorized IP addresses to access the devices.

  • Log remote logins to HMIs; be aware of failed attempts and unusual times.

  • Implement your vendor’s recommendations for best securing your product.

Sign up for CISA’s free cybersecurity vulnerability scanning service to identify software vulnerabilities and confirm that patching is up to date and done correctly.

This joint fact sheet, created in collaboration with the EPA, supplies Water and Wastewater Systems facilities with recommendations for limiting the exposure of HMIs and securing them against malicious cyber activity.

Learn more about the market for HMI Software and Services, SCADA Systems for the Water and Wastewater Industry, and Industrial Cybersecurity Challenges and Solutions.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients