We hate to say I told you so, but in our recent blog post OT Cyber Resilience and Microsegmentation for AI Attacks, we discussed how hackers are increasingly targeting operational technology networks. And they’re doing so with good reason, tactically speaking; hacking OT doesn’t just compromise customer data or encrypt business systems for a ransom payment, it affects the physical world, and can cost lives.
Earlier this week, more than 30 community water systems in Minnesota were targeted in a coordinated cyberattack, with additional incidents reported across at least seven U.S. states. U.S. authorities are investigating whether Iranian-backed hackers, potentially linked to the CyberAv3ngers group, were responsible. The attacks primarily affected operational technology: they exploited vulnerabilities in Human Machine Interface (HMI) devices and Programmable Logic Controllers (PLCs). The attackers remotely accessed these internet-exposed devices, altered IP addresses and passwords, and disrupted monitoring and control capabilities for wastewater systems, forcing some utilities to switch to manual operations.
Also Read: The Ghost in the Machine: Rogue Cellular Threats in Critical Infrastructure
One way to approach this vulnerability is to prevent an attack from penetrating the network in the first place, using such measures as firewalls, Identity and Access Management, Multi-Factor Authentication, Zero Trust Network Access, VPNs, and other perimeter defense strategies. These are all important measures that most certainly should be implemented.
However, in this case, and in many other recent examples of high-profile breaches, the attackers succeeded in penetrating the perimeter defenses. Increasingly, they are aided by AI automation, making an initial breach virtually inevitable. That’s why we recommend that water utilities and other critical infrastructure organizations assume that a breach will occur and be prepared in advance to survive it. That’s a foundational Zero Trust rust principle, and ColorTokens is a leader in solutions that deliver it. Our microsegmentation platform enforces strict Zero Trust controls that prevent the lateral movement of a cyberattack across operational technology devices, and between them and the rest of the network.
To do this, we first visualize the whole environment, both IT and OT, on our network asset and traffic map, as shown below:

Then, we define and enforce traffic controls that allow normal business processes, but stop unauthorized traffic using two methods, one agent-based and the other agentless. For Windows or Linux operating system devices such as:
- Human-Machine Interfaces (HMIs)
- Historians
- Engineering workstations
- SCADA servers
- Manufacturing Execution Systems (MES)
We enforce policies using our lightweight Xshield agent, or our integration with Endpoint Detection and Response agents from CrowdStrike, SentinelOne and MDE.
For L1 devices such as the PLCs and actuators, like those that were compromised in the Minnesota attacks, we enforce policies using our agentless Gatekeeper appliance, as shown below. We also have the capability to manage rules on firewalls and ACLs in industrial switches – which gives OT users flexible enforcement options and leverages their existing infrastructure.

The result is an operational technology network that has internal controls that prevent reconnaissance and lateral movement of an attack, so that an initial breach can’t become a crisis – possibly one that affects public health.
We urge you to schedule a discussion with one of our solution specialists about how we can help your water utility or critical infrastructure organization become cyber-resilient. We’re standing by to help; you can reach us here.