As cyberattacks on water systems in several states raise new alarms about the vulnerability of local utilities, Riverhead Water District Superintendent Frank Mancini said the town’s water system uses the same general type of industrial controls now being targeted nationally, but has spent the past two years tightening its defenses.
The concern follows reports of cyberattacks on water and wastewater systems in Minnesota and other states, and a July 22 federal cybersecurity advisory warning that Iranian-affiliated cyber actors have been exploiting internet-connected operational technology devices. Federal agencies have attributed the activity to suspected Iranian-affiliated cyber actors, warning in the July 22 advisory that the hackers are targeting internet-connected control devices used in water, wastewater, municipal and energy systems.
The targets are PLCs are industrial computers that help operate equipment such as pumps, valves and chemical feed systems. They are often monitored through SCADA systems, short for supervisory control and data acquisition, which allow operators to see and control system conditions.
The federal advisory, issued by the FBI, CISA, NSA, EPA, Department of Energy, U.S. Cyber Command and Treasury Department, warned that hackers have targeted internet-exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric and Siemens devices. Federal agencies said attackers have used legitimate programming software to access misconfigured PLCs, download project files, modify or delete logic, manipulate what operators see on SCADA displays and, in some cases, disable alarm or shutdown logic.
Mancini said Riverhead uses Allen-Bradley PLCs and Rockwell’s FactoryTalk software in its water system. He said the district works with Lexington Controls, its outside controls contractor, and the town’s IT department to maintain and patch the system as needed. Allen-Bradley PLCs are among those being targeted by cyber actors, according to the advisory.

But Mancini said Riverhead’s system is not simply sitting exposed. He credited town IT staff, particularly John West, the town’s deputy IT director, with pushing the district to upgrade its cybersecurity posture and strengthen its defenses.
“We are as prepared as we could be,” the superintendent said.
Over the last two years, Mancini said, the district has installed new firewalls, developed a coordinated process for updating firewall software and PLC-related patches, and added redundancy in its control system. Updates are scheduled carefully, he said, because a cybersecurity patch or firewall update can unintentionally interfere with industrial control software if it is not coordinated with the district’s controls contractor.
“I can’t just have IT go in there and update on a Sunday night in the middle of the summer, because come Monday, a well might not turn on or it might turn off or do something weird,” Mancini said, explaining that the town has to coordinate the updates carefully, especially at times of peak summer demand.
That balance between cybersecurity and operations is one of the challenges for water utilities. Systems must be patched against known vulnerabilities, but they also must continue to produce and distribute safe drinking water every day.
The July 22 advisory urged utilities and other critical infrastructure operators to remove PLCs from direct internet exposure, use secure gateways and firewalls, review logs for suspicious traffic, check PLC project files for unauthorized changes, change default passwords, maintain offline backups and coordinate with vendors and federal agencies if suspicious activity is found.
Mancini said Riverhead’s water system has several safeguards that could help operators recognize and respond to an attempted disruption.
The water district staffs its control room 24 hours a day, he said. Operators monitor tank levels, pump activity and other system conditions. If a pump shut off unexpectedly or a tank level dropped when it should not, he said, an operator would be there to notice.
That matters because, according to Mancini, the most immediate danger from a water-system cyberattack may not be a hacker “poisoning” the water, but disrupting the equipment that keeps the system pressurized.
If pumps were shut down and water tanks emptied, system pressure could fall. Once pressure falls below safe levels, the risk of contamination increases because the distribution system is no longer pushing water outward with enough force to prevent intrusion.
If the system pressure drops to below 20 PSI, the district is required to declare a boil-water emergency, Mancini said.
A successful attack could also affect chemical pumps, including chlorine feed systems, Mancini said. But a more likely disruptive scenario, based on what he has read about the recent attacks, would be hackers shutting off pumps or otherwise causing the system to lose pressure.
Riverhead’s summer demand makes that risk more significant, he said. In winter, the system may pump roughly 2 million to 3 million gallons a day, leaving more time before tanks drop to dangerous levels. In summer, demand can rise sharply. Mancini said the district has recently seen days in the range of 17 million to 18 million gallons, and one day just under 20 million gallons.
“If we shut the pumps off, then we’re going to empty quickly,” he said.
If the automated control system were compromised, Mancini said the district is capable of operating manually. With 24-hour staffing, “if something unusual was happening with the system, we would recognize that because they’re staring at it” on monitors in the control room. Then the district can go to hand-control operation, which is available at the flip of a switch. “So our backup plan would be to go station to station and operate in hand-control only.
Mancini said the district is far better prepared than it was several years ago, when its SCADA system was more limited and cybersecurity protections were less developed.
“Five years ago … I would have considered us much more vulnerable,” he said.
He said the district’s current posture depends heavily on coordination among the water district, town IT and outside controls specialists. West, he said, has helped configure the system, identify weaknesses and keep cybersecurity from becoming solely the responsibility of water operations staff.
“He really beat this drum a lot,” Mancini said.
Mancini also said the town conducts phishing tests of employees, part of a broader effort to reduce the risk that a worker will be tricked into giving up credentials. He said a recent test showed some, though few, employees still clicked and entered passwords, underscoring how difficult cybersecurity remains even when agencies are actively training staff.The federal warning does not say every PLC is vulnerable because of a new software flaw. Instead, it emphasizes common security weaknesses: devices left reachable from the internet, weak or default passwords, inadequate network segmentation and remote access that is not sufficiently controlled or monitored.
That is a particular challenge for small and medium-size utilities, which often rely on remote monitoring and outside vendors to maintain systems without having large in-house cybersecurity staffs.
New York has already moved to strengthen water-sector cybersecurity. In March, Gov. Kathy Hochul announced new cybersecurity requirements for drinking water and wastewater systems, including mandatory training for certified operators, cybersecurity incident reporting, risk-based standards and cybersecurity lead roles for larger drinking water systems. The state also launched grant funding to help utilities assess and improve their defenses.
Riverhead announced Monday that it has been awarded two grants totaling $278,285 through the New York State Environmental Facilities Corporation’s SECURE Cybersecurity Grant Program for IT infrastructure improvements in the Riverhead Sewer District. The grants are separate from the Water District safeguards Mancini described, but underscore the growing state and local focus on cybersecurity for water-related infrastructure.
Mancini said he does not want to overstate Riverhead’s security or suggest any system is immune from attack. The threat, he said, is changing.
“I think it’s going to get worse,” he said. Attackers may become more familiar with how water systems work, he said, and therefore more capable of causing serious disruption.
But for now, he said, Riverhead has made significant improvements.
Town officials did not report any cyberattack on Riverhead’s water system. The issue, Mancini said, is preparation.
The survival of local journalism depends on your support.
We are a small family-owned operation. You rely on us to stay informed, and we depend on you to make our work possible. Just a few dollars can help us continue to bring this important service to our community.
Support RiverheadLOCAL today.

























