{"691522":{"#nid":"691522","#data":{"type":"news","title":"As Water Systems Face Cyberattacks, Georgia Tech Research Points to Solutions","body":[{"value":"\u003Cp\u003E\u003Ca href=\u0022https:\/\/www.wsbtv.com\/news\/local\/water-supply-under-attack-by-cybercriminals-metro-atlanta-system-may-have-been-targeted\/XA46MWYNZRAZ5EYUN3RSJZG5SM\/\u0022\u003ERecent\u003C\/a\u003E cyberattacks on municipal water systems across the United States have renewed concerns about the cybersecurity of the operational technology that supports critical infrastructure.\u0026nbsp;\u003C\/p\u003E\u003Cp\u003EFor researchers in Georgia Tech\u0027s \u003Ca href=\u0022https:\/\/sites.gatech.edu\/capcpsec\/\u0022\u003ECyber-Physical Security\u003C\/a\u003E (CPSec) Lab, however, the vulnerabilities behind many of these incidents are far from new.\u003C\/p\u003E\u003Cp\u003EAssociate Professor \u003Cstrong\u003ESaman Zonouz\u003C\/strong\u003E leads the CPSec Lab and has studied programmable logic controllers (PLCs) for years. These devices automate critical infrastructure, including water treatment facilities, power grids, manufacturing plants, and transportation systems. The lab\u2019s work has revealed widespread internet exposure and software vulnerabilities that leave many industrial control systems vulnerable to cyberattacks.\u003C\/p\u003E\u003Cp\u003E\u0022Out of the 16 critical infrastructure sectors defined by the \u003Ca href=\u0022https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\u0022\u003ECybersecurity and Infrastructure Security Agency\u003C\/a\u003E, four are considered lifelines,\u0022 Zonouz said. \u0022Of those four, communications, energy, transportation, and water, the water sector is the most vulnerable, which is why it is so often targeted.\u0022\u003C\/p\u003E\u003Cp\u003EPLCs serve as the brains of industrial operations, monitoring sensors and controlling equipment that keep essential services operational.\u003C\/p\u003E\u003Cp\u003E\u0022Imagine you have a thermostat that controls the temperature of your house. That is a type of controller,\u0022 Zonouz explained. \u0022The professional version does the same thing in industry.\u0022\u003C\/p\u003E\u003Cp\u003EWhen these controllers are directly accessible from the internet, attackers can exploit them to disrupt operations, manipulate industrial processes, or interfere with the systems that deliver essential services. Controllers may be intentionally exposed to allow operators to monitor equipment remotely. They can also be unintentionally accessible online because of configuration errors.\u003C\/p\u003E\u003Cp\u003EHowever, internet exposure is only part of the problem.\u003C\/p\u003E\u003Cp\u003EThe CPSec Lab maintains a collection of PLCs that researchers reverse engineer to better understand their firmware, communication protocols, and security weaknesses. Their research has found that many controllers contain vulnerabilities that attackers can exploit once they gain access.\u003C\/p\u003E\u003Cp\u003E\u0022Not only can the attackers see the house they want to rob, but the doors are also left unlocked,\u0022 Zonouz said.\u003C\/p\u003E\u003Cp\u003EIn 2024, Zonouz and his collaborators presented \u003Ca href=\u0022https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690195\u0022\u003EPLCHound\u003C\/a\u003E at the ACM Conference on Computer and Communications Security (CCS), introducing an automated system that identifies internet-connected PLCs hidden within massive internet-scale datasets collected by services such as Shodan and Censys. The work was led by Ph.D. student \u003Cstrong\u003ERyan Pickren\u003C\/strong\u003E. Provost and Executive Vice President for Academic Affairs \u003Cstrong\u003ERaheem Beyah\u003C\/strong\u003E, Assistant Professor \u003Cstrong\u003EFrank Li\u003C\/strong\u003E, and Research Scientist \u003Cstrong\u003EAnimesh Chhotaray\u003C\/strong\u003E are co-authors of the study.\u0026nbsp;\u003C\/p\u003E\u003Cp\u003ERather than relying on traditional scanning techniques, PLCHound identifies subtle network signatures that reveal industrial devices that prior methods often missed. Using the system, the researchers conducted one of the largest studies of publicly reachable PLCs from major manufacturers.\u003C\/p\u003E\u003Cp\u003ETheir findings showed that previous estimates undercounted the number of internet-accessible industrial controllers by as much as 37 times. Even more concerning, nearly 96% of the identified devices exposed protocols linked to recently disclosed critical vulnerabilities.\u003C\/p\u003E\u003Cp\u003EThe researchers did more than document the problem. After identifying exposed devices, the team launched a large-scale notification campaign, contacting more than 7,000 industrial operators to alert them that their systems appeared vulnerable. The effort enabled many organizations to investigate and address security issues before they could be exploited.\u003C\/p\u003E\u003Cp\u003EThe recent attacks on municipal water systems reinforce concerns researchers have raised for years: many critical infrastructure operators continue to rely on operational technology designed primarily for reliability and performance rather than for cybersecurity.\u003C\/p\u003E\u003Cp\u003EImproving those defenses, Zonouz said, will require more than simply patching individual vulnerabilities.\u003C\/p\u003E\u003Cp\u003EThe researchers cite the energy sector as a model. Compared with other critical infrastructure sectors, electric utilities generally operate under more mature cybersecurity requirements and undergo routine compliance audits, providing organizations with greater visibility into the devices connected to their networks and the risks they pose.\u003C\/p\u003E\u003Cp\u003EImplementing those improvements will not be easy. Many municipal water utilities operate with limited budgets and aging infrastructure, leaving little funding available for cybersecurity investments. As attacks on critical infrastructure become more frequent, the researchers argue that gaining visibility into operational technology assets and strengthening oversight are essential first steps to protect the systems communities rely on every day.\u003C\/p\u003E\u003Cp\u003EThe CPSec Lab is a collaborative laboratory within the \u003Ca href=\u0022https:\/\/scp.cc.gatech.edu\/\u0022\u003ESchool of Cybersecurity and Privacy\u003C\/a\u003E as well as the \u003Ca href=\u0022https:\/\/ece.gatech.edu\/\u0022\u003ESchool of Electrical and Computer Engineering\u003C\/a\u003E.\u003C\/p\u003E","summary":"","format":"limited_html"}],"field_subtitle":"","field_summary":[{"value":"\u003Cp\u003ERecent cyberattacks on municipal water systems across the United States have renewed concerns about the cybersecurity of the operational technology that supports critical infrastructure.\u0026nbsp;\u003C\/p\u003E\u003Cp\u003EFor researchers in Georgia Tech\u0027s Cyber-Physical Security (CPSec) Lab, however, the vulnerabilities behind many of these incidents are far from new.\u003C\/p\u003E","format":"limited_html"}],"field_summary_sentence":[{"value":"Recent cyberattacks on municipal water systems across the United States have renewed concerns about the cybersecurity of the operational technology that supports critical infrastructure. "}],"uid":"36253","created_gmt":"2026-08-06 16:59:42","changed_gmt":"2026-08-11 16:28:52","author":"John Popham","boilerplate_text":"","field_publication":"","field_article_url":"","location":"Atlanta, GA","dateline":{"date":"2026-08-06T00:00:00-04:00","iso_date":"2026-08-06T00:00:00-04:00","tz":"America\/New_York"},"extras":[],"hg_media":{"673306":{"id":"673306","type":"image","title":"Saman Zonouz is a Georgia Tech associate professor and lead researcher for the DerGuard project. ","body":null,"created":"1709660104","gmt_created":"2024-03-05 17:35:04","changed":"1709660054","gmt_changed":"2024-03-05 17:34:14","alt":"Saman Zonouz is a Georgia Tech associate professor and lead researcher for the DerGuard project. ","file":{"fid":"256679","name":"Saman-Zonouz.jpg","image_path":"\/sites\/default\/files\/2024\/03\/05\/Saman-Zonouz.jpg","image_full_path":"http:\/\/hg.gatech.edu\/\/sites\/default\/files\/2024\/03\/05\/Saman-Zonouz.jpg","mime":"image\/jpeg","size":56998,"path_740":"http:\/\/hg.gatech.edu\/sites\/default\/files\/styles\/740xx_scale\/public\/2024\/03\/05\/Saman-Zonouz.jpg?itok=qOSZDIrt"}}},"media_ids":["673306"],"groups":[{"id":"1188","name":"Research Horizons"},{"id":"367481","name":"SEI Energy"},{"id":"1280","name":"Strategic Energy Institute"}],"categories":[{"id":"153","name":"Computer Science\/Information Technology and Security"},{"id":"144","name":"Energy"},{"id":"151","name":"Policy, Social Sciences, and Liberal Arts"},{"id":"135","name":"Research"}],"keywords":[{"id":"186858","name":"go-sei"}],"core_research_areas":[{"id":"145171","name":"Cybersecurity"},{"id":"39531","name":"Energy and Sustainable Infrastructure"},{"id":"39481","name":"National Security"}],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[{"value":"\u003Cp\u003EJohn Popham\u003C\/p\u003E\u003Cp\u003ECommunications Officer II at the School of Cybersecurity and Privacy\u003C\/p\u003E","format":"limited_html"}],"email":["jpopham3@gatech.edu"],"slides":[],"orientation":[],"userdata":""}}}