Are Public Water Systems the Next Target for Cyber Attacks?

OT Security

State-sponsored attackers recently hit more than 30 Minnesota community water systems [1], exposing a critical gap in operational technology defenses that legacy perimeter security cannot close. The OT security market has moved decisively from visibility to enforcement [2], with IT/OT integration now ranked the #1 organizational challenge [2]. ColorTokens' microsegmentation approach targets this gap directly, competing in a cybersecurity market projected to reach $338B by 2029 at an 11.6% CAGR [3].

What is Covered in this Article

  • State-actor OT attacks on critical infrastructure [1][1]
  • IT/OT governance misalignment and the enforcement gap [2][2]
  • Microsegmentation and Zero Trust as compensating controls for PLCs and HMIs [2][1]
  • Cybersecurity market growth trajectory to $338B by 2029 [3]
  • Near-term IoT/OT deployment pipeline signals [4]

The News: More than 30 community water systems in Minnesota were recently targeted in a cyberattack attributed to state-sponsored actors [1]. The incident underscores a well-documented shift in attacker strategy: compromising OT networks affects the physical world and can cost lives, not merely encrypt business data for ransom [1]. ColorTokens had previously flagged this trend in published analysis on OT cyber resilience and microsegmentation for AI-driven attacks [1]. The company's current focus centers on protecting PLCs and HMIs as the primary attack surface in water utilities and other critical infrastructure environments [1], positioning microsegmentation as the enforcement layer that perimeter-only defenses have failed to provide.

State Actors Target Water Systems: Why OT Microsegmentation Can No Longer Wait

Analyst Take: The Minnesota water system attacks are not an anomaly; they are a confirmation. State actors have identified OT networks as high-value targets precisely because the consequences extend beyond data loss into physical harm [1]. The cybersecurity industry's response must shift from monitoring to enforcement, and the structural conditions now favor vendors built for that transition [2].

OT Attacks Expose the Limits of Perimeter Defense

Traditional perimeter security was designed for IT environments where the goal is data confidentiality. OT environments operate on a different priority stack: availability and physical safety come first. When state actors target water system PLCs and HMIs [1], they are exploiting this mismatch. The Purdue Model air-gap that once separated OT from external networks is effectively obsolete as connectivity requirements have expanded. Attackers now move laterally through converged IT/OT environments with relative ease. Microsegmentation addresses this by isolating individual control devices so that a breach at one node cannot propagate to adjacent systems, containing the blast radius without interrupting control loops. This is not a theoretical benefit; it is the compensating control that network-level architecture demands [2].

Governance Misalignment Is Amplifying the Risk

The organizational dimension of OT security is as consequential as the technical one. IT/OT security integration has surpassed asset visibility as the #1 challenge, with organizations struggling to bridge IT's 'detect' workflows with OT's 'prevent' protocols [2]. Compounding this, 50% of organizations have shifted security responsibility to Enterprise IT teams, yet operational leaders retain a 'Latency Veto', any tool threatening Overall Equipment Effectiveness is rejected, forcing a pivot to passive-only monitoring to avoid non-determinism in sensitive control loops [2]. This governance deadlock leaves enforcement gaps that attackers exploit. Agentless microsegmentation resolves the standoff by delivering Zero Trust policy enforcement at the network layer, requiring no agent installation on legacy PLCs or HMIs and therefore posing no threat to operational availability [2].

Market Timing Favors Enforcement-Led OT Security

The OT security market has matured. The evolution from Operational Technology to Cyber Physical Systems is essentially complete, with the market moving beyond the 'convergence' phase of simply seeing what is on the network toward enforcement-led operations [2]. This maturation coincides with a cybersecurity market expanding at 11.6% CAGR from approximately $195B in 2024 to $338B in 2029 [3]. Demand signals confirm the near-term opportunity: survey data shows a strong pipeline of IoT/OT security deployments planned within 24 months, with 100 out of 115 respondents indicating a pilot planned within that window [4]. ColorTokens' microsegmentation-led positioning aligns with both the technical maturity of the market and the urgency created by incidents like the Minnesota water system attacks [1][1].

What to Watch

  • Regulatory response: whether the Minnesota attacks accelerate federal mandates for OT microsegmentation in water and other critical infrastructure sectors [1]
  • Deployment conversion rate: how many of the 100 organizations with IoT/OT pilots planned within 24 months convert to full production deployments by Q2 2027 [4]
  • Governance model adoption: whether organizations resolve the IT/OT 'Latency Veto' deadlock by formalizing joint security ownership structures in Q3-Q4 2026 [2]
  • Competitive differentiation: how agentless versus agent-based OT security vendors reprice or repackage offerings as enforcement-led demand displaces passive monitoring contracts [2][2]

Sources

1. Public Water Systems Are Targeted by State Actors: How to Protect PLCs and HMIs in the Operational Technology Network, Colortokens, August 2026

2. Who Owns Cyber Physical Systems (CPS) Security?, Futurum Research, January 2026

3. 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast, Futurum Research, June 2026

4. 1H 2026 Cybersecurity Global Enterprise Decision Maker Survey Report, Futurum Research, June 2026


Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.

Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Read the full Futurum Group Disclosure.


Other Insights from Futurum:

Can Replit's $9 Billion Valuation Redefine Software Development?

How BYOVD Attacks Challenge Traditional EDR Defenses

Agilico Inverness: 40-Year Partnership

Author Information

FuturumAI

This content is written by a commercial general-purpose language model (LLM) along with the Futurum Intelligence Platform, and has not been curated or reviewed by editors. Due to the inherent limitations in using AI tools, please consider the probability of error. The accuracy, completeness, or timeliness of this content cannot be guaranteed. It is generated on the date indicated at the top of the page, based on the content available, and it may be automatically updated as new content becomes available. The content does not consider any other information or perform any independent analysis.

Related Insights
SailPoint Bets on Identity to Govern AI Agents at Navigate 2026
October 9, 2026

SailPoint Bets on Identity to Govern AI Agents at Navigate 2026

Fernando Montenegro, VP at Futurum, analyzes SailPoint's Navigate 2026 launches, which extend just-in-time access, discovery, and autonomous agents to AI agents, and what they mean for identity teams....
AMD's Class Y Versal Package Extends AI Silicon to 15 Year Space Missions
October 9, 2026

AMD's Class Y Versal Package Extends AI Silicon to 15 Year Space Missions

Brendan Burke, Research Director at Futurum, examines AMD's sampling of the Versal AI Core XQRVC1902 in a Class Y space-grade package, bringing AI compute density to 15-year human-rated and deep...
Arctiq Joins Wiz MSP Program to Scale Multi-Tenant Cloud Security
October 7, 2026

Arctiq Joins Wiz MSP Program to Scale Multi-Tenant Cloud Security

Arctiq joined Wiz's MSP Program, gaining centralized multi-tenant management through Wiz Tenant Manager to deliver cloud and AI security at scale, strengthening its Google SecOps-powered security operations....
OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes
October 6, 2026

OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes

OPSWAT's MetaDefender NetWall Fend 4.3.0 adds UDP Multicast, Syslog, and MQTT support, enhancing secure data-sharing between operational and IT environments....
Sophos CISO Advantage Targets Organizations Without a CISO
October 5, 2026

Sophos CISO Advantage Targets Organizations Without a CISO

Fernando Montenegro, VP at Futurum, analyzes Sophos's CISO Advantage launch and what it means for managed service providers turning informal security leadership into a billable service....
OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609
October 5, 2026

OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609

OPSWAT's MetaDefender Endpoint v7.6.2609 release introduces configurable media controls, air-gapped anti-malware updates, and expanded audit trails—addressing critical security gaps for enterprises in high-compliance sectors....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.