Are Public Water Systems the Next Target for Cyber Attacks?

OT Security

State-sponsored attackers recently hit more than 30 Minnesota community water systems [1], exposing a critical gap in operational technology defenses that legacy perimeter security cannot close. The OT security market has moved decisively from visibility to enforcement [2], with IT/OT integration now ranked the #1 organizational challenge [2]. ColorTokens' microsegmentation approach targets this gap directly, competing in a cybersecurity market projected to reach $338B by 2029 at an 11.6% CAGR [3].

What is Covered in this Article

  • State-actor OT attacks on critical infrastructure [1][1]
  • IT/OT governance misalignment and the enforcement gap [2][2]
  • Microsegmentation and Zero Trust as compensating controls for PLCs and HMIs [2][1]
  • Cybersecurity market growth trajectory to $338B by 2029 [3]
  • Near-term IoT/OT deployment pipeline signals [4]

The News: More than 30 community water systems in Minnesota were recently targeted in a cyberattack attributed to state-sponsored actors [1]. The incident underscores a well-documented shift in attacker strategy: compromising OT networks affects the physical world and can cost lives, not merely encrypt business data for ransom [1]. ColorTokens had previously flagged this trend in published analysis on OT cyber resilience and microsegmentation for AI-driven attacks [1]. The company's current focus centers on protecting PLCs and HMIs as the primary attack surface in water utilities and other critical infrastructure environments [1], positioning microsegmentation as the enforcement layer that perimeter-only defenses have failed to provide.

State Actors Target Water Systems: Why OT Microsegmentation Can No Longer Wait

Analyst Take: The Minnesota water system attacks are not an anomaly; they are a confirmation. State actors have identified OT networks as high-value targets precisely because the consequences extend beyond data loss into physical harm [1]. The cybersecurity industry's response must shift from monitoring to enforcement, and the structural conditions now favor vendors built for that transition [2].

OT Attacks Expose the Limits of Perimeter Defense

Traditional perimeter security was designed for IT environments where the goal is data confidentiality. OT environments operate on a different priority stack: availability and physical safety come first. When state actors target water system PLCs and HMIs [1], they are exploiting this mismatch. The Purdue Model air-gap that once separated OT from external networks is effectively obsolete as connectivity requirements have expanded. Attackers now move laterally through converged IT/OT environments with relative ease. Microsegmentation addresses this by isolating individual control devices so that a breach at one node cannot propagate to adjacent systems, containing the blast radius without interrupting control loops. This is not a theoretical benefit; it is the compensating control that network-level architecture demands [2].

Governance Misalignment Is Amplifying the Risk

The organizational dimension of OT security is as consequential as the technical one. IT/OT security integration has surpassed asset visibility as the #1 challenge, with organizations struggling to bridge IT's 'detect' workflows with OT's 'prevent' protocols [2]. Compounding this, 50% of organizations have shifted security responsibility to Enterprise IT teams, yet operational leaders retain a 'Latency Veto', any tool threatening Overall Equipment Effectiveness is rejected, forcing a pivot to passive-only monitoring to avoid non-determinism in sensitive control loops [2]. This governance deadlock leaves enforcement gaps that attackers exploit. Agentless microsegmentation resolves the standoff by delivering Zero Trust policy enforcement at the network layer, requiring no agent installation on legacy PLCs or HMIs and therefore posing no threat to operational availability [2].

Market Timing Favors Enforcement-Led OT Security

The OT security market has matured. The evolution from Operational Technology to Cyber Physical Systems is essentially complete, with the market moving beyond the 'convergence' phase of simply seeing what is on the network toward enforcement-led operations [2]. This maturation coincides with a cybersecurity market expanding at 11.6% CAGR from approximately $195B in 2024 to $338B in 2029 [3]. Demand signals confirm the near-term opportunity: survey data shows a strong pipeline of IoT/OT security deployments planned within 24 months, with 100 out of 115 respondents indicating a pilot planned within that window [4]. ColorTokens' microsegmentation-led positioning aligns with both the technical maturity of the market and the urgency created by incidents like the Minnesota water system attacks [1][1].

What to Watch

  • Regulatory response: whether the Minnesota attacks accelerate federal mandates for OT microsegmentation in water and other critical infrastructure sectors [1]
  • Deployment conversion rate: how many of the 100 organizations with IoT/OT pilots planned within 24 months convert to full production deployments by Q2 2027 [4]
  • Governance model adoption: whether organizations resolve the IT/OT 'Latency Veto' deadlock by formalizing joint security ownership structures in Q3-Q4 2026 [2]
  • Competitive differentiation: how agentless versus agent-based OT security vendors reprice or repackage offerings as enforcement-led demand displaces passive monitoring contracts [2][2]

Sources

1. Public Water Systems Are Targeted by State Actors: How to Protect PLCs and HMIs in the Operational Technology Network, Colortokens, August 2026

2. Who Owns Cyber Physical Systems (CPS) Security?, Futurum Research, January 2026

3. 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast, Futurum Research, June 2026

4. 1H 2026 Cybersecurity Global Enterprise Decision Maker Survey Report, Futurum Research, June 2026


Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.

Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Read the full Futurum Group Disclosure.


Other Insights from Futurum:

Can Replit's $9 Billion Valuation Redefine Software Development?

How BYOVD Attacks Challenge Traditional EDR Defenses

Agilico Inverness: 40-Year Partnership

Author Information

FuturumAI

This content is written by a commercial general-purpose language model (LLM) along with the Futurum Intelligence Platform, and has not been curated or reviewed by editors. Due to the inherent limitations in using AI tools, please consider the probability of error. The accuracy, completeness, or timeliness of this content cannot be guaranteed. It is generated on the date indicated at the top of the page, based on the content available, and it may be automatically updated as new content becomes available. The content does not consider any other information or perform any independent analysis.

Related Insights
Why AI Learned to Attack Before It Learned to Defend
August 24, 2026

Why AI Learned to Attack Before It Learned to Defend

Fernando Montenegro, VP & Practice Lead at Futurum, shares his insights on how offensive AI succeeds because it's easier to verify than defensive security, shifting the need for vendors to...
Can Frontier Virtual Patching Close the AI Exposure Gap
August 24, 2026

Can Frontier Virtual Patching Close the AI Exposure Gap?

Fernando Montenegro, VP at The Futurum Group, shares insights on how Palo Alto Networks connects AI vulnerability discovery with pre-disclosure network protection....
Brinqa Buys PlexTrac to Put Proof Behind Exposure Management
August 24, 2026

Brinqa Buys PlexTrac to Put Proof Behind Exposure Management

Fernando Montenegro, VP at Futurum, analyzes Brinqa's acquisition of PlexTrac and what adding offensive security validation to an exposure management platform does, and does not, prove about remediation....
Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market
August 22, 2026

Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market

Thales positioned cybersecurity as a core growth pillar at its November 2024 Capital Markets Day, targeting a market expanding from $195B to $338B by 2029 at 11.6% CAGR, driven by...
FPT IS Bets on Vietnam's Data Privacy Law as a Platform Moment
August 22, 2026

FPT IS Bets on Vietnam’s Data Privacy Law as a Platform Moment

Vietnam's strict new data protection laws drive enterprise urgency. FPT IS launches a four-layer Data Privacy Management Platform to meet compliance demands and position itself as a strategic infrastructure partner....
DigiCert's PQC Event Franchise Shifts from Awareness to Action
August 21, 2026

DigiCert’s PQC Event Franchise Shifts from Awareness to Action

DigiCert's third annual World Quantum Readiness Day on September 17, 2026, marks a strategic shift from quantum awareness to active post-quantum cryptography deployment, addressing enterprises' top challenge: cryptographic agility....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.