Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Water treatment plants and utilities stay connected because they must monitor and manage equipment spread across large areas, including wells, pumps, tanks, and lift stations. That operational need does not mean a programmable logic controller (PLC) or operator interface should be directly reachable from the public internet. The key distinction is between controlled remote connectivity and unrestricted exposure.

Why water utilities need connected systems

Many water and wastewater assets sit far from a central treatment plant. Operators need visibility into their status and operating conditions, and supervisory control and data acquisition (SCADA) systems can bring information from remote sites together. The National Institute of Standards and Technology describes this connected ecosystem as supporting activities such as monitoring pumping stations and evaluating water quality, as well as analyzing data to improve operations and service. It does not quantify labor or cost savings.

  • Remote monitoring: Wells, tanks, pumps, and lift stations can report conditions without an operator having to visit each site just to check its status.
  • Centralized operations: SCADA systems let operators observe processes across multiple locations. A human-machine interface (HMI) is the operator-facing display; PLCs are controllers that operate equipment.
  • Remote support: Utility staff or system integrators may need to connect to equipment for operational tasks and maintenance. EPA recognizes remote-site management as a possible need, while NIST’s SP 1800-45 describes secure remote-access reference designs.

Utilities also operate a mix of older and newer technology. EPA warns that many SCADA and operational technology (OT) systems were not designed with cybersecurity in mind and may not be updated regularly, so their connectivity and security controls vary. There is no single architecture shared by every plant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Connected” does not always mean publicly exposed

An OT system may communicate over a private carrier network, across a segmented network, or through a controlled VPN or gateway. Those arrangements differ from assigning a publicly reachable address to an HMI or PLC. EPA specifically flags cellular modems as a connection that can be overlooked and recommends private telecom networks where possible. CISA’s July 30, 2026 advisory says remote access should go through a VPN or gateway device, not directly to a PLC.

#1 Best Overall
Moxa nat-102-2 Ports Industrial Network Address Translation Devices, -10 to 60°C. NAT
  • User-friendly NAT functionality simplifies network integration
  • Hands-free network access control through automatic whitelisting of locally connected devices
  • Integrated security features to ensure device and network safety
  • Ultra-compact size and robust industrial design suitable for cabinet installation
  • Supports secure boot for checking system integrity

EPA’s guidance is explicit: “Eliminate OT asset connections to the public Internet unless explicitly required for operations.” If a connection is genuinely required, the utility should document its operational reason and apply safeguards. The available agency sources do not establish what share of water plants use each architecture, or how many are directly exposed.

What can go wrong when OT is exposed

Publicly reachable HMIs can reveal information such as system maps, event logs, and security settings. Depending on the system and access protections, an unauthorized person may also be able to make changes that disrupt treatment or operations.

Rank #2
Vrupin 32 Piece Closed Rubber Grommet Firewall Solid Closed Hole Plug Kit, Tower and Round Double Sided Rubber Hole Plugs for Wire Electrical Plumbing Systems.
  • Great Variety of Sizes: 32 Pcs of the most commonly used 15 sizes assorted rubber grommet assortment kit.With retractable box cutter and velcro straps
  • High Quality: Rubber washers are made of flexible and durable rubber material, they are of good electric resistance capability.
  • Easy To Use: Wire grommets are quicker and easier to install since they can be placed on one side only.
  • Wide Range of Applications: Very useful for auto and other projects where wiring cable needs to be run through metal or plastic openings.
  • Packaging Includes:2-3/8''Drill Hole(2 Pcs),2''Drill Hole(2 Pcs)(2 Pcs),1-9/16''Drill Hole(2 Pcs),1-3/8''Drill Hole(2 Pcs),1-3/16''Drill Hole(2 Pcs),1''Drill Hole(2 Pcs),7/8''Drill Hole(2 Pcs),2-3/8''Drill Hole(2 Pcs),2''Drill Hole(2 Pcs),1-9/16''Drill Hole(2 Pcs),1-3/8''Drill Hole(2 Pcs),1-3/16''Drill Hole(2 Pcs),1''Drill Hole(2 Pcs),7/8''Drill Hole(2 Pcs),13/16''Drill Hole(2 Pcs).With retractable box cutter and velcro straps

In a joint fact sheet dated December 13, 2024, EPA and CISA described 2024 incidents in which pro-Russia hacktivists altered pump and blower set points, disabled alarms, and changed passwords. Affected utilities reverted to manual operations. These reported cases show a potential operational consequence; they are not a measure of how common such incidents are across the sector.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On July 30, 2026, CISA warned of increased targeting of water-sector PLCs. Its advisory said attackers changed passwords to lock out operators and changed PLC IP addresses; the activity resulted in boil-water notices and sustained manual operation. CISA also warned that cellular modems can be overlooked exposure paths. This is a dated advisory about reported activity, not evidence that every utility faces the same incident pattern.

How utilities can reduce exposure while preserving necessary access

EPA and CISA guidance emphasizes reducing public-facing exposure first, then protecting remote access that operations truly require. Because remote changes can affect essential service, decisions should involve the OT owner and a qualified system integrator.

  1. Inventory every connection. Identify internet-reachable devices and paths, including cellular modems, vendor-installed equipment, wireless links, and remote assets. Do not assume routine scans found every route.
  2. Remove unnecessary public access. Disconnect exposed HMIs and other accessible, unprotected systems from the public-facing internet where possible. For connections that must remain, document why they are operationally necessary and name an owner responsible for them.
  3. Put an intermediary between remote users and controllers. Route required remote access through a VPN or gateway rather than connecting directly to a PLC. Use network segmentation, such as a demilitarized zone (DMZ) or bastion host, to separate OT assets from other networks.
  4. Restrict and verify access. Use multifactor authentication (MFA), strong non-default credentials, and changed default passwords. Limit access to known IP addresses where appropriate.
  5. Maintain and monitor systems. Keep software patched and log remote logins so staff can look for unusual timing or repeated failed attempts.
  6. Prepare for recovery. Keep known-clean backups of PLC images so operators have a recovery path if credentials or configurations are changed.
  7. Get appropriate help. CISA recommends its free cyber vulnerability scanning service and qualified system-integrator support when needed. Its June 4, 2025 Internet Exposure Reduction Guidance also advises organizations to assess exposure, determine which assets need internet access, protect necessary exposed services, and review exposure routinely.

These are layers of risk reduction, not a guarantee that one control makes an OT environment secure. A utility should select and apply controls with operational context so that security changes do not themselves interrupt service.

Rank #4
MOXA EDR-810-2GSFP Industrial Secure Router Switch--- NO VPN--- with 8 10/100BaseT(X) Ports, 2 1000BaseSFP Slots, 1 WAN, Firewall/NAT, -10 to 60C
  • MOXA EDR-810-2GSFP Industrial Secure Router Switch with 8 10/100BaseT(X) ports, 2 1000BaseSFP slots, 1 WAN, Firewall/NAT, -10to60C -- NO VPN --
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to judge whether a connection is appropriate

When evaluating a water system’s remote connectivity, focus on the design and controls rather than the mere presence of a network connection:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Operational need: Is public internet access truly necessary, or can the task use a private network or controlled gateway?
  • Reachability: Is a PLC or HMI directly accessible, or protected behind a segmented boundary and intermediary?
  • Identity and permissions: Are MFA, strong unique credentials, and suitable access restrictions in place?
  • Visibility and recovery: Are remote logins recorded, and are known-clean PLC backups available?
  • Completeness: Have cellular modems, remote sites, and vendor-installed equipment been included in the inventory?

NIST SP 1800-45, published June 24, 2026, provides reference designs for secure remote access in the water and wastewater sector. These designs are examples for planning, not proof that all utilities use the same setup.

Best Value
MOXA EDR-810-2GSFP-T - Industrial Secure Router with Switch/Firewall/NAT - NO VPN- 8 10/100BaseT(X) Ports, 2 1000BaseSFP Slots, 1 WAN, -10 to 75C
  • 8+2G all-in-one firewall/NAT --- NO VPN-------/router/switch
  • Build up secure remote access tunnel / Protect critical assets by stateful firewall
  • Inspect industrial protocol with PacketGuard technology / Easy network setup with network address translation (NAT)
  • RSTP/Turbo Ring redundant protocol enhances network redundancy / -40 to 75°C operating temperature range
  • Security features based on IEC 62443 / NERC CIP / Check firewall settings with intelligent SettingCheck feature

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.