Recent cyberattacks against U.S. water and wastewater systems carry a warning well beyond municipal treatment plants. The same kind of internet-connected industrial equipment used to control water pumps, valves, chemical processes, alarms and monitoring systems also sits behind an expanding range of agricultural infrastructure—from irrigation pivots and well pumps to grain dryers, feed systems and poultry-house ventilation.
Federal agencies have warned that attackers are actively targeting internet-exposed programmable logic controllers, commonly called PLCs. These are rugged industrial computers that receive sensor data and direct physical equipment to act. A PLC can start a pump, open a valve, operate a conveyor, trigger an alarm, regulate a fan, or shut down a process when something goes wrong. In other words, if a bad actor gains control of PLC, the potential result is a physical disruption.
CISA reported a significant rise in attacks against internet-connected PLCs in the water and wastewater sector during the summer. In some cases, attackers reportedly changed passwords to lock operators out, altered IP-address settings, accessed controller project files, manipulated screens used by operators, and changed or deleted control logic. The consequences included disruptions, long periods of manual operation and, in some circumstances, boil-water notices.
Initial reports identified devices made by Siemens. However, devices from other manufacturers were also targeted, including equipment from Rockwell Automation, Allen-Bradley, and Schneider Electric. Rather than focusing on equipment brands, experts say the more relevant question is whether an operation has any remotely connected device that can control a physical process.
Irrigation is likely the clearest farm-level example. A connected system may include a well pump, pivot, booster pump, valve controller, soil-moisture sensor, flow meter, pressure monitor, weather station, fertigation system, cellular modem and cloud-based phone application. A compromise could prevent an operator from reaching a controller, interrupt irrigation during a heat-stress period, issue false data about soil moisture or flow, or change settings that control valves and pumps.
Livestock and poultry operations are also a concern, as facilities increasingly rely on connected systems for ventilation, heating, cooling pads, water delivery, feed, lighting, manure handling and environmental alarms. The same exposure can exist around grain drying, storage and movement. Grain bins and dryers may use temperature cables, fan controls, aeration systems, augers, conveyors, loadout equipment and remote-monitoring software.
Bottom line, systems that allow producers to monitor conditions and manipulate equipment remotely are convenient but need to be protected. Above all, none of these systems should be accessible directly from the public internet. CISA advises that all remote access pass through a firewall, VPN, secure gateway or controlled jump host. Access should be limited to authorized users, protected with multifactor authentication, and reviewed regularly.
Other practical measures include changing default passwords, eliminating shared passwords, disabling unused remote services, updating supported firmware, segmenting farm-office networks from control networks and keeping tested offline backups of PLC logic and configuration files. Operators should also make sure critical systems can be run safely in local or manual mode if a remote connection fails.
The lesson from the water-plant incidents is not that every connected farm device is unsafe. Connected equipment can improve labor efficiency, conserve water, reduce input waste and help operators manage dispersed assets. But the more a device can control a physical process, the more carefully it should be secured. (Sources: Reuters, South Dakota State, GAO, CISA)

