read
August 6, 2026

Securing the Tap: Defending Water OT with AZT PROTECT and Perimeter Defenses

The threat landscape for municipal water systems has never been more perilous, and the regulatory spotlight has never been brighter. A flurry of attacks has taken over the news: in some cases, ransomware-based attacks cripple water production and in other cases controls on individual unprotected PLCs are being suddenly accessed by bad actors attributed to hostile nation states. This should be no surprise recent findings from the EPA's ongoing 5-year risk assessments delivered a stark reality check: over 70% of inspected municipal water systems are currently non-compliant with Section 1433 of the Safe Drinking Water Act (SDWA).

Inspectors are consistently finding critical gaps in Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs), often stemming from unchanged default passwords, exposed under protected assets, vulnerable legacy systems and an inability to keep up with the flurry of security patches that are resulting from the advent of AI Assault attacks that expose undetected production system vulnerabilities to create new attacks on the fly. Water operators are increasingly having to face taking their water systems out of automated mode and go to costly manual mode – to avoid the risk to human harm by improper water treatment.

The mandate is clear—water utilities must modernize their cybersecurity posture to maximize production and operational integrity in OT environments.

Achieving this requires a layered approach. By combining perimeter firewall rules, simple zero trust network access, and the critical deep application-level defense of AZT PROTECT, utilities can block sophisticated attacks while keeping essential operations running smoothly by staying in fully automated mode, safely allowing work from home models all the while satisfying EPA mandates and CISA guidelines.

The Blueprint for Water OT Security

Securing operational technology in a water treatment facility requires balancing strict access control with operational necessity. Here is how these three technologies work together to create a compliant, resilient architecture:

1. AZT PROTECT™: Locking Down Vulnerable Systems

Perimeter defenses and identity-based access are crucial, but they are not infallible. Despite these controls ransomware is by far the greatest successful threat by a factor of 20:1 vs other attacks in Water Waste water systems.

How so? If a threat actor manages to bypass the network controls—perhaps through a compromised Remote workers Laptop spreading ransomware into the OT environment, a vendor or SI bring in a compromised system, or a highly sophisticated lateral move—legacy operating systems and unpatched applications become sitting ducks. The rise of AI Assaults over the last few months now threatens widespread water production and waste water treatment outages.

    • The Strategy: Deploy AZT PROTECT to lock down the applications and operating systems themselves. Instead of relying solely on identifying known malware signatures, or IoCs, AZT PROTECT restricts applications to their intended, known-good state. Even if a vulnerable system is targeted, the attack is stopped in its tracks because the malicious payload is denied execution rights at the OS and application level.
    • AI Assaults are stopped: AZT PROTECT to lock downs down the application vulnerabilities from being exploited
    • Stops Ransomware and zero-day Malware: never needs an update to maintain its efficacy
    • Runs in fully air gapped environments
    • Deploys in 2 hours – on live systems - no reboot required
    • Solution typically more than pays for itself and any firewall upgrades
      - Reduced need for Security Patching saving $1000s per year
      - Protection against CVE exploits allows operations to stay in Automated
      vs. Manual mode savings $1000 per week on average
      - Preserving legacy equipment, Win 10 etc - Savings $20,000 per device

AZT Solution Water customer ROI is typically 10:1 – paying for security while significantly lowering operating and capital expenses.

2. Firewalls: Blocking General Intent Access

Programmable Logic Controllers (PLCs) are the granular controls of water operations, controlling everything from chemical mixtures to pump pressures. They were historically designed for reliability, not security, and should never be directly exposed to general IT networks or the public internet.

    • The Strategy: Implement strict firewall rules that block all general internet and unauthorized access to PLCs. Firewalls act as the primary gatekeeper, ensuring that only highly specific, pre-approved traffic can even attempt to communicate with critical control systems. Most existing firewalls can lock down PLCs by their Internet address such that they cannot communicate out or be communicated to from the general Internet.

3. VPNs: Secure Access for Remote Operators

While PLCs need to be isolated, sanctioned remote human operators still require access. With the rise of remote work and off-site troubleshooting, plant managers and engineers need a way to monitor systems without physically being on the facility floor.

    • The Strategy: Deploy simple, encrypted Virtual Private Networks (VPNs). By routing known employees working from home through a secure VPN tunnel, the firewall can authenticate their identity and grant them highly restricted, role-based access to the OT network. This satisfies the operational need for remote visibility without exposing the network to the wider internet. VPN clients can be deployed on home devices to provide secure connectivity between those devices and the Water plant firewall(s).

Achieving SDWA Section 1433 Compliance

Section 1433 of the SDWA requires community water systems serving over 3,300 people to evaluate the vulnerabilities of their electronic and automated systems and develop concrete strategies to mitigate those risks.

By implementing this triad of defenses, water municipalities can directly address the EPA's core concerns:

Technology

Security Benefit

SDWA Compliance Impact

Firewalls

Eliminates public internet exposure.

Mitigates unauthorized access risks highlighted in RRAs.

VPNs

Cryptographically controls remote access.

Removes the threat of shared logins and unsecured remote connections.

AZT PROTECT

Stop Ransomware, AI based attacks, while it secures vulnerable, unpatchable legacy systems.

Demonstrates robust system resilience in ERPs, ensuring continuity of service even during an attempted breach.
Unpatched CVEs are no longer a concern. Keep your systems running safely in full automation mode.

 

Water is our most critical resource. By strategically combining AZT PROTECT with existing firewalls, and simple VPNs, municipal systems can close the glaring compliance gaps identified by the EPA and ensure safe, uninterrupted service for their communities.

 

Effective Cybersecurity Starts with a Trusted Partner

For more than 50 years, ARIA Cybersecurity has delivered peace of mind to some of the world’s most critical organizations—including the U.S. Department of Defense and Western intelligence agencies. Our proven patented solutions and expert team are here to help you protect what matters most.

To learn more about AZT PROTECT, click here.

Tags: cyber attack, cybersecurity, operational technology