
💦 Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
🔓 Minnesota counted over 30 community water systems targeted inside 48 hours in late July, CISA warned the whole water sector days later about threat actors going after internet-exposed controllers, and the FBI and EPA separately said utilities in at least seven unnamed states had reported incidents to the FBI. Publicly disclosed impacts stayed limited; the governance question they surfaced did not. Federal guidance tells utilities how to inspect and restore a locked controller safely, and for the MicroLogix devices the alerts name, Rockwell’s own manuals document no password bypass: the recovery path is clearing controller memory, which removes the running program. None of the documents reviewed for this piece says who should capture a controller’s running project or configuration first, when doing so is safe and feasible.
⚖️ For cybersecurity, data privacy, compliance and eDiscovery professionals, that lands in familiar territory: preservation duties, third-party records and litigation holds, applied to devices many data maps have never seen.
🔎 Watch what comes next: attribution remains open, preservation questions may follow as the incident record develops, and New York’s newly adopted rules put drinking-water requirements on a compliance clock ending Jan. 1, 2027.
📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at complexdiscovery.com/restore-the-co….
#WaterSector #OTSecurity #ICS #CISA #IncidentResponse #DataPreservation #LegalTech #eDiscovery


English


































