Saman Zonouz is a Georgia Tech associate professor and lead researcher for the DerGuard project.

As Water Systems Face Cyberattacks, Georgia Tech Research Points to Solutions

Recent cyberattacks on municipal water systems across the United States have renewed concerns about the cybersecurity of the operational technology that supports critical infrastructure. 

For researchers in Georgia Tech's Cyber-Physical Security (CPSec) Lab, however, the vulnerabilities behind many of these incidents are far from new.

Associate Professor Saman Zonouz leads the CPSec Lab and has studied programmable logic controllers (PLCs) for years. These devices automate critical infrastructure, including water treatment facilities, power grids, manufacturing plants, and transportation systems. The lab’s work has revealed widespread internet exposure and software vulnerabilities that leave many industrial control systems vulnerable to cyberattacks.

"Out of the 16 critical infrastructure sectors defined by the Cybersecurity and Infrastructure Security Agency, four are considered lifelines," Zonouz said. "Of those four, communications, energy, transportation, and water, the water sector is the most vulnerable, which is why it is so often targeted."

PLCs serve as the brains of industrial operations, monitoring sensors and controlling equipment that keep essential services operational.

"Imagine you have a thermostat that controls the temperature of your house. That is a type of controller," Zonouz explained. "The professional version does the same thing in industry."

When these controllers are directly accessible from the internet, attackers can exploit them to disrupt operations, manipulate industrial processes, or interfere with the systems that deliver essential services. Controllers may be intentionally exposed to allow operators to monitor equipment remotely. They can also be unintentionally accessible online because of configuration errors.

However, internet exposure is only part of the problem.

The CPSec Lab maintains a collection of PLCs that researchers reverse engineer to better understand their firmware, communication protocols, and security weaknesses. Their research has found that many controllers contain vulnerabilities that attackers can exploit once they gain access.

"Not only can the attackers see the house they want to rob, but the doors are also left unlocked," Zonouz said.

In 2024, Zonouz and his collaborators presented PLCHound at the ACM Conference on Computer and Communications Security (CCS), introducing an automated system that identifies internet-connected PLCs hidden within massive internet-scale datasets collected by services such as Shodan and Censys. The work was led by Ph.D. student Ryan Pickren. Provost and Executive Vice President for Academic Affairs Raheem Beyah, Assistant Professor Frank Li, and Research Scientist Animesh Chhotaray are co-authors of the study. 

Rather than relying on traditional scanning techniques, PLCHound identifies subtle network signatures that reveal industrial devices that prior methods often missed. Using the system, the researchers conducted one of the largest studies of publicly reachable PLCs from major manufacturers.

Their findings showed that previous estimates undercounted the number of internet-accessible industrial controllers by as much as 37 times. Even more concerning, nearly 96% of the identified devices exposed protocols linked to recently disclosed critical vulnerabilities.

The researchers did more than document the problem. After identifying exposed devices, the team launched a large-scale notification campaign, contacting more than 7,000 industrial operators to alert them that their systems appeared vulnerable. The effort enabled many organizations to investigate and address security issues before they could be exploited.

The recent attacks on municipal water systems reinforce concerns researchers have raised for years: many critical infrastructure operators continue to rely on operational technology designed primarily for reliability and performance rather than for cybersecurity.

Improving those defenses, Zonouz said, will require more than simply patching individual vulnerabilities.

The researchers cite the energy sector as a model. Compared with other critical infrastructure sectors, electric utilities generally operate under more mature cybersecurity requirements and undergo routine compliance audits, providing organizations with greater visibility into the devices connected to their networks and the risks they pose.

Implementing those improvements will not be easy. Many municipal water utilities operate with limited budgets and aging infrastructure, leaving little funding available for cybersecurity investments. As attacks on critical infrastructure become more frequent, the researchers argue that gaining visibility into operational technology assets and strengthening oversight are essential first steps to protect the systems communities rely on every day.

The CPSec Lab is a collaborative laboratory within the School of Cybersecurity and Privacy as well as the School of Electrical and Computer Engineering.