Imagine you run operations at a small water utility. You’ve got a programmable logic controller, a PLC, quietly managing pumps and chemical dosing. It’s been running fine for years. Then a CISA advisory lands in your inbox on a Thursday afternoon telling you that dozens of systems just like yours, in Minnesota, were breached. Not through some sophisticated nation-state exploit. Because the controllers were sitting on the open internet with weak or default credentials, waiting to be found.
That’s the situation CISA described on July 31, 2026. And while the target was the water and wastewater sector, the lesson underneath it belongs to every organization running something that quietly touches the internet and rarely gets checked. Nonprofits included.
What CISA actually warned about
According to BleepingComputer, CISA issued an urgent advisory about a significant increase in cyberattacks aimed at internet-exposed PLCs in the water and wastewater systems sector. The agency urged utilities to immediately lock down exposed controllers. The warning followed confirmed intrusions hitting dozens of Minnesota water systems.
The mechanics here matter, because they aren’t exotic. A PLC is an industrial controller, essentially a small purpose-built computer. When one of these is directly reachable from the public internet, attackers can scan for it, find it, and try known default passwords or unpatched weaknesses. No phishing email required. No insider. Just an exposed device that should never have been reachable in the first place.
CISA’s guidance was direct: get these controllers off the open internet, put them behind a firewall or VPN, change default credentials, and apply available updates. Basic controls. The kind that get skipped when a system “just works” and nobody’s watching it.
Why a nonprofit should care about a water utility breach
You’re probably not running a wastewater PLC. But you are almost certainly running something that fits the same pattern: a device or service that touches the internet, that got set up once, and that nobody has reviewed since.
Think about the security camera system a donor funded three years ago, reachable through a web portal with the password the installer set. The door-access controller for your building. A remote-access tool an IT volunteer stood up during the pandemic so people could reach the office network from home. A network-attached storage box holding case files or donor records, shared out so a remote team member could grab a document. Each of these can end up exposed to the internet the same way those water controllers were. And attackers scan the entire internet constantly. They don’t skip your organization because your mission is good.
For a nonprofit, the stakes are specific. An exposed system can be the doorway into donor data, grant records, or the personal information of the people you serve. A breach doesn’t just cost money you don’t have. It costs the trust that makes your work possible. Donors give because they believe you’ll protect what they hand you. A funder auditing a grant wants to know their data was handled responsibly. One exposed device can undo years of that.
The uncomfortable truth in the CISA advisory is that the breached utilities weren’t targeted because someone hated them. They were breached because they were reachable. Being small, being mission-driven, being under-resourced, none of that makes you invisible. It often makes you an easier find.
What to do right now
You don’t need an industrial control system to act on this warning. You need to answer one question: what does my organization have sitting on the internet that I haven’t looked at?
- Inventory what’s exposed. List every device and service reachable from outside your network. Cameras, door controllers, remote-access tools, file shares, any “appliance” a vendor installed. If you can’t produce this list, that’s the first finding.
- Kill default and weak passwords. Every exposed device gets a strong, unique credential. Default passwords are the single reason those water controllers fell. This is the highest-value hour you’ll spend this month.
- Get exposed systems behind a barrier. Devices that don’t need to be on the open internet should sit behind a firewall or require a VPN to reach. Remote access should be gated, not open.
- Turn on multi-factor authentication. Anywhere it’s available, especially on remote-access tools and cloud services holding donor or client data.
- Apply the updates you’ve been ignoring. The patches sitting undone on that camera system or NAS box are the exact weaknesses attackers scan for.
If your team is three people and one of them is you, this is precisely the work that falls through the cracks, not because you don’t care, but because nobody has the bandwidth to hunt for exposed systems. That’s a reasonable place to ask for help.
Common Questions
We’re a small nonprofit. Are we really a target? You’re not being singled out, and that’s the point. Attackers scan the entire internet for exposed systems and try to break into whatever answers. Your size and mission don’t remove you from the scan. Exposed is exposed.
How do I even know what’s exposed to the internet? Start with an inventory of every device and service reachable from outside your network, then have someone technical run an external scan against your public address. A managed IT provider can do this quickly and tell you exactly what an attacker would see.
We don’t have industrial controllers, so does this advisory apply to us? The advisory targeted water utilities, but the failure mode is universal: an internet-exposed device with weak credentials and no oversight. Cameras, remote-access tools, and file shares fail the same way. The lesson transfers directly.
What’s the single most important thing to do first? Remove default and weak passwords from anything reachable from the internet. Default credentials were the entry point in the breached water systems, and fixing them is the fastest way to close the most common door.
centrexIT has been the IT team nonprofit organizations across the West have trusted since 2002. If you’re not sure what your organization has exposed to the internet, that’s exactly the gap worth closing before an attacker finds it first. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/
Sources
- CISA warned of increased attacks on internet-exposed PLCs in the water and wastewater sector on July 31, 2026, following intrusions at dozens of Minnesota water systems: BleepingComputer, “CISA warns of attacks targeting exposed water system controllers” (2026), https://www.bleepingcomputer.com/news/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team