Why this matters: attackers took over small water systems across the country this summer without exploiting a single software flaw — and Vermont's own program to help systems like yours has yet to deliver. Here's what you can do without waiting for it.

No one exploited a software flaw to take down water plants this summer. The controllers were reachable from the open internet, and the attackers changed their passwords. Most of the fix is not a purchase order. It's an afternoon.

Find out what's exposed. Ask your integrator or your internet provider one question: is anything at the plant port-forwarded from the internet? You're allowed to check your own equipment — look your utility's own public IP address up on a free Shodan account and see what answers.

Close it. The ports that matter here are 44818 and 502, plus any web login pointed at a controller. Deleting that firewall rule is the whole fix for the attack that actually happened. It costs nothing.

Then give the access back safely. Take remote access away without replacing it and it returns as a new port-forward within six months, because operators really do need to see the plant at 2 a.m. Route it through a VPN into the plant network first — a feature most business firewalls already have and nobody switched on. CISA's July guidance on isolating vital systems covers exactly this.

Back up your controller program and write the date on it. One utility in this campaign caught the intruders by noticing its ladder logic no longer matched across sites. You can't spot a modified program with nothing to compare it to.

Check that safety interlocks are hardwired. If overpressure protection exists only in software, whoever controls the software controls the safety case.

Write the one-page manual-operation sheet. When Braham, Minnesota lost its controls, the plant came back on manual. Every system should have a single page a fill-in operator can follow at 2 a.m. It's free, and it's the difference between an incident and a boil-water notice.

Free help, one email each

CISA will scan your utility from outside, at no cost, indefinitely. Email vulnerability@cisa.dhs.gov, subject line "Requesting Vulnerability Scanning Services," with your utility's name, a contact, and your headquarters address. Two forms come back; scanning starts in about 10 days. Weekly reports after that, and urgent findings get flagged within 24 hours. Details here.

Vermont has a cybersecurity circuit rider, and almost nobody knows it. The Vermont Rural Water Association was one of only two state associations in the country — the other is Oregon — picked for a national program run with the USDA and the White House cyber office: free onsite cybersecurity assessments for drinking water systems. Programs like this come and go with their funding, so ask VRWA what's on offer this year — the ask itself puts your system on their radar.

EPA runs free assessments and a help desk for water and wastewater systems.

Free threat alerts, for nearly every Vermont system — but not for long. Through the end of 2026, systems serving fewer than 10,000 people can get a 12-month WaterISAC membership at no cost through their state rural water association. That threshold covers almost every system in Vermont. Application here.

The training the state's stalled program was going to give you is already free, from the Cyber Readiness Institute — the same organization the state's own plan named as its source.