Hackers disabled alarms and altered pumping cycles at two small Colorado water utilities in late August, a warning sign for UK operators who assume OT breaches are a US-only problem. The tactics — not the target size — are what should worry UK buyers.
View the data behind this chart
| State-linked | Other | |
|---|---|---|
| Share of incidents | %75 | %25 |
What happened in Colorado, and why it reads differently to a typical breach
According to SecurityWeek, attackers described only as "foreign actors" targeted industrial control systems at two private Colorado water utilities serving fewer than 200 people, changing equipment settings, disabling remote access and alarms, and altering pumping cycles. The disruption was brief and did not affect water services or public safety, but the intent — degrading operator visibility and process control simultaneously — is a more deliberate attack pattern than a simple ransomware encryption event.
A spokesperson for Colorado's governor told The Denver Post the state cannot confirm which foreign actors were involved, but noted CISA's ongoing awareness of an Iranian-backed group targeting drinking water and wastewater systems nationally. It has not been confirmed whether this incident is linked to the wider campaign that hit water utilities across at least a dozen US states in July, including confirmed targets in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin and Alabama.
Alarm and pump-cycle tampering: a more advanced escalation
Disabling alarms while altering pumping cycles could indicate attackers understood the process logic well enough to hide their own changes from operators — not just to cause outage, but to erode trust in monitoring itself. That distinction matters for UK buyers assessing risk: an attacker who can silence your alerting layer has effectively removed your early-warning system before doing anything else.
CISA said it is aware of 100 internet-exposed water systems targeted in cyberattacks during July alone, and independent group Infracritical has since built a central repository of technical indicators from the breaches. Experts warn that similar patterns – small utilities, exposed remote access, minimal segmentation – are still seen in UK water, energy and district-heating environments.
UK critical infrastructure is already under comparable pressure
This isn't a hypothetical import risk. NCSC CEO Dr Richard Horne has said the agency handled more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026, with roughly 75% believed linked to state actors. A separate NCSC and partner warning highlighted state-sponsored attackers hiding on critical infrastructure networks using techniques defenders can only catch with out-of-band logging and stronger segmentation.
A 2026 analysis reported widespread poor IT-OT segmentation across UK CNI — meaning lateral movement from a compromised business network into SCADA and ICS environments remains a common weak point across UK operators.

Backup and DR readiness is now a core OT defensive control, not an afterthought
NCSC's latest OT advice explicitly calls for tested backups and recovery procedures, including backups of controller logic and engineering data and regular restoration practice, alongside strong segmentation between OT, management and business networks to contain any breach and preserve recovery options.
For SCADA-heavy estates, that means treating robust backup and disaster recovery strategies as inseparable from ICS security, not a separate IT workstream. Where ransomware or tampering can corrupt controller configurations as easily as file servers, operators should understand immutable backups for enhanced protection and consider how a clean-room recovery and cyber recovery vault approach isolates a trusted recovery point from an actively compromised network.
What UK water, energy and utilities buyers should check now
NCSC guidance is specific about the fundamentals still missing at too many sites: keeping PLCs and HMIs off the public internet, maintaining a definitive OT asset inventory, enforcing strong authentication on remote access, and adopting secure configurations or modern alternatives to insecure legacy protocols where feasible. Devices providing external connectivity — gateways, firewalls, routers, remote access appliances — should stay within vendor support and be replaced before end of life.
UK operators, particularly in water, energy and manufacturing, should treat this Colorado incident as a prompt to test rather than assume readiness.
- •Verify no PLC, HMI or remote access appliance is internet-facing without strong authentication
- •Confirm OT, management and business networks are genuinely segmented, not just logically separated on paper
- •Test restoration of controller logic and engineering data on a realistic schedule, not annually on paper
- •Run tabletop exercises against a state-actor threat model, not a legacy ransomware-only scenario
- •Review whether cloud-hosted SCADA deployments have vendor confirmation before treating cloud as a backup destination
View the data behind this chart
| Traditional Backup | Immutable Backup | Recovery Vault | |
|---|---|---|---|
| Ransomware resilience | Vulnerable to encryption | Write-once protection | Isolated air-gapped copy |
| Recovery speed | Hours to days | Hours | Minutes to hours |
| OT protocol/config coverage | Limited | Partial | Full logic + engineering data |
| Separation from live network | None | Logical | Physical/air-gapped |
Sizing the exposure and the cost of getting it wrong
Bridewell's 2026 CNI research found AI risk has entered the top tier of concern for a growing share of organisations, a sign that OT threat prioritisation is broadening even as fundamentals like segmentation and backup testing remain unresolved for most operators. Boards should be asking both questions at once, not trading one for the other.
Before budgeting a fix, UK buyers should assess your backup and DR readiness against current OT-specific guidance, and use tools to calculate the potential cost of downtime against a realistic SCADA incident scenario rather than a generic IT outage. Operators evaluating their exposure holistically may also benefit from comprehensive cybersecurity solutions that treat OT segmentation, MDR and DR as one architecture rather than three separate purchases.
- 01SecurityWeek — Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems · 15 September 2026
- 02NCSC — Disruptive cyber activity highlights risk from internet-exposed systems and edge devices · 1 September 2026
- 03NCSC — NCSC CEO: hostile states linked to three-quarters of cyber attacks · 1 June 2026
- 04Computer Weekly — Global conflicts accelerate cyber threats against UK CNI · 1 January 2026
- 05Computer Weekly — AI makes debut in Bridewell cyber security in CNI report · 1 January 2026
- 06NCSC — State-sponsored cyber attackers hiding on critical infrastructure networks · 1 January 2026
- 07ncsc.gov.uk
