
Remediation Guide
Cyber Resilience Assessment Questionnaire for
Water and Wastewater Facilities Against Iran-Linked Cyber Threats
Assessing Your Water Utility's Readiness Against Iran-Linked OT Cyber Threats
In November 2023, IRGC-affiliated actors operating under the persona "CyberAv3ngers" began compromising internet-connected Unitronics Vision Series PLCs across US and international water utilities. They didn't need a zero-day. They authenticated using default or absent passwords and gained full engineering access to at least 75 devices. A follow-on joint advisory, updated as recently as July 2026, documents a second, more advanced campaign: Iranian-affiliated actors exploiting internet-facing PLCs from Rockwell Automation, Siemens, and Schneider Electric, using the vendors' own legitimate engineering software to alter control logic and falsify what operators see on their HMI screens.
This isn't speculative threat modeling. It's two joint advisories from CISA, the FBI, NSA, EPA, and international partners, naming water and wastewater systems among the confirmed victims. And it raises a question most utilities can't answer with confidence: if the same technique were pointed at your facility, would it work?
Shieldworkz built the Cyber Resilience Assessment Questionnaire for Water and Wastewater Facilities Against Iran-Linked Cyber Threats to answer that question, with discipline. It's a 112-question, 13-domain self-assessment that traces every question back to a documented attack pathway, not generic best practice dressed up as threat intelligence, telling you precisely where these campaigns would have found an opening in your environment.
Why This Assessment Matters
Most OT security questionnaires ask generic maturity questions borrowed from IT frameworks. This one is built backward from two real campaigns, so every domain and every critical control traces to a specific, cited technique rather than assumed best practice.
Internet exposure as the confirmed entry point: internet-exposed PLCs and HMIs were the documented initial-access vector in both campaigns.
Default credentials as the exact 2023 mechanism: unremediated factory-default passwords gave attackers full engineering access with no technical sophistication required.
Legitimate software as the 2026 attack tool: control logic was altered using the vendor's own engineering software, not custom malware, which is why change-detection matters more than antivirus.
Falsified displays as a documented technique: HMI and SCADA screens showed values inconsistent with the actual process state, concealing the compromise from operators.
The assessment is also careful never to overstate what the evidence shows. It distinguishes explicitly between what's documented and attributed to Iran-linked actors, what's been observed against OT/ICS environments generally, and what's simply sound OT security practice, so findings stay defensible in front of a board or a regulator.
Key Takeaways From the Assessment
Thirteen domains, mapped to real frameworks. From Governance and Asset Visibility through Engineering Workstation Security, Detection, Incident Response, Backup and Recovery, and Physical Consequences, each domain maps to NIST CSF, NIST SP 800-82, or IEC 62443, so findings trace back to established practice, not assessor opinion.
A scoring model that can't be gamed by good paperwork. The methodology deliberately avoids letting a facility with strong governance scores numerically offset a single catastrophic gap. If a critical control, like an internet-exposed PLC or an untested incident response plan, scores zero or one, the overall grade is capped at D no matter what the percentage says.
Eight critical findings that override everything else. Internet-exposed OT devices, default credentials, absent IT/OT segmentation, uncontrolled remote access, no visibility into unauthorized logic changes, an untested IR plan, unreliable recovery capability, and no manual operating fallback, each one tied directly to a documented attack pathway, not a theoretical risk.
Behavioral detection over indicator matching. CISA has already withdrawn the original 2023 indicators of compromise as outdated, and the 2026 campaign has evolved across multiple vendors. The assessment scores whether you can detect unexpected write commands, new devices, and abnormal engineering activity, because static IOCs won't catch what comes next.
Manual operations as the ultimate backstop. Domain L asks the question that decides outcomes during a real intrusion: can the plant keep making safe water if SCADA is compromised, unavailable, or lying to the operator? Every other control reduces the likelihood of compromise; this one limits the consequence when everything else fails.
How Shieldworkz Supports Your CISA and EPA Compliance Readiness
Completing the assessment tells you where you stand. Closing what it finds is where Shieldworkz comes in. CISA, the FBI, NSA, and EPA have issued two joint advisories on this threat set in under three years, signaling growing regulatory expectation that utilities can demonstrate, not just claim, defensive readiness against known attack pathways.
OThello Assess: validates the exposure findings this questionnaire surfaces, mapping your actual internet-facing PLCs, RTUs, and HMIs in sub-24-hour assessment cycles.
OT network detection and response: delivers the behavioral monitoring this assessment scores you against, unauthorized write commands, new devices, and anomalous engineering activity.
Incident response tabletop exercises: scoped to the same scenarios this questionnaire tests, PLC logic tampering, HMI falsification, and remote-access compromise, so a tested plan is a fact, not a checkbox.
Regulatory readiness engagements: translate CISA advisory guidance, EPA sector expectations, and IEC 62443 requirements into remediation your team can actually execute, sequenced by consequence, not convenience.
Utilities that pair this assessment with Shieldworkz validation get more than a grade. They get an evidence-backed answer to the question every board eventually asks: are we exposed to a threat that has already compromised facilities like ours?
Download the Assessment
Two documented campaigns have already targeted water-sector OT with these techniques. The next one won't announce itself in advance.
Fill in the form to receive your free copy of the Cyber Resilience Assessment Questionnaire for Water and Wastewater Facilities Against Iran-Linked Cyber Threats. You'll also have the option to book a no-obligation consultation with a Shieldworkz OT security expert, who can help you interpret your scores, validate your critical findings, and prioritize remediation by consequence.
Schedule a Demo With Shieldworkz OT Security Experts
Download your copy today!
Assess your utility's resilience against documented Iran-linked OT cyber threats. Download the Free Cyber Resilience Assessment Questionnaire today.
