Cybersecurity discussions around critical infrastructure often focus on the biggest and most visible targets, from national power grids to major energy networks. But for attackers looking to exploit operational technology (OT), the less prominent infrastructure supporting water and gas networks may offer equally attractive opportunities.
As critical infrastructure becomes increasingly connected, the security perimeter is no longer confined to the control room. Water and gas operators depend on distributed networks of sensors, remote telemetry units (RTUs), communications links and other connected field equipment to monitor and control assets across large geographical areas. Each of these devices can introduce another potential route into an operational environment.
Here, Julian Booth, SCADA Service Delivery Manager at Ovarro, argues that securing critical infrastructure means looking beyond the central SCADA platform and protecting the entire telemetry chain – from the control room to the remote Edge. He examines why legacy equipment, dispersed assets and increasingly connected operations are creating new cybersecurity challenges for water and gas operators, and why a more proactive approach to securing RTUs and communications infrastructure is becoming essential.
A wider attack surface
In water and gas networks, SCADA systems allow operators to monitor assets, track alarms, collect data and support operational decisions across large, dispersed sites.
However, SCADA is not simply a central software platform. It also depends on field devices that connect remote assets to the central system.
Remote Telemetry Units (RTUs) sit at this critical Edge layer, collecting data from remote sites and communicating it back to the central SCADA system. If they are not properly secured, they can become weak points in an otherwise protected architecture.
The consequences can extend far beyond data loss. In 2021, the BBC reported that a hacker accessed the water system of Oldsmar, Florida, and attempted to increase sodium hydroxide levels in the water treatment process. The incident was spotted and reversed by an operator, but it showed how cyber compromise can move quickly from digital access to physical process manipulation.
In water and gas networks, such attacks could potentially target pumping stations, valves, pressure management systems or dosing processes. Even where built-in safeguards prevent a dangerous outcome, the operational, reputational and regulatory impact of an incident can be significant.
A wider attack surface
Power grids are often seen as the highest-profile cyber targets in critical infrastructure. However, water and gas networks present a different kind of risk.
These systems are highly distributed. They often include remote, unmanned assets, legacy equipment, communications links and field devices spread across large operating areas. Many assets are difficult to access, expected to remain in service for many years, and connected back to central systems through telemetry infrastructure.
The attack surface is therefore not limited to the control room. It extends across the network.
For many years, cybersecurity activity in SCADA environments focused heavily on central systems. That remains vital. Servers, software platforms, user access and control-room infrastructure all need to be protected. However, operators are now paying closer attention to the wider telemetry chain.
A practical approach to securing distributed SCADA networks must cover three areas: the central SCADA system, the RTUs themselves and the communications paths between them. This means hardening central systems and servers, hardening RTUs at the Edge and protecting the routes that connect remote sites to the wider operational environment.
Moving from reactive to proactive security
A common weakness in OT environments is legacy infrastructure. Many organisations have historically been willing to run older systems for long periods, sometimes using operating systems that are no longer supported by suppliers.
This creates risk. As new vulnerabilities are discovered, patches may not be available for unsupported systems. Even where patches do exist, operators must carefully manage how and when updates are deployed, because SCADA and telemetry systems often support essential live operations.
A more proactive approach starts with visibility. Operators must understand where assets are, what software and firmware they run on, how they communicate and which vulnerabilities present the greatest risk.
Vulnerability scanning, patching and pre-production environments can all help. Pre-production environments are particularly important because they allow teams to test updates, patches and configuration changes before deploying them into live operational environments.
This is where adaptive security becomes important. Rather than relying on static controls, operators need systems and processes that can respond as risks change.
Securing the Edge
Ovarro’s work with Greater Western Water in Victoria, Australia, shows this resilience objective in practice. The utility needed to replace legacy RTUs at more than 100 critical sites, selecting Ovarro’s TBox LT2 for its protocol compliance, low power operation and easy installation.
The TBox LT2 provided real-time data access and seamless integration with the utility’s existing systems, while supporting the replacement of its legacy telemetry infrastructure.
Integration with existing SCADA templates required no changes, helping minimise disruption while improving real-time monitoring across operational infrastructure.
This kind of project demonstrates why RTUs matter to cyber resilience. They are not simply data collection devices. They are part of the secure link that connects critical assets to central decision-making.