Cody Bann • September 29, 2026

When Hackers Target Your PLC, Alarm Notification Becomes a Critical Line of Defense

Last month, the Cybersecurity and Infrastructure Agency (CISA) confirmed that over 100 U.S. water and wastewater systems were targeted by cyberattacks in July. The attacks focused on PLCs from Rockwell, Schneider Electric, and Siemens. Some intrusions allowed attackers to disable alarms, precluding alarm notification. The communities hit hardest were largely rural, where a disruption to water infrastructure affects a large area with limited backup resources.

For many years I’ve been writing and presenting on OT cybersecurity as it relates to the water and wastewater sector. I’ve shared my views at WEFTEC, with the NRWA, and in trade publications including Water Online and Pumps & Systems. The consistent message has been that water utilities face a specific and underappreciated combination of risk factors that make them attractive targets: aging infrastructure with minimal built-in security, the convergence of IT and OT networks as facilities modernize, and a fragmented regulatory environment that leaves many smaller systems without meaningful cybersecurity guidance or resources.

What has changed is the barrier to entry for attackers has dropped while sophistication of the attacks has increased. CISA noted that the current wave of intrusions is using AI tools to develop scripts capable of targeting vulnerable PLCs at scale. The July campaign targeted over 100 systems in a single month. That’s not a targeted operation against a specific utility, it’s a systematic sweep.


Why the Architecture of Your Notification System Matters

Operators need information from the SCADA system, not access to the SCADA system. A well-architected notification solution moves the information operators need outward without requiring operators or mobile devices to have direct access to the control network. This is meaningfully different from approaches that grant broad remote access and then try to secure it after the fact. I’m an outspoken critic of exposing HMI to the internet.

WIN-911’s architecture is designed around this principle. The WIN-911 source module process runs alongside the SCADA system on the control network, while notifier modules and their communication channels are isolated from the interfaces that face the control system. This matters more than ever in the current threat environment where attackers are specifically targeting and modifying PLC behavior. If an attacker suppresses alarms at the PLC or SCADA level, hiding alarm activity, WIN-911 can still surface anomalies to operators through independent notification channels.

What SmartSights Mobile Adds to This Picture

The July attacks disproportionately affected rural communities. These are exactly the kinds of operations where a single operator or a small team may be responsible for multiple remote sites across a relatively wide geography. In that context, the ability to receive, acknowledge, and investigate alarms from a mobile device isn’t just a convenience. It’s operational infrastructure.

SmartSights Mobile extends WIN-911’s notification capabilities to a mobile interface designed to keep mobile access outside the control network. Alarm visibility, acknowledgment, reporting, and team communication are built into a single app. The connection between the app and WIN-911 runs through the SmartSights Edge Gateway using outbound-only communication. This requires no inbound ports and no direct mobile access to the control network. For rural utilities managing remote pump stations or treatment sites, this means operators can stay informed and responsive without the security tradeoffs of broad remote access tools

What Water Utilities Should Be Doing Now

The CISA advisory recommends specific actions: inventory and patch internet-exposed devices, implement network segmentation, enforce multifactor authentication, and review remote access configurations. These are the right starting points. I’d add a few that are specific to the notification layer:

  • Audit your alarm notification architecture. If your operators’ primary channel for receiving alarm information runs through or depends on the same network path that an attacker would target, that’s a single point of failure worth addressing.
  • Ensure your notification system can detect process anomalies that your PLC or SCADA may not report if compromised. This means comparing expected process behavior against what’s being reported. Historical process data can provide a good way to identify discrepancies between what the control system says is happening and what the process is actually doing. Tools such as XLReporter can help maintain an independent record of process values and events for investigation and comparison.
  • Test your notification system regularly. When an attack occurs is not the time to discover that an SMS modem has gone offline, a cloud SMS credential has expired, or a new operator hasn’t been added to the contact list.
  • For utilities that haven’t yet connected alarm notification to a secure mobile platform, the current threat environment makes that a priority, not a future project.

The water sector has been told for years that it’s a target; July confirmed it with specifics. The question now isn’t simply whether your utility could be targeted. It’s whether your team will know when something is wrong.

Talk to an Expert

Explore WIN-911 

FAQs

1. How does SmartSights Mobile deliver field access to alarms without exposing my control network?

SmartSights Mobile connects to WIN-911 through the SmartSights Edge Gateway, which acts as a secure intermediary between your control network and the internet. All communication is outbound-initiated. Mobile devices never have direct access to your SCADA system or control network, and no inbound firewall ports are required. Operators get full alarm visibility, acknowledgment capability, and team communication from their phone without the security tradeoffs of VPN access or remote desktop tools.

2. What’s the difference between WIN-911 and a remote access tool like TeamViewer for alarm monitoring?

They solve fundamentally different problems. TeamViewer and similar tools grant access to the SCADA workstation itself. A remote user can see and interact with everything on that machine, which is powerful but creates a broad attack surface. WIN-911 takes a different approach. It doesn’t give operators remote access to the SCADA system. Instead, it pushes alarm data outward from the control network through dedicated notification channels: SMS, voice, email, and SmartSights Mobile. Operators get the information they need without the control network ever being exposed to a remote session. That’s a meaningful architectural distinction, and it’s the right one for critical infrastructure.

3. Can WIN-911 integrate with my existing SCADA system without opening it to the internet?

Yes. WIN-911 source modules run on the same control network as your SCADA system. There’s no requirement to expose the SCADA system to the internet. Outbound notification (SMS, voice, email, Mobile) is provided by separate notification modules that operate completely independently of the SCADA interface. These modules can be network distributed (e.g. to the DMZ). For facilities using SmartSights Mobile or cloud SMS, the SmartSights Edge Gateway handles internet communication as a separate process, keeping the control network boundary intact. WIN-911 supports a wide range of SCADA platforms and historians out of the box; if you’re unsure about compatibility with your specific system, [our team can help](https://smartsights.com/contact-us/).

4. How do I verify that alarm notifications are still reaching my team after a cyber incident?

Start by testing each notification channel independently. Send a test alarm and confirm delivery through SMS, voice, email, and SmartSights Mobile separately. Check that contact lists are current and that all active operators are enrolled. For cloud SMS, verify that API credentials for Twilio or Flowroute are valid and that the Edge Gateway is communicating normally. For hardware SMS, confirm the modem is online and the SIM is active.

Beyond point-in-time testing, XLReporter can support ongoing verification by maintaining an independent record of process data and alarm activity. If WIN-911’s logs and XLReporter’s records diverge after an incident, that discrepancy itself is a signal worth investigating. Regular scheduled tests, not just post-incident checks, are the best way to catch failures before they matter.

5. If an attacker disables alarms at the PLC or SCADA level, can WIN-911 still notify my operators?

This depends on where in the alarm chain the suppression occurs. WIN-911 reads alarm conditions from the SCADA or OPC server data source it’s connected to. If an attacker modifies PLC behavior in a way that prevents the alarm condition from being reported upstream, WIN-911 won’t see an alarm that was never raised.

What WIN-911 can do is provide a notification path that’s independent of the SCADA HMI interface. So if alarms are raised but then suppressed within the HMI layer, WIN-911’s independent process still delivers them. It also means that compromising the notification channel requires a separate effort from compromising the control system. The strongest defense combines WIN-911’s independent notification architecture with XLReporter’s independent process data logging, which can surface anomalies even when alarm systems have been tampered with.

6. We’re a small rural utility with limited IT resources. Is WIN-911 2025 realistic for our team to manage?

Yes. It’s designed with you in mind. WIN-911 is widely deployed across small and mid-sized water and wastewater utilities. The software runs on a standard Windows machine alongside your existing SCADA system, and most configurations don’t require dedicated IT staff to maintain day-to-day. SmartSights Mobile is a straightforward app install for operators, and cloud SMS eliminates the hardware modem management that has historically added complexity.

Where small utilities sometimes need support is during initial setup and when making configuration changes. Your WIN-911 subscription includes access to current software, documentation, and support from a team that understands the water/wastewater environment. If you’re not sure where to start, [talk to one of our experts](https://smartsights.com/contact-us/). We work with utilities of all sizes and can help you find a configuration that fits your team and your budget.

7. What role does network segmentation play in protecting alarm notification systems and where does WIN-911 fit?

Network segmentation is one of the most effective controls available to water utilities. It limits an attacker’s ability to move laterally from a compromised device to the rest of the control network. The principle is to separate your OT network (PLCs, SCADA, historians) from your IT network (business systems, email, internet access) with a clearly defined boundary, typically enforced by a firewall or DMZ.

WIN-911 fits naturally into a segmented architecture. WIN-911 Source modules are designed to run on the OT network alongside the SCADA system, accessing alarm data through local connections. Outbound notification channels are handled by separate processes that can be routed through the DMZ or a dedicated communication segment, keeping the OT network boundary intact. The SmartSights Edge Gateway, when used for SmartSights Mobile or cloud SMS, bridges the OT environment and the internet without creating a direct path between them. CISA’s advisory recommends segmentation as a primary control; WIN-911’s architecture is designed to operate within it.