Critical Infrastructure Attack: 5 SMB Lessons

by The Creator | Jul 27, 2026

Critical infrastructure attack on operational technology systems affecting manufacturing and professional services buildings

A critical infrastructure attack temporarily knocked a Minnesota city’s water system offline, forcing officials to switch to manual operations while technicians worked to restore digital controls. The incident wasn’t a Hollywood scenario. It was a Tuesday morning problem that required city workers to physically operate valves and pumps while residents wondered whether their tap water was safe.

For small business owners, this story matters because the same vulnerabilities exist in your facility right now. If you run a manufacturing plant, your production line uses programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) systems. If you manage a professional services office, your building management system controls HVAC, security badges, and fire suppression. These operational technology (OT) systems were often installed years ago, rarely updated, and almost never included in your cybersecurity planning.

The water system attack exposes a pattern we see across manufacturing and infrastructure: organizations treat OT as separate from information technology (IT), assume air gaps provide protection, and discover too late that attackers don’t respect those boundaries.

What makes operational technology vulnerable to a critical infrastructure attack?

Operational technology runs physical processes. It opens valves, starts motors, regulates temperature, and monitors pressure. Unlike the laptop you’re reading this on, OT systems were designed for reliability and uptime, not security. Many run operating systems from the 1990s or early 2000s. Patching them risks breaking production. Replacing them costs six or seven figures.

Three factors make OT particularly attractive to attackers. First, many supposedly air-gapped systems connect to corporate networks for remote monitoring or data collection. That SCADA system your maintenance team checks from the office? It’s a bridge. Second, OT vendors often require remote access for support, creating persistent entry points. Third, OT protocols like Modbus and DNP3 were designed without authentication or encryption because they assumed a trusted, isolated environment.

A Connecticut precision manufacturer learned this during a 2024 incident when ransomware spread from office computers to the production floor through a shared network segment used for inventory tracking. The attack didn’t just encrypt files. It altered machine parameters and corrupted quality control data. Recovery took nine days and cost $340,000 in lost production, emergency IT response, and customer penalty clauses.

How does a critical infrastructure attack affect small manufacturers differently than large enterprises?

Scale changes everything. A Fortune 500 manufacturer absorbs a three-day production halt. A 50-person machine shop does not. When your annual revenue is $8 million and your margin is 12%, a week of downtime erases a quarter’s profit. You don’t have redundant production lines. You can’t shift orders to another facility. Your customers have backup suppliers who would love your purchase orders.

Small manufacturers face another challenge: skilled labor. The person who understands your 15-year-old CNC controller probably isn’t a cybersecurity expert. Your IT provider (if you have one) focuses on email and file servers, not industrial protocols. When a critical infrastructure attack hits OT, you’re calling the equipment vendor, who sends a technician qualified to fix mechanical problems, not investigate malware.

The financial impact compounds quickly. Direct costs include lost production, emergency response, and potential equipment damage. Indirect costs include missed delivery commitments, customer attrition, and reputation damage. A New Haven area fabrication shop that experienced a five-day OT outage in 2023 lost two major customers who couldn’t risk supply chain disruption. The owner estimated total impact at $680,000 over 18 months.

What specific risks do professional services firms face from operational technology attacks?

If you run a law firm, accounting practice, or consulting business, you might think OT doesn’t apply to you. Wrong. Your building management system (BMS) is operational technology. Your physical access control is operational technology. Your HVAC, elevators, fire suppression, and backup generators all run on connected systems that were installed by the lowest bidder and configured by technicians who left default passwords in place.

A Hartford law firm discovered this when attackers compromised their BMS, disabled HVAC during a July heat wave, and locked conference room doors during client meetings. The attack originated through a vendor portal used by the building maintenance company. Recovery required three days, forced remote work (complicated by the fact that physical files were locked inside), and prompted two major clients to ask pointed questions about data security during their annual vendor audits.

Professional services firms also face reputational consequences that manufacturers sometimes avoid. Your clients trust you with sensitive financial records, legal strategies, medical information, or proprietary business data. When they read that your building systems were compromised, they wonder what else was accessed. The breach notification might say “no evidence of data exfiltration,” but client trust doesn’t recover that easily.

How should SMBs protect operational technology without breaking the budget?

Effective OT security starts with visibility. You can’t protect what you don’t know exists. Walk your facility with your IT provider and document every connected system: production equipment, building controls, security cameras, environmental sensors, badge readers, and UPS systems. Create a simple spreadsheet: device name, vendor, model, network connection type, and last update date.

Next, segment your network. OT should not share network infrastructure with office computers. Use separate VLANs at minimum, dedicated switches if possible. This doesn’t require a massive investment. A basic managed switch costs $300-800. Configuration takes a few hours. The goal is to ensure that ransomware encrypting your accounting files can’t reach your production line or building controls.

Third, eliminate or strictly control remote access. Many OT vendors insist on VPN access for support. Fine, but use a jump box, require multi-factor authentication (MFA), log every session, and disable the connection when not actively in use. Better yet, require vendors to schedule access windows instead of maintaining always-on connections.

Fourth, document manual procedures. When digital controls fail (and they will, whether from attack, age, or accident), your team needs to know how to operate systems manually. Create step-by-step guides with photos. Test them annually. Train multiple people. The municipal water system in Minnesota survived because operators knew how to switch to manual mode. Your manufacturing plant or office building should have the same capability.

Finally, include OT in your backup and recovery planning. This doesn’t mean backing up PLCs like you back up file servers (though configuration backups are valuable). It means documenting system configurations, maintaining vendor contact information, keeping installation media or firmware copies offline, and establishing relationships with specialized OT recovery firms before you need them. A manufacturing-focused IT provider understands these requirements in ways that a general break-fix shop does not.

What should you do immediately after discovering an operational technology incident?

Speed matters, but panic causes mistakes. If you suspect a critical infrastructure attack on your OT systems, follow this sequence. First, physically isolate affected systems by disconnecting network cables (not just disabling software connections, which malware can re-enable). Second, switch to manual operation using your documented procedures. Third, contact your IT provider and, if the incident involves production systems, your equipment vendors.

Fourth, preserve evidence. Don’t restart systems or delete files, even if they appear corrupted. Forensic analysis may be necessary for insurance claims, regulatory notifications, or law enforcement investigation. Fifth, activate your communication plan. Notify customers if deliveries will be affected, inform employees about operational changes, and prepare a brief statement for inquiries.

Sixth, engage specialized help quickly. OT incident response requires different skills than IT incident response. You need people who understand industrial protocols, can analyze PLC logic, and know how to verify that physical systems are operating safely even if digital controls are compromised. Expect this to cost $15,000-50,000 for a small-scale incident, more if you need forensic analysis or have regulatory obligations.

Finally, document everything: timeline, actions taken, systems affected, data potentially compromised, and costs incurred. This documentation supports insurance claims, customer explanations, and (if necessary) regulatory notifications. Cybersecurity and data breach risk management extends beyond office networks into every connected system your business relies on.

How much does operational technology security cost for a typical SMB?

Budget reality: basic OT protection for a small manufacturer or multi-tenant office building runs $8,000-25,000 in first-year costs, then $3,000-8,000 annually. This includes network segmentation hardware, initial assessment and configuration, vendor access controls, documentation, and quarterly reviews.

Break it down: managed switches and basic firewall upgrades cost $2,000-5,000. Professional assessment and network segmentation (labor) runs $3,000-8,000. Vendor access controls and jump box setup add $1,500-3,000. Documentation and training cost $1,500-4,000. Ongoing monitoring and quarterly reviews run $250-650 monthly.

Compare this to recovery costs. The average small manufacturer experiencing OT downtime loses $5,600 per minute of halted production, according to industry data. A three-day incident (the median for OT ransomware) costs roughly $2.4 million in lost production alone, before counting emergency response, customer penalties, or equipment damage. Professional services firms face different math but similar scale: a week-long building systems outage forcing remote work costs $40,000-120,000 in productivity loss, alternative workspace, and client service disruption.

Insurance helps but doesn’t eliminate the problem. Cyber policies increasingly cover OT incidents, but expect sub-limits, waiting periods, and detailed security requirement questionnaires. Premiums for policies covering OT run 20-40% higher than IT-only coverage. Deductibles typically start at $25,000-50,000 for SMBs.

Do regulatory requirements cover operational technology for SMBs?

Yes, and the requirements are expanding. Manufacturing firms pursuing defense contracts face Cybersecurity Maturity Model Certification (CMMC), which explicitly covers OT systems starting at Level 2. Financial services firms under the Federal Trade Commission (FTC) Safeguards Rule must secure all systems that access customer information, including building access controls tied to employee databases. Healthcare providers subject to the Health Insurance Portability and Accountability Act (HIPAA) must protect building management systems that control temperature and humidity in areas where medical records are stored.

State-level regulations are emerging too. Critical infrastructure designation now extends to smaller facilities in some states. Connecticut has discussed expanding cybersecurity requirements beyond utilities to include manufacturing facilities above certain employee or revenue thresholds. The trend points toward more regulation, not less, as attacks on infrastructure increase.

Even without specific mandates, customer requirements drive change. Large manufacturers increasingly require OT security attestations from suppliers. Professional services firms face similar pressure during client audits and vendor risk assessments. Proving compliance is easier (and cheaper) than explaining why you’re exempt. A clear compliance and regulatory exposure strategy treats OT and IT as integrated components of business risk.

Frequently Asked Questions

Can ransomware actually damage physical equipment or just lock digital controls?

Both. Ransomware typically encrypts control software and data, preventing operation without destroying hardware. However, some attacks deliberately alter operational parameters (temperatures, pressures, speeds) to cause physical damage that extends downtime and increases recovery costs. A 2021 incident at a water treatment facility saw attackers attempt to increase chemical levels to dangerous concentrations before operators intervened.

Should SMBs maintain completely air-gapped operational technology networks?

True air gaps (zero network connectivity) provide strong security but eliminate remote monitoring, data collection, and vendor support capabilities that many SMBs rely on. A better approach for most organizations: network segmentation with strict access controls, allowing limited connectivity for specific business purposes while blocking lateral movement from office networks. Complete air gaps work best for highly sensitive processes where manual operation is practical.

How often should operational technology systems be updated or patched?

OT patching follows different rules than IT. Stability and uptime take priority over immediate patching. Best practice: test patches in non-production environments first, schedule updates during planned maintenance windows (not emergency deployments), and maintain the ability to roll back if problems occur. Many SMBs adopt a quarterly patching cycle for OT after thorough testing, versus monthly or continuous patching for office IT systems.

What insurance coverage do small businesses need for operational technology incidents?

Standard cyber liability policies often exclude or limit OT coverage. Look for policies that explicitly cover operational technology, physical damage from cyber events, and business interruption from OT system failures. Expect insurers to require network segmentation, access controls, and documented recovery procedures. Premiums vary widely ($3,000-15,000 annually for typical SMBs) based on industry, revenue, and existing security controls. Work with an agent experienced in manufacturing or infrastructure risks.

Can building management systems in small office buildings really be entry points for attackers?

Absolutely. BMS platforms often run outdated software, use default credentials, and connect to the internet for remote management by building owners or maintenance companies. Attackers exploit these systems both as initial entry points and for persistence (they’re rarely monitored or included in security scans). A compromised BMS provides network access, information about occupancy and schedules, and in some cases, access to connected systems like security cameras or access control databases that reveal sensitive business information.

Keep reading

Sources

Source: Officials in Minnesota city say cyberattack knocked water system offline – MPR News