The physical priority is preventing overpressure, tank overflow, loss of disinfection, or loss of fire-flow—not immediately restoring the screen. Fact: the FBI and Rockwell report targeting of internet-facing MicroLogix controllers; WaterISAC says actors changed IP settings, enabled unknown passwords, and caused loss of operator visibility. Unknown: the reported pressure loss and flooding do not, by themselves, prove that malicious PLC commands caused the process upset. This is a direct Purdue Level 1 control-trust incident, with Level 2 HMI visibility potentially unreliable.
Immediately place the site under its approved abnormal-operations procedure. Verify pressure, level, flow, pump state, valve position, and alarms through independent instruments and operator rounds. Move to local or manual control only where procedures, staffing, and communications support it. Block public-internet paths and port forwarding to the controllers at the firewall, and suspend vendor access at the Level 3/3.5 boundary—but do not abruptly disconnect controller networks, power-cycle PLCs, or download logic while pumps are operating. Any segmentation change must be safety-tested first; breaking PLC-to-I/O or supervisory communications can create a worse event.
Preserve firewall/NAT, VPN, HMI alarm, historian, engineering-workstation, and controller diagnostic records where available. Record device displays and switch-port states, and safely upload the running program/configuration before altering it. Compare timestamps across PLC IP/password changes, online edits, setpoint or timer changes, remote sessions, pump run feedback, motor current, valve feedback, and independent pressure/level measurements. That synchronized chain distinguishes malicious control from sensor failure, pump trip, communications loss, or ordinary maintenance error far better than an alarm screenshot.
Recover in this order: stabilize the process; close internet and remote-access paths; preserve evidence; validate or rebuild the engineering workstation from trusted media; rotate controller, engineering, VPN, vendor, and firewall credentials from a clean administrative system; then recover PLCs one at a time using Rockwell’s model-specific SD1790 procedure and a verified known-good project. WaterISAC notes that MicroLogix 1100 recovery includes placing the controller in Program mode, so treat that as loss of automatic control and schedule it only with safe manual or redundant control available. Validate I/O, scaling, interlocks, alarms, pump sequencing, and fail-safe behavior before controlled recommissioning. Remote access should return only through a monitored OT jump path—not directly to Level 1. Firm position: for an affected utility, this outranks unrelated enterprise RCEs until hydraulic stability and controller trust are restored; an enterprise RCE becomes co-equal only if it provides a path into OT or compromises systems needed for safe operations.