News

Water-System Hacking Warning Puts OT Security Jobs in Focus

Water-System Hacking Warning Puts OT Security Jobs in Focus

Five federal agencies warned Wednesday that hackers are using artificial intelligence to write exploit scripts aimed at Siemens S7 industrial controllers that run water, energy, manufacturing and agriculture systems across the country. The joint advisory, AA26-231A, comes from the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency, according to TechCrunch's report on the bulletin. Officials said hackers are targeting "all" Siemens S7 programmable logic controllers, or PLCs, using AI to generate exploit scripts built from publicly available information.

The advisory covers the S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller families, BleepingComputer reported. The AI-written Python tools use the "snap7" library to talk to PLCs over the S7comm protocol while disguised as legitimate monitoring software, giving attackers read and write access to controller memory and programming logic and cutting the technical skill and time it takes to build a working exploit.

It's the latest in a string of federal warnings about the water sector this year. In July, the FBI and EPA warned that hackers were targeting internet-connected PLCs at water and wastewater plants, with incidents reported to the FBI across at least seven states, Gizmodo reported. One incident hit roughly 30 municipal water and wastewater systems in Minnesota over two nights in late July, according to Cybersecurity Dive, which reported that an industry coalition is now pushing Congress to renew state and local cybersecurity grant funding for the roughly 148,000 public water systems nationwide.

What this means for job seekers considering cybersecurity or critical-infrastructure careers

Advisories like this one are effectively a hiring signal. Operational technology, or OT, security, which means protecting physical controllers rather than just IT networks, is a distinct specialty, and employers aren't primarily looking for general cybersecurity generalists to fill these roles. Most ICS security analysts come from IT or engineering backgrounds, commonly networking, industrial controls or systems administration, rather than starting a security career from scratch, according to SANS Institute's career guidance.

The credentials that move a resume forward in this niche are narrower than general security certifications: GIAC's GICSP, GCIP and GRID credentials, familiarity with industrial protocols such as Modbus and DNP3, and working knowledge of standards like NERC CIP and IEC 62443, per SANS. Entry- to mid-level ICS security analysts earn $85,000 to $115,000 a year, with experienced critical-infrastructure specialists exceeding $130,000, the same guidance shows. That demand is emerging against a broader cybersecurity hiring crunch: a Fortinet survey of more than 2,750 IT and security decision-makers found 49 percent can't get budget approval to add cybersecurity staff, even as 60 percent call finding candidates with AI skills their toughest recruiting problem, Fortinet's 2026 report found. For job seekers still mapping out which security specialty to pursue, our guide to narrowing a career focus is a useful starting point before targeting a niche as specific as OT security.

Sources

Posted in
News

Related Posts

Job Opportunities

Browse all opportunities →