Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Polish water utilities told to remove OT from the public internet: boards also have work to do

A new government recommendation calls for segmentation, MFA, configuration backups and monitoring. We translate it into service resilience.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
1 October 2026
READING TIME
9 min read
TOPIC
Cloud, Infrastructure and DevSecOps
Polish water utilities told to remove OT from the public internet: boards also have work to do

Poland’s Government Plenipotentiary for Cybersecurity has issued a security recommendation for the water and wastewater sector. Its central direction is clear: operational-technology devices and administrative panels should not be directly reachable from the internet, OT should be separated from corporate IT, and remote access should use encrypted channels and multi-factor authentication.

This is not merely an automation administrator’s technical task. OT controls physical processes, so compromise can disrupt operations, interrupt service and put people at risk. The utility’s management needs to understand which processes depend on remote access, how long they can run manually and who makes decisions during an incident.

When a convenient remote panel becomes a material risk

Industrial control systems were once more isolated. Today they connect with IT and are accessed by staff, administrators, integrators and maintenance providers. Remote connectivity reduces travel and repair time, but also creates a path from the internet toward a physical process.

The weakest design is a public administrative panel protected only by a password. A VPN is not enough either when every supplier shares one account, their devices are not checked and nobody reviews the logs. Security depends on the entire service session: person, device, time, purpose, permitted actions and a record of what changed.

The recommendation calls for separating OT from the corporate network and using DMZs. In practice, this creates controlled boundaries through which only necessary traffic can pass. A compromised office laptop should not provide a simple path to a controller, and an integrator’s account should not expose the entire plant.

What the government recommendation covers

Beyond isolation and protected remote access, the guidance lists changing default administrative credentials, individual user accounts, least privilege, logging administrative activity and monitoring OT security events. It also covers vulnerability and update management, backups of data and configuration, risk assessment, security testing and incident response.

Organisations should monitor advisories from the appropriate national CSIRTs and maintain communication routes that work during an incident. A contact list stored only inside the system affected by an attack is not sufficient. Phone numbers, responsibilities and a secure alternative communications method need an offline option.

Every control should produce evidence. “We have segmentation” should be supported by an up-to-date diagram and traffic rules. “We take backups” should be supported by a successful recovery of a controller or operator-station configuration. “Suppliers use MFA” should be supported by an account inventory and session review.

Improve security without disrupting the service

Office IT procedures cannot be copied blindly into OT. An update may affect controller behaviour, a vulnerability scan may overload an older device and sudden disconnection may make the process harder to operate safely. Changes need an asset inventory, impact review, maintenance window and an agreed rollback plan.

Start with a map of processes, equipment, versions, connections, remote users, suppliers and external-service dependencies. Next, remove obvious exposure and replace default credentials. Then govern remote access and logs. That foundation makes it possible to plan updates and longer-term investment responsibly.

Contracts matter too. An integrator should be required to secure its accounts, report its own incidents quickly, use the approved remote-access route and provide current configuration documentation. When the relationship ends, revoke access and check for remaining service accounts.

Exercise a loss of trust, not only a dramatic attack

A useful scenario does not need to assume poisoned water. It can begin when an operator no longer trusts a workstation, telemetry becomes inconsistent and a contractor says urgent remote access is necessary. The team has to decide whether to disable remote connectivity, how to confirm a safe process state, how to move to local operation and whom to notify.

This connects technology with business continuity. It reveals whether the utility has current contacts, configuration backups, manual operating procedures and clear authority to stop a process. Management gets a realistic view of the cost of poor readiness.

Our guide to third-party risk management provides a wider framework for maintenance access, while the incident-response plan explains crisis roles. Utilities can test their operating assumptions through an incident-response tabletop exercise.

Source facts and Breachroad conclusions

The Ministry of Digital Affairs release distributed by PAP lists OT isolation, segmentation, DMZs, encrypted remote access, MFA, individual accounts, logging, monitoring, updates, backups and incident readiness. PAP states that it publishes the release unchanged and identifies the ministry as its source. The Ministry of Digital Affairs maintains the official recommendations page.

The implementation sequence, supplier requirements, control evidence and exercise scenario are Breachroad conclusions. Every OT change should be assessed for process safety and service continuity.

SHARE / COPY