Back to Home  
Blog & Insights

September 14, 2026

The Challenge Water Utilities Face Is They Cannot Patch Architecture

Closed control creates two problems at once: you cannot put optimization on the field, and you inherit security risk that never gets a patch.

The Challenge Water Utilities Face Is They Cannot Patch Architecture

A 10.0 CVE. The vendor said a patch cannot fix it. That is not a missed firmware drop. That is the architecture.

CVE-2021-22681. Rockwell Logix programmable logic controllers (PLCs). CISA published the advisory in February 2021. The CVSS v3 score is 10.0. Rockwell determined the vulnerability cannot be mitigated with a patch.

In March 2026, CISA added the same CVE to the Known Exploited Vulnerabilities catalog. The hole was five years old. It was still open. Then it was confirmed in use.

Two costs, one lock

Closed control is sold as a complete system. Engineering software. Controller family. I/O. Network. Support contract. The plant gets one throat to choke. It also gets one throat that owns the key.

That lock shows up twice.

First, optimization. Energy and water projects need to write setpoints at the field. They also need ground truth they can trust. A closed PLC family does not give you a field you can plug into. The application stays inside the vendor stack. The optimizer stays outside it. You pay for both and connect them with custom glue.

Second, security. The same closure that blocks that plug also blocks a patch. If the verification key lives in the design, a firmware file cannot take it out. Compensating controls can reduce exposure. They do not change the key.

You cannot patch architecture.

What CISA actually said

CISA advisory ICSA-21-056-03 covers Studio 5000 Logix Designer, RSLogix 5000, and a long list of Logix controllers. CompactLogix. ControlLogix. GuardLogix. DriveLogix. SoftLogix.

The defect is insufficiently protected credentials. Studio 5000 uses a key to verify that it is talking to a Logix controller. An unauthenticated attacker can bypass that check and connect as if they were the engineering workstation. They can change configuration. They can change application code.

CISA scored it 10.0. Remote. Low skill. No user action. Confidentiality, integrity, and availability all high.

Rockwell's line is the one that matters for architecture: this vulnerability cannot be mitigated with a patch.

CISA lists compensating controls. Take the PLC off the public internet. Put the control network behind a firewall. Restrict CIP traffic on TCP 44818. Use a VPN for remote access. Put the mode switch in Run. On supported products, deploy CIP Security, which does not use hardcoded keys.

Those are real controls. They are also an admission. The original key stays. The plant must work around a design it cannot change.

SoftLogix 5800 has no extra mitigation in the advisory. Follow the network guide. That is the whole list.

SecurityWeek reported on 6 March 2026 that CISA added CVE-2021-22681 to KEV. Federal agencies had until 26 March 2026 to address it. Rockwell updated its advisory to mention in-the-wild exploitation. The company did not publish details of the attacks.

A five-year-old design defect does not become less of a design defect because the catalog finally caught up.

Minnesota is the illustration, not the proof

In late July 2026, reporting described cyber incidents against Minnesota water systems. Tenable assessed the pattern as this class of unpatchable PLC risk.

Public authorities have not confirmed the CVE. They have not confirmed the equipment. They have not confirmed the actor. Do not treat a secondary write-up as a forensic finding.

The class still holds. Water and wastewater plants run the same controller families as the rest of critical manufacturing. If the verification key cannot be patched, every internet-facing or poorly zoned Logix cabinet carries that key. A new control layer does not un-ship those cabinets. You cannot retrofit a closed family after the fact.

This article does not claim that an open stack would have stopped Minnesota. That claim is false on its face. The controllers are already in the plant.

The field you cannot write to

Security is the loud half of the story. It is not the only half.

Plants want to cut energy and water. They buy historians, dashboards, and models to do it. Those tools need a field they can read and a field they can write. Closed control keeps the loop inside one vendor's runtime. The model sits one layer up and hopes the tags are honest.

That is the same lock. You cannot drop in a different controller and keep the application. You cannot put an optimizer on a loop you do not own. You cannot rotate a key the vendor refuses to change.

Separation is the foundation of OT security covers the related failure: implicit trust on the wire, tank gauges in June, S7 controllers in August. This page is the next sentence. Even when the device is not on the public internet, a key you cannot patch is still in the cabinet.

What a standard changes

Open Process Automation (O-PAS) does not patch CVE-2021-22681. No standard can. The installed Logix base keeps that defect until the cabinet is replaced.

What a standard changes is the next cabinet.

O-PAS defines control as separable, interoperable functions. Compute can change without a rewrite of the whole stack. I/O can come from more than one supplier. Security controls can sit on published interfaces instead of a private verification key. When a component is retired, you replace the component. You do not replace the plant.

Reliability was the last argument for staying proprietary is the availability half of that case. This page is the security and optimization half. Same lock. Two costs.

Ask the architecture question before you ask the patch question:

  • Can I replace the controller without rewriting the application?
  • Can a second supplier deliver this function?
  • Does remote access stop before the PLC, or on it?
  • If the vendor cannot patch a 10.0, what is my path off that family?

If the answers are no, no, on it, and none, you do not have a patch problem. You have an architecture problem.

The challenge water utilities face is they cannot patch architecture. Cybersecurity must be part of the architecture.

{"@context":"https://schema.org","@graph":[{"@type":"Article","@id":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face#article","headline":"The Challenge Water Utilities Face Is They Cannot Patch Architecture","description":"The challenge water utilities face is they cannot patch architecture. Closed control creates two problems at once: you cannot put optimization on the field, and you inherit security risk that never gets a patch.","datePublished":"2026-09-14","image":"https://cdn.prod.website-files.com/6a457bcd33376d2561fe71d5/6aa859cb0c2991b8b6ea9509_6aa8597d8c94f1e32e2f2695_cybersecurity-must-be-part-of-the-architecture.png","author":{"@type":"Organization","name":"CPLANE","url":"https://www.cplaneai.com"},"publisher":{"@id":"https://www.cplaneai.com/#organization"},"url":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face","mainEntityOfPage":{"@id":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face#webpage"},"inLanguage":"en-US"},{"@type":"WebPage","@id":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face#webpage","url":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face","name":"The Challenge Water Utilities Face Is They Cannot Patch Architecture | CPLANE","description":"The challenge water utilities face is they cannot patch architecture. Closed control creates two problems at once: you cannot put optimization on the field, and you inherit security risk that never gets a patch.","isPartOf":{"@id":"https://www.cplaneai.com/#website"},"about":{"@id":"https://www.cplaneai.com/#organization"},"inLanguage":"en-US"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.cplaneai.com/"},{"@type":"ListItem","position":2,"name":"Resources","item":"https://www.cplaneai.com/resources"},{"@type":"ListItem","position":3,"name":"The Challenge Water Utilities Face Is They Cannot Patch Architecture","item":"https://www.cplaneai.com/resources/the-challenge-water-utilities-face"}]}]}