Is Your Business More Connected—and More Vulnerable—Than You Think?
Aug 5, 2026 11:08 AM
Recent cyberattacks on water utilities offer an important warning for small businesses: internet-connected systems can create hidden vulnerabilities long before anything appears to be wrong. From security cameras and door access to thermostats and point-of-sale systems, business owners should know what equipment can be reached remotely—and confirm, in writing, who is responsible for keeping it secure. Local cybersecurity provider Lockbaud shares two practical steps every small business can take now to reduce its risk.
Hackers Hit Water Systems in 12 States. Federal Warnings Went Out in April.
Neither Missouri nor Kansas has turned up on the list of affected utilities. Both states run thousands of systems on the same internet-connected equipment that was targeted everywhere else.
KANSAS CITY, Mo., Aug. 5, 2026 — Cyberattacks on water and wastewater utilities have been reported in at least 12 states, including more than 30 systems across Minnesota in one weekend. Missouri has more than 2,700 public water systems. Kansas has more than 1,000.
The attackers never touched the water. They reached the small industrial computers that run pumps, wells, and valves, connected straight to the internet. They changed passwords to lock operators out and knocked equipment offline by changing addresses. Utilities that recovered went manual. No drinking water contamination has been reported. Federal investigators consider Iran the leading suspect, though attribution isn’t confirmed.
“Hackers put up smoke screens so nobody thinks anything is going wrong, while they change the systems that actually run the place,” said Sam Sapp, owner of Lockbaud. “The readout said normal. It wasn’t.”
The timing should bother any business owner. The Cybersecurity and Infrastructure Security Agency published an advisory on this weakness April 7 and updated it July 22. Minnesota was hit four days later. There is no vendor patch and none is coming. The only fix was taking the equipment off the internet.
That gap isn’t unique to water utilities. “About 75% of our members are five or less employees, with most leaning toward the less. Very few, if any, have actual IT positions on payroll,” said Stacie Bratcher, executive director of the Kearney MO Chamber of Commerce. “They deal with issues when they arise, often relying on those who provided the system to serve and protect the system.”
Two things any small business can check this week:
Neither Missouri nor Kansas has turned up on the list of affected utilities. Both states run thousands of systems on the same internet-connected equipment that was targeted everywhere else.
KANSAS CITY, Mo., Aug. 5, 2026 — Cyberattacks on water and wastewater utilities have been reported in at least 12 states, including more than 30 systems across Minnesota in one weekend. Missouri has more than 2,700 public water systems. Kansas has more than 1,000.
The attackers never touched the water. They reached the small industrial computers that run pumps, wells, and valves, connected straight to the internet. They changed passwords to lock operators out and knocked equipment offline by changing addresses. Utilities that recovered went manual. No drinking water contamination has been reported. Federal investigators consider Iran the leading suspect, though attribution isn’t confirmed.
“Hackers put up smoke screens so nobody thinks anything is going wrong, while they change the systems that actually run the place,” said Sam Sapp, owner of Lockbaud. “The readout said normal. It wasn’t.”
The timing should bother any business owner. The Cybersecurity and Infrastructure Security Agency published an advisory on this weakness April 7 and updated it July 22. Minnesota was hit four days later. There is no vendor patch and none is coming. The only fix was taking the equipment off the internet.
That gap isn’t unique to water utilities. “About 75% of our members are five or less employees, with most leaning toward the less. Very few, if any, have actual IT positions on payroll,” said Stacie Bratcher, executive director of the Kearney MO Chamber of Commerce. “They deal with issues when they arise, often relying on those who provided the system to serve and protect the system.”
Two things any small business can check this week:
- Find out what of yours is reachable from the internet: cameras, door access, thermostats, point-of-sale, anything a vendor set up remotely.
- Ask every vendor, in writing, who secures the system they sold you. Don’t assume it’s them.
“We need to make reviewing our own systems a routine instead of a reaction,” Sapp said. “And we need to review them differently, because the old checklist never asked what was online.”
Lockbaud is offering its Needs Assessment, at no charge through Sept. 30 to Missouri and Kansas water districts, municipalities, public safety agencies, school districts, and rural electric co-ops. One of its five areas is external attack surface. Requests go to connect@lockbaud.com or 816-208-2888.
About Lockbaud
Lockbaud is a managed IT and cybersecurity provider based in Kansas City, Missouri, serving small and mid-sized businesses across the United States. Lockbaud works most often with accounting firms, law firms, and chambers of commerce, and backs its work with same-day support, zero-downtime onboarding, and a money-back guarantee. Founded and owned by Sam Sapp. More at lockbaud.com.
Contact
Sam Sapp, Owner, Lockbaud
(816) 264-1337 · sam@lockbaud.com
lockbaud.com