We Tried to Solve This in 2022
On July 27, 2026, hackers began systematically attacking water facilities across the United States. By the time the FBI and EPA issued a joint advisory three days later, more than 30 water systems in Minnesota alone had been compromised. Attackers remotely accessed internet-facing Programmable Logic Controllers, changed passwords and IP addresses, and caused facilities to lose monitoring and control capabilities. Flooding. Pressure loss. Boil-water notices. Most security vendors commenting on this story are drawing analogies. We are not drawing analogies. We know exactly why this happened — because we spent years trying to solve it.
The Origin Story
In January 2022, we founded Trustcore Technologies in Gatineau, Quebec with a specific mission:
use machine learning to monitor PLC and SCADA systems at the edge, detect cyber intrusions in real time, and protect industrial infrastructure before attacks cause physical consequences.
Water treatment plants were explicitly in scope. So were manufacturing facilities, utilities, and the broader IIoT environment. We understood the threat. We understood the attack surface. And we built Trustcore BA — a behavioral analytics platform that monitored operational technology at the chip layer, learned what normal looked like, and detected deviations in real time. Then we ran into the wall that every OT security company eventually hits. Then we ran into the wall that every OT security company eventually hits.
Getting to PLC telemetry without massive, custom, site-by-site integration overhead is
extraordinarily hard. Not impossible — but hard enough to make scalable commercialization impractical for an early-stage company.
The problem is structural. PLCs were designed for reliability and determinism, not connectivity. Many
run proprietary protocols. Many are air-gapped by design or by legacy. Getting telemetry out of a
Rockwell Allen-Bradley MicroLogix — the exact PLC model targeted in last week's attacks — requires
either deep vendor-specific integration, physical access, or both. At scale, across dozens of facilities, the
integration cost made the business model unworkable.
The facilities that were attacked last week took the shortcut most facilities take: they put those PLCs on
the internet to make them accessible for remote management. That shortcut eliminated the integration
problem — and created the vulnerability the attackers exploited.
What We Did With What We Learned
We didn't abandon the problem. We pivoted to where we could apply the same behavioral analytics approach without the integration friction.
The insight was this: the identity control plane of a financial institution has the same detection gap as an OT environment — legitimate access pathways being used by actors who shouldn't have them, with no continuous behavioral monitoring to catch the deviation. The attack surface is different. The underlying failure is identical.
In a bank, the equivalent of the PLC is the Active Directory credential. In a water facility, the attacker changes a PLC password and takes control of a valve. In a bank, the attacker drifts a credential's behavior and takes control of a transaction pathway. The mechanism is the same. The detection approach is the same. The integration path — LDAP logs, directory telemetry, OS-level behavioral data — is dramatically cleaner.
Trustcore BA evolved into Identera. The behavioral baseline modeling we built for OT anomaly detection became the foundation for identity threat detection in financial services. And it works — because the core technical problem is the same.
Three Attacks, One Pattern — This Week Alone
- July 22: OpenAI models autonomously breached Hugging Face using credential-based access.
No human attacker. Authorized-looking behavior that wasn't authorized.
• July 27–30: Coordinated PLC attacks across 7 states. Internet-facing industrial controllers
accessed as authorized operators — then reconfigured.
• Ongoing in financial services: Credential-based attacks remain the leading breach vector — slow,
careful misuse of valid identities that signature tools were never built to catch.
Three incidents. Three different attack surfaces. One detection gap: no continuous behavioral baseline to
recognize when something authorized-looking has stopped acting authorized.
What This Means — And What Comes Next
The water attacks validate something we learned the hard way in 2022: the OT security problem is not
primarily a signature problem or a firewall problem. It is a behavioral visibility problem. And the vendors
who have solved the OT integration challenge — Claroty, Dragos, Nozomi Networks — have the
telemetry layer that we couldn't build efficiently at scale. We have the behavioral modeling layer they don't. The combination is the complete solution the water
attacks proved is missing. We're exploring exactly that partnership now. The market just caught up to the thesis we built four years ago.
We didn't abandon the water security problem. We built the solution that makes it solvable. And we're bringing it back.
In financial services, Identera is already doing what the water facilities needed: continuously monitoring identity behavior, detecting drift before it becomes an incident, and surfacing what looks authorized but isn't. Security's Identity Layer — in financial services today, and in critical infrastructure tomorrow.
Identera provides ITDR for financial institutions built on longitudinal behavioral modeling of AD/LDAP telemetry.
Partnership inquiries for OT/ICS environments: [email protected] | www.identera.ai