Word on the street was that this same software was used by the big boys for power generation and distribution, ditto water, etc. And that the security on the installations was laughable--once you got into the network you could monkey at will. It might be hard to cause damage unless you knew the details of the system. But if you coordinated an arson attack with a water outage... Something as naive as "clicking the power off" button could cause temporary problems, but editing the reaction scripts would cause harder-to-find issues.
This was a few years after 9/11, and one would have expected a certain heightened awareness of vulnerabilities. Perhaps there was, and the details were kept quiet while people tried to fix them. Or perhaps there was, and the cans were quietly kicked down the road.
I gather from the news yesterday that some vulnerabilities still exist--not least to denial of service attacks on such service infrastructure.