8
minute read

Recent headlines and FBI advisories have uncovered a stark reality: municipal water systems are targets for cyberattacks. Bad actors and sophisticated threat groups have breached public utility systems across seven states and more than 30 facilities in Minnesota alone. The risk to physical infrastructure, public health, and operational continuity has never been higher.
To address this expanding threat, utility leaders must shift from reactive crisis management to proactive risk mitigation. While it’s nearly impossible to make your utility immune to cyber threats, there are some basic actions every utility can take to appreciably improve its cyber security. The primary objective for most water utilities today should be to eliminate basic vulnerabilities so they are less likely to be easy targets. By performing basic hygiene and aligning with industry-standard cybersecurity frameworks, utilities can withstand initial attacks and establish a scalable foundation for long-term cyber resilience.
Water and wastewater utilities face expanding compliance mandates that make cybersecurity an urgent legal and operational priority, led by America’s Water Infrastructure Act (AWIA) Section 2013, which requires systems serving over 3,300 people to evaluate electronic and SCADA resilience in their mandatory 5-year Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs). Utilities are also governed by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), mandating substantial cyber incidents be reported to CISA within 72 hours and ransom payments within 24 hours, alongside heightened EPA enforcement scrutiny that treats basic vulnerabilities like default credentials and lack of MFA as serious compliance violations. Integrating these statutory requirements with emerging state-level mandates and State Revolving Fund (SRF) financing conditions elevates baseline cyber hygiene from a discretionary IT expense into an essential fiduciary requirement.
Water and wastewater systems rely heavily on interconnected Information Technology (IT) and Operational Technology (OT) environments. While digital integration has optimized operations, SCADA monitoring, and billing efficiency, it has also increased utilities’ vulnerabilities to attacks.
Nation-state adversaries and hacktivists routinely scan for unpatched remote-access portals, default passwords, and exposed industrial control devices. Utilities that lack basic security controls are therefore easy targets. Implementing basic cyber hygiene raises the cost of attack, forcing adversaries to move on to less prepared targets.
[[CTA:subscribe]]
Raftelis’ cybersecurity advisory team works exclusively at the intersection of local government, public sector utilities, and digital transformation. We help water and wastewater providers answer the fundamental strategic question: "Are we doing enough of the right things to protect our operations and community?"
Water and wastewater utilities have unique operational realities that require a comprehensive and specific approach to cybersecurity. The following are best practices to that answer that question:
1. Framework-driven cybersecurity assessments
2. Foundational cyber hygiene and baseline hardening
3. Strategic cybersecurity roadmaps
4. Governance and executive oversight
To evaluate whether your organization is operating with baseline cyber hygiene, ask these five core questions of your operations and technology leaders:
While these questions help you establish a baseline, engaging in a full cybersecurity assessment is the single most effective step a utility can take to understand its exposure profile and prioritize immediate remediation.
The financial disparity between reactive recovery and proactive defense is stark. According to IBM's Cost of a Data Breach Report, the average cost of a critical infrastructure cyber incident exceeds $4.8 million when factoring in system downtime, forensic remediation, legal liability, and emergency public communications.
In contrast, implementing basic cyber hygiene measures, such as deploying multi-factor authentication, segmenting networks, and conducting baseline vulnerability scans, costs a fraction of that. For most utilities, eliminating the obvious vulnerabilities offers the best opportunity for reducing risks.
Building a resilient water utility does not require overnight perfection—it requires proactive momentum. By buttoning up baseline cybersecurity controls today, utilities can protect their essential water infrastructure and ensure long-term operational continuity for the communities they serve.
Raftelis can help you conduct a cybersecurity assessment or build a customized protection roadmap for your utility. Visit Raftelis Cybersecurity Services or reach out to Andrew Fedson.
Link copied