Navigating the rising wave of cyberattacks through cyber hygiene and resilience

8

minute read

Andrew Fedson

Andrew Fedson

Manager

afedson@raftelis.com

Recent headlines and FBI advisories have uncovered a stark reality: municipal water systems are targets for cyberattacks. Bad actors and sophisticated threat groups have breached public utility systems across seven states and more than 30 facilities in Minnesota alone. The risk to physical infrastructure, public health, and operational continuity has never been higher.

At a glance

  • Municipal water systems are increasingly targetd by cyber attacks, making baseline security a critical requirement to protect physical infrastructure and ensure operational continuity.
  • Expanding regulations like AWIA and CIRCIA mean addressing basic network vulnerabilities is no longer a discretionary IT expense but a priority for utility leadership.
  • Utilities can deter most adversaries and prevent costly breaches by implementing practical measures like multi-factor authentication, network segmentation, and baseline patch management.

To address this expanding threat, utility leaders must shift from reactive crisis management to proactive risk mitigation. While it’s nearly impossible to make your utility immune to cyber threats, there are some basic actions every utility can take to appreciably improve its cyber security. The primary objective for most water utilities today should be to eliminate basic vulnerabilities so they are less likely to be easy targets. By performing basic hygiene and aligning with industry-standard cybersecurity frameworks, utilities can withstand initial attacks and establish a scalable foundation for long-term cyber resilience.

Water and wastewater utilities face expanding compliance mandates that make cybersecurity an urgent legal and operational priority, led by America’s Water Infrastructure Act (AWIA) Section 2013, which requires systems serving over 3,300 people to evaluate electronic and SCADA resilience in their mandatory 5-year Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs). Utilities are also governed by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), mandating substantial cyber incidents be reported to CISA within 72 hours and ransom payments within 24 hours, alongside heightened EPA enforcement scrutiny that treats basic vulnerabilities like default credentials and lack of MFA as serious compliance violations. Integrating these statutory requirements with emerging state-level mandates and State Revolving Fund (SRF) financing conditions elevates baseline cyber hygiene from a discretionary IT expense into an essential fiduciary requirement.

The reality of modern cyber threats to water systems

Water and wastewater systems rely heavily on interconnected Information Technology (IT) and Operational Technology (OT) environments. While digital integration has optimized operations, SCADA monitoring, and billing efficiency, it has also increased utilities’ vulnerabilities to attacks.

Nation-state adversaries and hacktivists routinely scan for unpatched remote-access portals, default passwords, and exposed industrial control devices. Utilities that lack basic security controls are therefore easy targets. Implementing basic cyber hygiene raises the cost of attack, forcing adversaries to move on to less prepared targets.

[[CTA:subscribe]]

How Raftelis helps utilities button up defenses

Raftelis’ cybersecurity advisory team works exclusively at the intersection of local government, public sector utilities, and digital transformation. We help water and wastewater providers answer the fundamental strategic question: "Are we doing enough of the right things to protect our operations and community?"

Water and wastewater utilities have unique operational realities that require a comprehensive and specific approach to cybersecurity. The following are best practices to that answer that question:

1. Framework-driven cybersecurity assessments

  • NIST Cybersecurity Framework alignment: Make sure you benchmark your organization against the National Institute of Standards and Technology (NIST) Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
  • Bridging IT and OT/ICS security: Water utilities require security solutions that understand the difference between enterprise IT and Industrial Control Systems (ICS)/SCADA environments. Evaluate both domains to ensure operational safety is preserved without interrupting service delivery.

2. Foundational cyber hygiene and baseline hardening

  • Vulnerability and exposure identification: Identify wide-open access vectors, default configurations, unsegmented network zones, and gaps in credential management.
  • Practical control implementation: Deploy critical controls—such as multi-factor authentication (MFA), network segmentation between enterprise and SCADA networks, and baseline patch management routines.

3. Strategic cybersecurity roadmaps

  • Tailored strategic planning: While its tempting to copy what your neighboring utility is doing, cybersecurity cannot take a one-size-fits-all approach. Make sure your cybersecurity plan aligns with your utility’s unique capital and operational budgets and any resource constraints you have.
  • Resource optimization: Prioritize your security investments to ensure every dollar spent directly reduces risks to tasks that are core to your missions, by prioritizing high-risk critical assets (SCADA/OT), targeting low-cost hygiene fixes, and utilizing free federal tools and grant funding.

4. Governance and executive oversight

  • Board and executive engagement: Cyber risk is an enterprise risk, not just an IT issue, but the issues and the appropriate actions to take can get very technical, very fast. Make sure you translate the language of your vulnerabilities into easy-to-understand business and operational decisions so board members, city councils, and executive leadership can make those decisions with clear understanding of what’s at stake.
  • Policy and incident response preparedness: Create clear policies, governance structures, and incident response protocols so your organization can respond decisively in the event of a breach.

Next steps for utility leadership

To evaluate whether your organization is operating with baseline cyber hygiene, ask these five core questions of your operations and technology leaders:  

  1. Do we have multi-factor authentication (MFA)  across all remote administrative access points, including third-party vendor portals?  
  2. Are enterprise IT networks strictly separated from SCADA and operational technology (OT) systems using firewalls and access controls?  
  3. Have default passwords and admin credentials been removed from all exposed industrial control devices?  
  4. Do we maintain an updated inventory of all internet-facing devices connected to our water treatment and distribution networks?  
  5. When was our incident response plan last tested with a tabletop exercise involving both operational staff and executive leadership?  

While these questions help you establish a baseline, engaging in a full cybersecurity assessment is the single most effective step a utility can take to understand its exposure profile and prioritize immediate remediation.

The financial disparity between reactive recovery and proactive defense is stark. According to IBM's Cost of a Data Breach Report, the average cost of a critical infrastructure cyber incident exceeds $4.8 million when factoring in system downtime, forensic remediation, legal liability, and emergency public communications.

In contrast, implementing basic cyber hygiene measures, such as deploying multi-factor authentication, segmenting networks, and conducting baseline vulnerability scans, costs a fraction of that. For most utilities, eliminating the obvious vulnerabilities offers the best opportunity for reducing risks.

Building a resilient water utility does not require overnight perfection—it requires proactive momentum. By buttoning up baseline cybersecurity controls today, utilities can protect their essential water infrastructure and ensure long-term operational continuity for the communities they serve.

Raftelis can help you conduct a cybersecurity assessment or build a customized protection roadmap for your utility. Visit Raftelis Cybersecurity Services or reach out to Andrew Fedson.

Andrew Fedson

Andrew Fedson

Manager

afedson@raftelis.com