Water Utilities Face Growing Cybersecurity Pressure as OT Risks Rise
The cybersecurity of water and wastewater infrastructure is drawing renewed attention across the industrial automation sector following a series of cyber incidents involving US water systems. Although the operational consequences of recent attacks appeared limited, the incidents have highlighted a broader vulnerability: many smaller utilities operate essential infrastructure with constrained budgets, limited cybersecurity personnel and aging operational technology (OT) environments.
The issue was recently examined by the International Society of Automation (ISA) through its latest Podomation episode, which brought together automation, cybersecurity and rural water experts to discuss practical lessons from recent incidents. The discussion focused not only on technology, but also on operator preparedness, incident response, cybersecurity standards and the realities faced by small and rural water utilities.
The panel included Steve Mustard of au2mation and a former ISA president, Leo Staples of Staples Farm and a former ISA president, cybersecurity consultant Arun Rajagopal, and Charles Stephens of the National Rural Water Association (NRWA). Morgan Foor moderated the conversation.
One of the most important observations from the discussion was that cybersecurity cannot be separated from the operational requirements of a water utility. Unlike many conventional IT environments, water and wastewater systems are responsible for continuous physical processes. Pumping stations, treatment systems, chemical dosing equipment, control systems, remote telemetry and other automation assets must remain available even when a security incident is underway.
For utility operators, availability and operational continuity therefore remain central objectives. A cybersecurity response that disrupts the ability to provide safe and reliable water can create a different type of operational risk. This makes the protection of industrial control systems (ICS), supervisory control and data acquisition (SCADA) environments and other OT assets particularly important.
The recent incidents also illustrate why internet exposure remains a significant concern. Some of the systems discussed by the panel were directly connected to the internet, potentially creating straightforward entry points for attackers. Internet-connected control equipment, remote access services and poorly segmented OT networks can increase the attack surface of facilities that were not originally designed around modern cybersecurity requirements.
However, the panel stressed that utilities should not simply be criticized after an incident occurs. The fact that several recent events did not result in widespread public disruption may indicate that some organizations had at least basic preparation and incident response capabilities in place.
That distinction is important for the wider industrial automation industry. Cybersecurity maturity is rarely achieved through a single software installation or network configuration. It depends on a combination of OT network segmentation, access control, asset visibility, backup procedures, incident response planning, operator training and ongoing risk assessment.
Standards such as ISA/IEC 62443 can provide an important framework for organizations seeking to establish a more structured approach to industrial cybersecurity. The standard series addresses cybersecurity across industrial automation and control systems and can help organizations establish common terminology, define responsibilities and develop security practices across different layers of an automation environment.
The need for a common cybersecurity language is particularly relevant when IT and OT teams work together. Industrial operators understand process requirements and equipment behavior, while IT and cybersecurity specialists often approach risk from a network and information-security perspective. Effective protection requires both sides to understand how a digital compromise can affect physical operations.
This challenge becomes even more pronounced in rural water infrastructure.
According to Charles Stephens, more than 90% of US water systems are small and rural. Many of these organizations do not have the financial resources or dedicated personnel available to operate a sophisticated cybersecurity program. For such facilities, security recommendations designed for large industrial enterprises may be difficult to implement and maintain.
A practical cybersecurity strategy must therefore account for the operating reality of smaller utilities. Instead of relying on complex security architectures that require extensive specialist support, utilities may need to prioritize fundamental controls that can be consistently maintained.
These can include identifying all internet-connected assets, eliminating unnecessary external access, strengthening authentication, maintaining reliable backups, separating critical control networks from business networks and regularly testing incident response procedures. Even basic measures can significantly improve resilience when they are implemented systematically.
Operator preparation is another recurring theme. Cybersecurity policies are of limited value if personnel do not know how to respond when an abnormal event occurs. Regular exercises can help operators recognize suspicious activity, understand escalation procedures and make decisions under pressure.
This approach increasingly resembles the principles used in functional safety. In safety engineering, teams routinely ask what can go wrong, determine the potential consequences and establish safeguards to reduce the likelihood or severity of an incident. Rajagopal argued that cybersecurity for critical infrastructure should be approached with a similar discipline.
The comparison is particularly relevant because cyber events can move beyond the digital environment. A compromised control system may affect pumps, valves, treatment processes or monitoring functions. In a water treatment facility, a cybersecurity failure can therefore become an operational issue and, under certain circumstances, a public health concern.
For industrial automation suppliers and system integrators, this trend also reinforces the importance of cybersecurity throughout the lifecycle of automation equipment. PLCs, RTUs, HMIs, industrial Ethernet devices, SCADA servers and remote monitoring systems increasingly operate as connected components within larger digital ecosystems.
Legacy equipment presents an additional challenge. Many water facilities rely on automation hardware that was installed years or even decades ago. Replacing every legacy controller or control system is rarely economically realistic, particularly for smaller utilities. Compensating controls, network isolation, access restrictions and improved monitoring can therefore play an important role in reducing risk around older systems.
The NRWA's Cybersecurity Circuit Rider Program provides one example of a more practical support model. The program connects experienced cybersecurity personnel with smaller utilities, offering direct assistance and guidance rather than expecting every organization to build a large internal security team.
This type of hands-on support could become increasingly important as water utilities face growing regulatory expectations and a more complicated threat environment. Cybersecurity programs need to be sustainable after consultants leave, meaning training and knowledge transfer are just as important as technical remediation.
The broader lesson from the ISA discussion is that cybersecurity for water infrastructure cannot be treated solely as an IT project. It is an operational risk-management issue involving engineering, automation, maintenance, management and cybersecurity personnel.
For B2B automation companies, this shift is also changing how industrial control products are evaluated. Procurement teams increasingly need to consider not only whether a PLC, controller, communication module or monitoring device performs its intended function, but also how the equipment fits into a secure OT architecture.
As industrial systems become more connected, OT cybersecurity is moving closer to the center of automation strategy. Water and wastewater utilities provide a particularly clear example because their systems support essential public services while often operating with limited technical resources.
The ISA discussion ultimately points toward a pragmatic approach: improve visibility, reduce unnecessary exposure, strengthen basic controls, train operators and establish response procedures that can actually be used during an incident. Technology remains an important part of the solution, but resilience depends equally on preparation and people.
The conversation comes at a time when water utilities, system integrators and automation professionals are reassessing how cybersecurity should be incorporated into critical infrastructure projects. For smaller organizations in particular, incremental improvements supported by practical expertise may prove more valuable than highly complex security programs that cannot be maintained over the long term.
ISA is continuing to address the subject through education and professional training. Its Cybersecurity Awareness Training for Water/Wastewater Industry Professionals course is scheduled as part of the 2026 ISA Automation Summit & Expo, with an in-person session planned for September 26 in Lake Buena Vista, Florida, followed by a virtual session on October 19. The event will also feature a panel discussion dedicated to cybersecurity in the water and wastewater industry.
For automation professionals, the message is increasingly clear: protecting critical infrastructure requires cybersecurity to be considered alongside control engineering, process reliability and functional safety from the beginning of a system's lifecycle.
Written by: Daniel Mercer — Daniel has more than 12 years of experience covering industrial automation, control systems and OT cybersecurity, with a focus on the technologies and operational challenges shaping modern critical infrastructure.