Categories
Emerging Tech & AI Public Works & Infrastructure (DPW)

What Municipal Leaders Need to Know About Today’s Cyber Threats to Water Systems

For most residents, turning on the faucet is one of the most routine actions of the day. They expect clean water to come out. They expect toilets to flush, wastewater to be treated, fire hydrants to work, and the systems supporting their community to operate quietly in the background.

Behind that reliability, however, is an increasingly complex network of pumps, sensors, programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, computers, communications equipment, vendors, and employees. As water and wastewater operations have become more connected, they have also become more exposed to cyber threats.

That threat is no longer theoretical.

In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Environmental Protection Agency (EPA), and other government partners issued an updated warning regarding Iran-affiliated cyber actors targeting U.S. critical infrastructure. Federal agencies specifically highlighted exploitation of PLCs across multiple sectors, including U.S. water and wastewater facilities.

EPA has also warned more broadly that cyberattacks against public water systems are increasing.

For municipal leaders, the lesson should be clear: cybersecurity at a water or wastewater facility is no longer simply an IT issue. It is an operational resilience, public safety, financial, and governance issue.

Why Water Systems Are Attractive Targets

Water and wastewater utilities present a particularly challenging cybersecurity environment. Many municipalities operate systems that combine modern technology with equipment installed years—or sometimes decades—ago. Operational technology may have been designed primarily for reliability and longevity rather than today’s cybersecurity environment.

At the same time, remote connectivity has become increasingly common. Employees, contractors, integrators, and vendors may need remote access to equipment. Internet-connected human-machine interfaces (HMIs), PLCs, SCADA environments, and other operational systems can create pathways into infrastructure when they are improperly configured or inadequately protected.

The threat actors themselves vary. A municipality may face ransomware criminals seeking money, hacktivists looking for attention, opportunistic attackers scanning the internet for exposed devices, or sophisticated actors associated with foreign governments.

The motivation may be different, but the result can be the same: disruption of an essential public service.

EPA’s cybersecurity incident guidance warns that incidents can interfere with treatment, distribution, and conveyance processes; compromise industrial control systems; expose sensitive information; damage components; and disrupt a utility’s ability to provide safe water and wastewater services.

Cybersecurity Has to Reach the Operational Technology Environment

One of the most important conversations municipal leaders should have with their water departments is simple:

What equipment in our water or wastewater operations can be accessed remotely—and who can access it?

The answer may surprise you.

Municipalities should identify every internet-facing or remotely accessible operational technology asset, including HMIs, PLCs, SCADA systems, engineering workstations, remote monitoring equipment, vendor connections, and communications devices.

Then determine whether that connectivity is actually necessary.

Federal guidance recommends restricting internet access to process-control systems unless absolutely necessary, separating operational/process-control traffic from business networks, identifying all methods of remote access, eliminating unnecessary remote connectivity, and tightly restricting whatever access must remain.

This is especially important because attackers do not necessarily need to develop an elaborate attack specifically for a small municipality. Poorly secured internet-connected equipment can provide an opportunity.

In other words, being small does not necessarily make a municipality invisible.

Seven Actions Municipalities Can Take Now

Municipal cybersecurity can quickly become overwhelming, particularly for smaller communities with limited staff and budgets. Rather than trying to solve everything at once, municipal leaders can begin with several practical actions.

1. Know what you have.
Create and maintain an inventory of critical IT and operational technology. Identify PLCs, SCADA servers, HMIs, engineering workstations, remote-access systems, network equipment, computers, software, and communications systems supporting water operations. Document who owns, maintains, and has access to each critical system. CISA has emphasized asset inventories as a foundation for protecting operational technology.

2. Identify and reduce internet exposure.
Determine which devices and systems are accessible from the public internet. If internet connectivity is unnecessary, remove it. Where remote access is operationally necessary, restrict it and protect it appropriately. Reducing exposure to the public-facing internet is the first action highlighted in the federal government’s Top Cyber Actions for Securing Water Systems.

3. Separate IT from OT.
The computer used for email and administrative work should not have unrestricted access to systems controlling pumps, valves, treatment processes, or chemical operations. Network segmentation and firewalls can help prevent a compromise of the municipality’s business network from becoming an operational emergency.

4. Review remote and vendor access.
Municipalities frequently depend upon outside vendors to maintain specialized equipment. That relationship does not eliminate the municipality’s responsibility for understanding how vendors connect to its environment. Ask who has remote access, how accounts are authenticated, whether access is continuously available or enabled only when needed, and how access is removed when an employee or contractor leaves.

5. Prepare to operate manually.
Technology can fail due to cyberattacks, equipment failures, communication outages, or other emergencies. Public works personnel should know how critical operations will continue if SCADA or other automated systems become unavailable. Procedures should be documented, accessible offline, and periodically exercised.

6. Develop and exercise a cyber incident response plan.
Do not wait until an attack occurs to decide who calls the mayor, supervisor, emergency management, law enforcement, regulators, IT provider, cyber insurer, or outside incident-response firm. EPA now provides a customizable Cybersecurity Incident Response Plan specifically for drinking water and wastewater systems. The agency recommends that utilities develop, practice, and regularly update these plans.

7. Assess the system—and turn the findings into a budget.
An assessment sitting on a shelf does not reduce risk. Identify vulnerabilities, prioritize them based on operational consequences, assign responsibility, set deadlines, and determine the required funding. EPA offers both self-assessment resources and a program through which water systems can receive cybersecurity assessments and risk-mitigation assistance.

Questions Elected Officials Should Be Asking

Elected officials do not need to become SCADA engineers or cybersecurity specialists. They do, however, have a responsibility to ask appropriate governance questions.

At an upcoming board or council meeting, consider asking:

  • Do we have a current inventory of our water and wastewater IT and operational technology?
  • Are any PLCs, HMIs, SCADA components, cameras, or other control devices directly accessible from the internet?
  • Who can remotely access our water systems—including outside vendors?
  • Is multifactor authentication required for remote access where technically feasible?
  • Are our administrative IT systems appropriately separated from operational technology?
  • When were our critical systems last assessed for cybersecurity vulnerabilities?
  • Do we maintain secure backups, and have we tested our ability to restore them?
  • Can operators safely maintain essential operations if SCADA or network connectivity becomes unavailable?
  • Do we have a written cyber incident response plan?
  • Has that plan actually been exercised with municipal leadership, public works, IT, emergency management, and other key partners?
  • Who has authority to make critical decisions during an incident?
  • Who must be notified if an incident occurs?
  • What cybersecurity improvements need to be included in the next municipal budget or capital plan?

If municipal leadership cannot readily answer those questions, that is not necessarily evidence that the municipality has failed. It is evidence that a conversation needs to begin.

Put Cybersecurity Into the Emergency Response Plan

Cybersecurity should not exist in isolation from emergency management.

A cyberattack against a water facility could simultaneously become a public works emergency, a public health issue, a communications challenge, a financial event, and a political crisis.

That means the emergency response plan should account for scenarios such as loss of SCADA visibility, manipulation of control systems, loss of communications, compromised employee credentials, ransomware, inability to process customer payments, loss of access to operational data, or suspicious changes to treatment processes.

EPA provides “rip and run” Incident Action Checklists designed specifically to help water and wastewater utilities prepare for, respond to, and recover from cybersecurity incidents.

For community water systems serving more than 3,300 people, federal law also requires risk and resilience assessments and emergency response planning under Section 1433 of the Safe Drinking Water Act, as amended by America’s Water Infrastructure Act. Those emergency plans must incorporate the findings of the system’s risk and resilience assessment and address physical security and cybersecurity.

But compliance should be the starting point—not the finish line.

Cybersecurity Is Also a Budget Conversation

One of the greatest mistakes municipal governments can make is identifying cybersecurity deficiencies without creating a realistic path to correct them.

Public works departments cannot implement improvements without resources.

If an assessment identifies obsolete equipment, unsupported operating systems, insecure remote access, inadequate network segmentation, insufficient backups, or a need for monitoring, those findings should be incorporated into the municipality’s operational and capital planning.

Not everything has to happen in one budget year. Prioritize improvements according to their potential consequences.

Ask: If this system were compromised tomorrow, what could affect our ability to safely provide water or wastewater services?

Start there.

Preparedness Matters More Than Perfection

No municipality can eliminate cyber risk completely.

The objective is resilience.

Can you detect something unusual? Can you isolate affected equipment? Can operators continue critical functions? Can you communicate with the public? Can you quickly reach the right external resources? Can you restore systems safely? And can municipal leaders make informed decisions under pressure?

Those capabilities can dramatically change the outcome of an incident.

Municipal water and wastewater systems are among the most important pieces of infrastructure local government operates. Protecting them requires cooperation between public works, IT professionals, vendors, emergency management, municipal administrators, elected officials, insurers, state partners, and federal agencies.

Cybersecurity cannot belong exclusively to the IT department or the water superintendent.

It has to become part of how the entire municipality thinks about continuity and public safety.

The next cyber incident affecting the water sector may target a large metropolitan utility—or it may begin with an exposed device at a small community water plant.

Municipal leaders cannot control who attempts to attack their systems.

They can control how difficult they make those systems to compromise—and how prepared their community will be if an attacker succeeds.

Resources for Municipal Water and Wastewater Leaders

EPA maintains cybersecurity planning, assessment, incident response, and emergency planning resources specifically for drinking water and wastewater systems.

EPA Cybersecurity for the Water Sector

EPA Cybersecurity Planning and Top Cyber Actions

EPA Risk and Resilience Assessment and Emergency Response Planning Resources

EPA Incident Action Checklists for Water Utilities

CISA’s July 2026 Advisory on Threats to U.S. Water and Wastewater Facilities

Elisabeth Dubois's avatar

By Elisabeth Dubois

Elisabeth Dubois, Ph.D., is a cybersecurity expert and researcher dedicated to protecting communities and empowering public leaders in the digital age. Currently serving as a Cyber Risk Specialist with NYMIR and Co-Director of the Local Government Cybersecurity Alliance, Elisabeth specializes in helping local governments navigate the complexities of AI, cyber risk management, and incident response.

Her research focuses on the intersection of technology, risk management, and social equity—specifically investigating how cyber threats and crisis communications affect vulnerable populations. With a Ph.D. in Information Science (specializing in crisis communication and information assurance), an MBA, and a B.S. in Digital Forensics from the University at Albany, Elisabeth combines technical expertise with a passion for public policy and international education.

Leave a Reply

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.

Discover more from Local Government Cybersecurity Alliance

Subscribe now to keep reading and get access to the full archive.

Continue reading