Most Water Utilities Remain Sitting Ducks for Cyberattacks

Image courtesy of DoD News under Attribution 2.0 Generic Deed, resized to 700 x 391 pixels.
The most common water utility vulnerabilities were yet again exposed thanks to the widespread attack that impacted at least 30 water systems in July 2026. The unfortunate reality is that hacking is easy, and most water utilities, save for the large players like American Water, are sitting ducks (pun intended). And there are a lot of targets for hackers – shockingly, only about 3% of the 156k public water systems in the U.S. serve more than 10,000 people.
The core issue is that these systems were never designed to protect against cyberattacks. That said, there are a few things water utilities can do to help shore up their defenses, and that’s what I’ll cover here.
5 Steps Water Utilities Can Take to Protect Against Cyberattacks
- Conduct regular risk assessments and vulnerability scans. It’s critical to execute regular system scans of SCADA, operational technology (OT) networks, and interconnected IT systems to identify potential weaknesses, outdated software, or misconfigurations.
- Implement strong access controls and segmentation. This includes enforcing the principle of least privilege, as well as segmenting the network to allow the OT systems to be isolated from the broader IT network if necessary to prevent malicious code from spreading.
- Establish comprehensive incident response and recovery plans. Ah, my favorite! Hopefully it goes without saying that the availability of detailed plans for detecting, responding to, and recovering from cyber incidents is critical. Like an ERP, these plans should cover things such as communication protocols, roles and responsibilities, and recovery procedures.
- Invest in employee training and awareness. This is probably the most important tactic of all, because most cyberattacks start with phishing. There’s no doubt, continuous training is vital to stay ahead of evolving cyber threats.
- Secure remote access and third-party connections. Relying on remote access for maintenance and third-party vendors is fine if the proper security measures are in place, like thoroughly vetting all vendors, limiting access to only what is absolutely necessary, and requiring multi-factor authentication (MFA).
The bottom line: Even pursuing just one of these steps will help fortify your system against cyberattacks, so have at it!
