Skip to main content

Water Utility Cybersecurity: Risk, Compliance & Audits

August 7, 2026

Written by: Nick Weaver, Director, Water and Wastewater
Bill Bateman, Principal, Cybersecurity and NERC Compliance

This article surveys the current threat landscape, the patchwork of federal and state requirements that apply to utilities, and the water utility cybersecurity audit and cybersecurity consulting services that GDS provides that can help utilities ensure they are in compliance with regulatory standards and industry best practices that help mitigate the risk of cyber attack and potential liability for not enacting reasonable safeguards against attackers.

Threat Landscape

The potential threats to water and wastewater utilities do not differ significantly from those generally familiar to anyone who has undergone cybersecurity training and can range in sophistication from individuals with access due to employment or contractual responsibilities to the utility to nation states which could leverage access to systems for either targeted or strategic effect.

In addition to phishing and other attacks that would allow for compromise of any system, water and wastewater utilities have several structural weaknesses which have been identified in assessments of the sector:

  • Human-Machine Interfaces (HMI) that are publicly available on the internet, misconfigured, or protected by default/weak credentials.
  • Aging equipment such as PLCs, SCADA, and other systems, which may be decades old and do not or cannot receive security updates required to make them secure
  • Remote access programs and portals, which have been identified as the vector for several recent attacks. These pose additional risk in cases where two-factor authentication is not enabled. Another threat falling under this category is the possibility of backdoors being introduced into some equipment by commercial or state actors.
  • Limited firewalls between Information Technology (IT) and Operational Technology (OT) networks allow for compromises of administrative systems or personal equipment to bleed over to control systems for pumps, valves, and chemical feeds.
  • Third-party and vendor access allowing access for maintenance or support but also increase the potential for hacking of entities outside the utility to be used to gain control of systems.

As mentioned above, in addition to industry-specific risks, water and wastewater utilities also are subject to general cyberthreats common to all businesses or service providers, such as ransomware, commercial or state-sponsored infiltration of meter or usage data and stealing of customer information. These general cybersecurity threats are not a subject of this article but would be addressed as part of overall audit of cybersecurity audit.

Regulatory Requirements and Industry Standards

Unlike the electric sector, which is subject to mandatory and enforced standards for cybersecurity (NERC CIP), water and wastewater utilities are subject to a patchwork of federal and state standards along with voluntary adherence to industry best practices or standards. Some of the more broadly applicable regulatory frameworks are:

  • Safe Drinking Water Act (SDWA) and America’s Water Infrastructure Act (AWIA) Section 2013 of AIWA require community water systems serving over 3,300 people to conduct risk and resilience assessments and emergency response plans for multiple risk factors that include cybersecurity. While cybersecurity risk reduction is a goal of this act, no technical standards are prescribed, however checklists and guidance provided to support Section 2013 requirements are valuable tools for assessing risk.
  • The Environmental Protection Agency (EPA) has previously sought to incorporate a cybersecurity analysis into state sanitary surveys, however the efforts have been hampered by legal and political opposition.
  • The Cybersecurity and Infrastructure Security Agency (CISA) publishes water and wastewater specific cybersecurity goals, which are voluntary but represent a robust framework that can be used to reduce both baseline and enhanced risks.
  • Voluntary frameworks such as the NIST Cybersecurity Framework (CSF) or the American Water Works Associations (AWWA) Cybersecurity Guidance and evaluation tools, which are based on AWIA assessment requirements and CISA performance goals.

While compliance with assessment and planning mandates is necessary, simply meeting the letter of the law may leave utilities exposed to substantial and unaddressed risk exposure. For utilities serving large populations, critical infrastructure, a more proactive security posture and in depth review of potential vectors of attack and controls that are in place to reduce risk of cyberattack or mitigate the effect of an active threat.

Mitigating Cyber Risk: A Framework

Mitigating potential economic and operational risk of cyberattacks is an exercise in defense in depth, where the layers compliment each other to reduce the chances that an attacker can gain access to the system, or if access is obtained, reduce the ability to assert control over operations. Since risk can never be completely eliminated, mitigating potential risk extends to how the utility is able to recover from an incident where a successful attack has affected the utility’s ability to operate, disrupted customer operations, or public health has been impacted. In general terms, a robust framework involves:

  • Implementation of technical and operational controls such as network firewalls/segmentation, multi-factor authentication for system access, secure credentials, ensuring security patches are current, system monitoring, and staff and vendor training on identifying and responding to incidents. This first layer reduces the probability that an attacker will succeed in the first place.
  • Staff training the EPA provides cybersecurity training, exercises, and technical assistance courses at various levels to enhance staff awareness, preparedness, and response capabilities.
  • Audits and assessments simply having controls in place may create a sense of false security if vulnerabilities are not identified or if controls are not working as intended. Having a recurring cybersecurity audit or third-party assessment, including review of asset inventories, network architecture, access control, and assessing incident response through tabletop exercises ensure that the assumed level of security provided by technical and operational controls is verified and effective. If a cybersecurity incident does occur, audits provide documentation that the utility has taken prudent measures to reduce risk that can be provided to regulators, insurers, or utility governance. In the context of a utility subject to rate regulation, documentation provided as part of the audit or assessment process can be used to support the prudency of costs related to cybersecurity and the recovery of those costs from customers.
  • Insurance provides protection against the costs of responding to incidents, system restoration, business interruption, ransom/extortion payments (where legally permissible), and third-party liability claims. Having a history of audits and control documentation can directly affect the coverage available to a utility, the cost of coverage, and how any claim is ultimately resolved. We recommend utilities work with insurers experienced with critical infrastructure risk as generic cyber-security policies are not always well matched to the needs of a water or wastewater utility.
  • Plan and train for emergencies training and planning are necessary to ensure that the utility has a clear chain of command and plan for identifying and responding to a cybersecurity incident. This includes ensuring that backup systems and communication channels are available for critical personnel, forensic and legal resources can be quicky deployed, and that communications to customers and regulators are timely and professional. Training also allows for alignment of internal plans with a variety of situations, reducing the risk of unforeseen difficulties in an actual situation and allowing for identifications of gaps in planning or coverage that should be addressed.

Recommended Steps

The guidance from CISA, EPA, AWWA, and other industry sources all generally support taking the steps we outline below, organized by general category and impact.

  • Governance
    • Establish clear ownership of cyberattack risk identification and mitigation at the executive or board level, rather than compartmentalizing that responsibility within operational or IT departments.
    • Designate clear lines of responsibility for cybersecurity management, outside of the IT function
    • Designate clear lines of responsibility and decision-making authority that can be relied upon if a cyberattack has degraded standard organizational lines of authority and communication systems.
  • Technical
    • Segment IT and OT networks so that a compromise of one system is less likely to be used to infiltrate another
    • Require multi-factor authentication for access to systems
    • Eliminate use of default credentials on equipment or put compensating controls on legacy equipment that is not secure
    • Implement logging and monitoring of OT networks to enable identification and response to any anomalous access or activity.
    • Maintain patching program for systems, with documented and risk-based approach for OT equipment that cannot be patched without an operational impact.
  • Operational
    • Prepare incident response and business continuity plans and rehearse under specific realistic scenarios. Include plans for falling back to manual operation of system.
    • Conduct staff training on cybersecurity risks, both those which generally impact all organizations (e.g. phishing, social engineering) and those specific to utility operations
    • Scope and monitor vendor remote access and include contractual security and risk mitigation requirements in procurement documents and standard agreements.
  • Financial
    • Explore opportunities for funding mitigation efforts, including state revolving funds, EPA and CISA grants, regional collaboration or pooling costs across systems may allow smaller or less resourced systems to reduce risk.
    • Insurance is essential but compliments rather than replace the need to have controls in place. Baseline controls are often required as a condition of coverage and not having adequate controls in place may affect the resolution of a claim.
    • For utilities subject to rate regulation, the general standard of prudency needs to be met to recover costs associated with cybersecurity from customers. Having documentation of an effective and appropriate control environment supports successful inclusion of these costs.

How GDS supports Water and Wastewater Utility Cybersecurity

GDS provides cybersecurity audit and design services to clients, historically focusing on ensuring that clients meet the robust security standards required by the North American Electric Reliability Corporation (NERC). We have extended our services to offer similar services to water and wastewater utilities, including:

  • AIWA Risk and Resilience Assessments (RRA), EPA Vulnerability-based assessment, and emergency response plan support meeting Section 2013 requirements and documentation required to meet mandate and board, lender, and regulator requirements.
  • Cybersecurity audit and control assessments benchmarked against AWWA guidance, NIST Cybersecurity Framework and CISA’s water and wastewater goals, with findings translated into prioritized action plan.
  • Enhanced security posture including helping scope penetration testing, OT network engineering, or SCADA hardening to meet your requirements.
  • Training and planning including security awareness, tabletop incident response exercises, and system recovery rehearsals
  • Governance and board reporting translating technical audit findings into financial and risk-management language that board members or officials need to make resource allocation decisions.
  • Expert witness and regulatory support for capital investment, cost recovery, or defending the prudence of a cybersecurity-related cost.

For more information or to discuss your needs contact:

Nick Weaver, Director, Rates and Regulatory nick.weaver@gdsassociates.com

Bill Bateman, Principal, Cybersecurity and NERC Compliance bill.bateman@gdsassociates.com