The original iteration of this article was published in The League of Minnesota Cities
🔒 Key Takeaways
- Water systems are now cyber-physical infrastructure: as SCADA/OT connectivity increases, cyber risks directly impact water quality, operations, and public safety (not just IT).
- Critical infrastructure is a growing target because disruption creates immediate, visible impact: making water utilities attractive to cyber threats and attacks.
- Most vulnerabilities start small and go unnoticed: common entry points include weak access controls, phishing, and legacy systems not designed for modern cybersecurity.
- Early warning signs matter: unusual logins, system changes, operational anomalies, and ransomware indicators can signal intrusion before major disruption occurs.
- Resilience depends on proactive risk management: regular assessments, staff training, strong access controls, and use of frameworks (e.g., NIST) help utilities prevent, detect, and respond to threats.
Turning on the tap feels simple, but today’s water systems are anything but. Once mostly mechanical, they now rely on connected software, sensors, and control networks. That shift improves efficiency and visibility, but it also opens the door to cyber risk.
Cybersecurity is no longer just an IT issue in the background. It is an operational reality that directly affects reliability, public health, and community trust. For utility leaders, understanding this shift is key to keeping water operations safe, reliable, and resilient.
Cybersecurity in Water Systems: What It Actually Means
Modern water infrastructure relies on computer-based technology, often referred to as Supervisory Control and Data Acquisition (SCADA) and Operational Technology (OT) systems. These platforms act as the control layer behind the scenes, directing how water is treated, monitored, and distributed across communities. In simple terms, they keep day-to-day water operations running safely and consistently.

Both systems manage critical processes such as treatment operations, chemical balancing, pump controls, and distribution. Because these technologies directly control physical processes, any disruption, unauthorized access, or manipulation can have immediate operational impacts, from incorrect chemical dosing to service interruptions or equipment damage. Without this level of control, modern water infrastructure could not deliver the reliability communities depend on every day.
Cybersecurity in this context goes far beyond protecting traditional IT systems like office networks, computers, or email. It also includes safeguarding OT that directly controls physical water processes, protecting both digital information and the physical environments it supports.
As connectivity increases, so does the importance of understanding where risk exists and how it can impact operations and public safety.
Why Cybersecurity Has Become a Water Sector Issue
Water systems have become a target not because they are easy to attack, but because they are essential. Disruptions create immediate, visible impacts, making them attractive to cyber threats.
At the same time, the way these systems operate has changed. Utilities are expanding digital connectivity across treatment, distribution, and monitoring systems to improve efficiency and visibility. That connectivity improves operations, but it also expands the number of potential access points into critical infrastructure.
“We’re seeing an increase in cyber activity targeting metropolitan areas of all sizes, where attackers can have the greatest impact by going after large-scale systems and data,” says Bill Kloster, Chief Information Officer at SEH. “Even the smallest exposure can create entry points that can be used to disrupt operations and critical services.”
In October 2024, American Water, which serves more than 14 million people across 14 states and 18 military installations, experienced a cyberattack that forced billing pauses, disrupted customer service, and required system isolation. The incident showed how quickly digital disruption can affect essential services.
With artificial intelligence (AI) and other emerging technologies, the environment is becoming more complex. While these tools improve monitoring and response, they also introduce new layers of exposure that must be managed. Together, connectivity, evolving technology, and critical service demands are pushing cybersecurity from a background concern to a core operational priority.
Key Warning Signs and Exposure Points
Many utilities operate with legacy infrastructure systems that were not designed with modern cybersecurity protections in mind. As a result, these environments can create gaps that are difficult to fully secure without updates or additional safeguards.
“Some cyber threats operate quietly, with little to no warning signs. That’s why it’s critical to actively manage vulnerabilities, categorize risk levels from low to critical, and have a clear remediation plan in place,” says Bill.
Understanding where that risk exists is the first step toward managing it. Most cyber threats in water operations don’t begin with a major system failure. It often enters through routine access points and gradually becomes harder to detect.
Early warning signs of potential cyber activity include:
- Unusual login activity or behavior: Access attempts from unfamiliar users or devices, especially outside of normal operating patterns.
- Unexpected changes in system settings or controls: Unexplained adjustments to operational parameters such as chemical dosing, pressure levels, or treatment settings.
- Sudden operational malfunctions: Irregular equipment or system disruptions such as pump issues, valve malfunctions, or unexplained slowdowns in performance.
- Increased phishing activity or suspicious communications: An increase in phishing and hack attempts to obtain login credentials or system access.
-
Ransomware indicators or access issues: Users being locked out of systems or receiving messages demanding payment to restore access to operational platforms.
These signals may seem minor, but they can indicate intrusion and help prevent wider disruption if recognized in time.
What Utility Leaders Should Be Doing Now
Cyber attacks against vulnerable community water systems (CWSs) are increasing across the country. In May 2024, the Environmental Protection Agency (EPA) reported that more than 70 percent of inspected systems were not meeting cybersecurity requirements under Section 1433 of the Safe Drinking Water Act. These findings point to a broader gap between regulatory expectations and on-the-ground implementation.

“Most utilities are partnering with cybersecurity experts across the country to evaluate risks and identify opportunities,” says Bill. “While no system is completely risk-free, the goal is to manage risk in a way that strengthens overall resilience.”
Maintaining strong cybersecurity hygiene supports efforts to prevent, detect, respond to, and recover from cyber incidents. Even though risk cannot be fully eliminated, there are clear, practical steps utility leaders can take to strengthen resilience and better protect their systems.

Some best practices include:
- Maintaining strong cybersecurity hygiene: Reinforcing secure password practices, access control, and routine system updates.
- Conducting regular OT and SCADA-focused assessments: Identifying vulnerabilities within operational environments.
- Training staff on best practices: Helping teams recognize threats and follow secure access protocols
- Using established frameworks: Applying standards such as National Institute of Standards and Technology (NIST) and Cybersecurity Maturity Model Certification (CMMC) to guide risk management.
- Integrating cybersecurity into planning: Embedding security into system design, upgrades, and long-term strategy.
Taking these steps not only reduces risk but helps ensure water systems remain reliable, secure, and ready to serve the communities that depend on them every day.
The Takeaway: Building Cyber Resilience in Water Systems
Reliable water service depends on more than infrastructure alone. It depends on how well evolving risks are understood, managed, and addressed before they disrupt business operations.
Cyber threats continue to evolve, but utilities do not have to navigate them alone. Working with experienced partners who understand both operational and cybersecurity challenges can help utilities identify gaps early, strengthen resilience and protect the systems communities rely on every day.
About the Experts
William (Bill) R. Kloster is a principal and chief information officer at SEH with more than a decade of experience with the firm. As an information technology specialist, he leads strategic technology initiatives and supports innovative, secure, and efficient IT solutions across the organization.

.png?width=113&name=SEH_Logo_RGB%20(1).png)