The recent cybersecurity attacks affecting water and wastewater utilities across multiple states serve as an important reminder of a reality facing the water sector today: as utilities become more connected, resilience increasingly depends on both physical infrastructure and digital security.
Just as utilities prepare for storms, floods, droughts, power outages, and equipment failures, they must also prepare for cyber incidents. Cybersecurity is no longer solely an IT function. It is a core component of operational resilience, and an essential part of ensuring communities continue to receive safe and reliable water services.
Resilience is ultimately built by people. Technology matters, but trained operators, strong emergency plans, cross-functional coordination, and a culture of preparedness remain the foundation of effective utility operations.
The good news is that many of the most effective cybersecurity measures are achievable for utilities of any size. The recent incidents highlighted a reality that applies across the sector: cybersecurity is not a one-time project or compliance exercise. Like emergency preparedness, asset management, and workforce development, it requires ongoing attention and continuous improvement.
While every utility's needs and resources are different, there are several practical steps utilities can take today to strengthen resilience and reduce risk.
1. Review Internet-Facing Operational Technology
Recent attacks specifically targeted internet-facing programmable logic controllers (PLCs). Utilities should review their OT environment, confirm that critical assets are not directly accessible from the public internet, and ensure remote access occurs through secure gateways or VPNs rather than direct connections.
Even utilities with mature cybersecurity programs should periodically validate all external connections, including cellular modems and remote access solutions installed or managed by vendors and third-party partners.
2. Strengthen Authentication and Remote Access Controls
Weak or default credentials remain one of the most common pathways for unauthorized access. Utilities should eliminate default passwords, implement multi-factor authentication wherever possible, and regularly review who has privileged access to operational and control systems.
3. Assess Your Cybersecurity Posture
Understanding where vulnerabilities exist is the first step toward reducing risk. Utilities should regularly evaluate their cybersecurity programs to identify gaps, prioritize improvements, and ensure protective measures keep pace with evolving threats.
Routine assessments can help organizations focus limited resources where they will have the greatest impact.
4. Know Your Assets and Protect Your Data
Utilities cannot secure systems they do not know exist. Maintaining a current inventory of internet-facing assets, operational technology, software, and connected devices is a foundational cybersecurity practice.
At the same time, utilities should regularly back up critical systems and data, test restoration procedures, and ensure backups are protected from network-based threats by isolating them from operational environments whenever possible.
5. Review and Exercise Emergency Response Plans
The recent incidents demonstrated the value of preparation. Utilities should confirm they can safely transition to manual operations if automated systems become unavailable, verify emergency contact information is current, and ensure staff understand their responsibilities during a cyber incident.
Just as importantly, response plans should be practiced through exercises and updated regularly based on lessons learned.
6. Build a Culture of Cybersecurity Awareness
Cybersecurity is not solely the responsibility of IT departments. Operators, engineers, supervisors, executives, and front-line staff all play a role in recognizing and responding to potential threats.
Creating a culture of awareness through training, communication, and cross-functional collaboration helps ensure that cybersecurity becomes part of daily operations rather than an isolated function.
At WEF, we view moments like this as opportunities for education, collaboration, and continuous improvement. Through workforce development, peer-to-peer knowledge sharing, and partnerships with organizations such as the WaterISAC, EPA, AWWA, and CISA, WEF helps utilities strengthen cybersecurity and operational resilience while embracing emerging technologies and best management practices.
In response to the recent cyber incidents affecting water and wastewater utilities, WEF is also making A Guide to Cybersecurity for Water and Wastewater Utilities free for a limited time. No purchase will be necessary once a free profile is set up on Access Water, our digital content platform. The resource provides practical guidance on managing information technology systems, reducing risk, and supporting resilient utility operations.
As utilities continue modernizing infrastructure and adopting innovative technologies, cybersecurity must advance alongside that progress. Recent incidents serve as a reminder that resilience is built through preparation, collaboration, continuous learning, and investment in people. WEF remains committed to helping water professionals innovate securely and strengthen the systems that protect public health and the environment every day.
See how WEF connects the people and ideas driving clean water and public health. Membership gives you access to benefits, resources, and a network committed to impact.
WEF is a source of high-quality technical resources featuring the latest research, news, and education. WEF's members and other credible resources have created and compiled this information into the Practice Area groupings listed in the dropdown menu.