Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

The Next Water Cybersecurity Challenge: Protecting the Systems Behind the Pipes

By Ankita Dutta, Senior Product Marketing Manager
Share this Post

Water and wastewater utilities are entering a more difficult cybersecurity environment, with vulnerabilities described by experts as “alarming”.

Across the world, utilities are connecting pumping stations, treatment systems, sensors, SCADA environments and remote sites to networks that enable centralized monitoring, automation, analytics, and remote maintenance. While the digital transformation improves water management, it also creates more opportunities for attackers to reach the OT (Operational Technology) powering essential services. NIST's 2026 water-sector cybersecurity guidance specifically identifies secure remote access as an immediate priority for the sector.

The Threat Goes beyond IT Ransomware and Other Cyberattacks

Attackers are reaching the systems that control the physical processes of water and wastewater operations.

Recent U.S. activity provides a particularly clear warning. In July, the FBI reported incidents involving internet-facing Rockwell Automation PLCs at water and wastewater utilities in at least seven states. Attackers modified PLC passwords to lock out operators and changed IP addresses to disconnect PLCs, degrading water operations in some cases.

In August, U.S. agencies issued another advisory concerning targeted activity against Siemens S7 PLCs, with authorities warning that threat actors were using AI-assisted capabilities to develop exploitation scripts. The affected technologies span water, energy, manufacturing, and other critical infrastructure sectors. The same month, news surfaced about Minnesota and Michigan water systems being struck by coordinated cyberattacks.

These incidents are U.S.-based, but the underlying vulnerabilities are global.

Legacy infrastructure, increasing connectivity, remote access, limited cybersecurity resources, and exposed OT is a combination which exist across water and wastewater systems worldwide.

Security teams need to treat water infrastructure as a high-value target and critically assess whether their current architecture can contain an IT compromise before it reaches OT.

Why Water and Wastewater Are Increasingly Attractive Targets

Water utilities have a particularly challenging security profile: geographically distributed infrastructure needing protection and immediate operational consequences in case of failure.

Many facilities operate with long equipment lifecycles and legacy PLCs and SCADA components. Smaller utilities may have limited cybersecurity personnel, while vendors and operators require remote access to geographically dispersed systems.

PLCs can control pumps, valves, and other equipment involved in water distribution and treatment. Recent reporting on the U.S. incidents highlights how attackers reaching these systems can move beyond data theft and affect the physical operation of water infrastructure. Some affected utilities had to revert to manual operations.

Since taking away an operator's ability to monitor or control a process can itself become an operational incident, water and wastewater facilities become different than a conventional enterprise environment.

The problem doesn’t stay within one country or one technology. Europe's NIS2 framework includes drinking water and wastewater among the critical sectors subject to increased cybersecurity requirements, reflecting the broader recognition that disrupting these services can have significant societal consequences.

What Should Security Teams Prepare for?

1. Direct Attacks against Exposed OT

Internet-facing PLCs should be considered a high-priority risk.

Security teams need an authoritative inventory of PLCs, HMIs, engineering workstations, remote-access gateways and other network-enabled OT assets, including systems managed by third parties.

Assuming by default that devices are vulnerable: can an external actor reach it at all? CISA's recent water-sector alert specifically recommends removing PLCs from direct internet exposure and protecting OT through appropriate access controls and network architecture.

2. Compromise of Remote-Access Pathways

Remote access is increasingly essential to distributed water operations and vendor-maintenance workflows, but it can also create a bridge directly into OT.

NIST's new Cybersecurity for the Water and Wastewater Sector guidance provides practical reference architectures for securely enabling remote access to OT across utilities with different sizes and resource levels. The guidance emphasizes controls such as role-based access, authentication, logging, and network segmentation.

Utilities should therefore examine not only who is authorized to connect, but what that connection can reach, and whether compromised credentials could provide a route toward control systems.

3. Faster Exploitation through AI

The Siemens advisory mentioned earlier introduces another concern: attackers may increasingly use AI to reduce the expertise and time required to develop industrial exploitation tooling. Reporting on the advisory indicates that malicious scripts can be disguised as legitimate software and used against vulnerable industrial environments.

For water utilities, this could make reconnaissance and exploitation of exposed industrial devices more scalable. Security teams should therefore assume that attackers can move from discovery to exploitation faster than before.

4. Persistent and Repeatable Attacks

A weakness in a particular PLC, remote-access configuration or third-party deployment can potentially be identified and reused against multiple organizations.

For smaller utilities in particular, this creates an asymmetry: an attacker can automate reconnaissance across a large number of potential targets, while each utility has limited personnel and resources to investigate its own environment. This resource imbalance has been highlighted in recent analysis of the water-sector attacks.

Design OT Boundaries to Limit Attack Paths

The response cannot simply be "patch the PLC." Some OT systems cannot be patched immediately. Some require continuous operation. Some need remote access. And some must exchange operational data with enterprise systems.

The stronger approach is to reduce the number of paths an attacker can use. Where OT data needs to leave a protected environment, but commands do not need to return, utilities should consider hardware-enforced one-way communication.

Instead of:

OT ⇄ IT

a data diode can establish:

OT → Data Diode → IT

This allows operational information to move to historians, analytics platforms, SOCs or enterprise systems while preventing network traffic from travelling back through the same boundary.

Data diodes should not replace firewalls or segmentation. They provide another layer of architectural control where the business requirement is inherently one-way.

Protect the Content, not just the Connection

Water and wastewater environments routinely exchange engineering documents, PLC configurations, software, firmware, vendor tools, and other files. Network isolation addresses one attack path but doesn’t guarantee every file is trustworthy.

Files should be treated as untrusted content until inspected. This is where MetaDefender™ Core can complement network isolation. Multiscanning can analyze files using multiple anti-malware engines, providing additional detection perspectives.

Deep file analysis can inspect actual file structures, embedded objects and suspicious content rather than relying solely on filenames or extensions.

Deep CDR™ Technology can remove potentially dangerous active content and reconstruct files according to security policy.

The resulting architecture separates two different security questions:

  • Where can data go? A data diode can enforce the answer.
  • What content is allowed to cross the boundary? Multiscanning, deep file analysis and Deep CDR™ Technology can help answer that.

The Next 12 Months: Prepare for a more Capable Adversary

Water and wastewater security teams should prioritize:

  1. Eliminating direct internet exposure of OT systems to internet-facing devices.
  2. Mapping every remote-access path into operational environments.
  3. Validating actual IT/OT communication paths rather than relying on network diagrams.
  4. Identifying where bidirectional connectivity is genuinely required and eliminating it where possible.
  5. Protecting files entering sensitive environments with multiscanning, deep analysis and CDR.
  6. Preparing for attackers who can automate reconnaissance and exploitation.
  7. Testing manual and degraded operations when OT visibility or control is lost.

These priorities also align with the direction of international cybersecurity policy. The latest U.S. advisories provide a useful indicator of where the threat is heading, but the underlying challenge extends far beyond the United States. In Europe, water and wastewater are within the scope of NIS2, while ENISA's work continues to assess cybersecurity maturity and criticality across EU critical sectors.

The goal is no longer just detecting attacks, but limiting how far an attacker can move into systems that control physical processes. By combining secure network boundaries such as data diodes with file security through MetaDefender Core, utilities can modernize while strengthening operational resilience.

Get in touch with an OPSWAT expert and get more information on how OPSWAT can help you successfully secure your critical infrastructure, with no effect on operational continuity.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.