Municipal water & wastewater
Water utility cybersecurity, verified — not self-reported.
Starting in July 2026, attackers reached water systems in at least a dozen states. Operators were locked out of their own controllers, some utilities reverted to manual operation, and some issued boil-water notices. None of it required sophistication. It required equipment that could be reached from the internet.
Request your free consultation12
states with water systems reached in the campaign that began 27 July 2026.FBI and EPA public service announcement, 30 July 2026
308
of 1,062 large drinking water systems were found carrying cybersecurity vulnerabilities.EPA Office of Inspector General, November 2024
70%
of inspected systems were out of compliance with federal risk assessment and response planning rules.EPA enforcement alert, May 2024
Four exposures that keep showing up
Across every publicly reported water sector incident of the last three years, the same handful of weaknesses appear. None of them are exotic.
Controllers on the public internet
Pumps, valves and chemical feed run on programmable logic controllers. When one answers from the open internet, anyone scanning can find it. In the 2026 campaign, attackers changed PLC passwords and IP addresses and locked operators out of their own equipment. At least one utility found its ladder logic had been modified.
Default and shared passwords
In Aliquippa, Pennsylvania, a controller sat exposed on the internet still using its factory password. An Iranian-linked group took over the booster station serving two townships. Shared logins that no one has rotated since installation are the same problem wearing a different hat.
One flat network
When office email and plant controls share a network, a single phished click reaches the process side. American Water, the largest investor-owned water utility in the country, shut down its customer portal and paused billing for about a week in October 2024 after an intrusion on the business side.
Equipment nobody owns
Vendor-installed cellular modems, aging human-machine interfaces, controllers past end of support. If no one at the utility can produce a list of every device that touches the process, that list is always longer than anyone expects.
Why a checklist isn't a test
Most utilities that have "done cybersecurity" have filled in a questionnaire. A questionnaire records the network someone believes they have. It cannot tell you whether that belief is correct, and on nearly every assessment we run, the network diagram and the actual network disagree somewhere that matters.
A self-assessment will tell you that remote access requires multi-factor authentication. It will not find the vendor's maintenance modem installed in 2019 that bypasses it entirely. That gap is not a paperwork problem. It is the whole problem.
Request your free consultation
What a real test looks like
Three steps. You know exactly what you are buying before you spend anything.
External exposure review
We start where an attacker starts: everything belonging to your utility that answers from the public internet, including credentials already sitting in breach data. This needs no access to your systems and no time from your operators.
On-site walkthrough
Then the part a scan cannot see. Whether plant controls are genuinely separated from the business network, who holds remote access, and what sits on the process network that nobody remembers installing. Roughly 45 minutes of an operator's time.
Findings in plain language
A written report and a 30-minute call, ranked by what would actually hurt you and what it costs to fix. Written to be handed to a board, not to a network engineer.
You may already have the budget for this
Section 1433 of the Safe Drinking Water Act, as amended by section 2013 of America's Water Infrastructure Act, requires community water systems serving more than 3,300 people to prepare or revise a risk and resilience assessment and certify its completion to the EPA.
That statute explicitly covers electronic, computer and other automated systems, including the security of those systems. Cybersecurity is not an optional extra inside the assessment — it is part of what the assessment is required to address. The EPA names a third-party contractor assessment as one of the legitimate ways to satisfy it.
For most utilities this moves the conversation off discretionary security spend and onto a statutory obligation with a deadline that already exists. If you are not sure where your utility stands, that is a good first question for the call.
Questions we get from utilities
Will this take our plant offline?
No. The external review touches nothing you operate. Anything that would interact with live control equipment is planned in writing and approved by you before it happens, and in most engagements it is not necessary at all.
We are a small system. Are we really a target?
Nobody chose the systems hit in 2026. More than 30 community water systems in Minnesota were reached over a single weekend because their equipment answered an internet scan. Small is not the same as obscure when a device is reachable from anywhere.
Does this satisfy our federal risk assessment requirement?
It supports it. The cybersecurity portion of a risk and resilience assessment has to address the security of your automated systems, and the EPA recognises third-party assessment as a valid route. We will tell you plainly on the call how our findings map to what you have to certify.
How much of our operators' time does it take?
Around 45 minutes for the walkthrough, plus a 30-minute call at the end to go through the findings. The external portion takes none of your time at all.
What do we actually get?
A written report ranked by real-world impact, with what each fix costs and how urgent it is, written so a board or council can read it without a translator. Plus a call to walk through it.
What does it cost?
The consultation is free and carries no obligation. If a test makes sense after that conversation, we scope it against your system and quote it, and you decide from there. We do not quote before we understand what we would be testing.
Start with a call, not a contract.
A no-cost 30-minute consultation. We walk your setup with you and say plainly whether you have exposure worth testing. If a test makes sense, we scope it and quote it, and you decide.
Request your free consultation