Updated August 2026: This guide now includes CISA’s latest cyber resilience framework and recommendations for protecting operational technology (OT) systems.
Cybersecurity has become one of the most pressing challenges facing water and wastewater utilities. Recent attacks on critical infrastructure have highlighted the risks posed by increasingly sophisticated cyber threats, prompting renewed guidance from the EPA, CISA, and other federal agencies. Whether you’re a small utility with limited IT resources or a large regional provider, understanding your cybersecurity risks is now an essential part of protecting public health and maintaining reliable service.
This guide walks through the EPA’s recommendations, explains how to assess your utility’s cybersecurity risk, and outlines practical steps to strengthen both your cybersecurity and operational resilience.
Why water utility cybersecurity matters
A quick cybersecurity pop quiz. Which of these three events is based on an actual occurrence?
- A malicious cyber actor deploys a SCADA-based ransomware attack against a water and wastewater system.
- A hacker accesses the computer systems for a water treatment facility, modifying the sodium hydroxide (lye) levels from 100 ppm to an extremely poisonous 11,100 ppm.
- A former employee at a water treatment plant remotely accesses a computer and shuts down the cleaning and disinfecting procedures that make water potable.
The correct answer, unfortunately, is “all of the above”. These were all actual events in California, Florida, and Kansas that were thankfully stopped in their tracks by attentive employees. To date, there has been no successful attempt by hackers to poison an American community’s water supply.
However, these types of attacks will inevitably become more sophisticated over time, which has prompted the US government to raise a cybersecurity alarm for the US’s 148,000+ public drinking water systems and 16,000+ publicly owned wastewater treatment systems.
What types of attacks might be directed at water utilities?
The specific details of how hackers might wreak havoc in the water sector vary, but the major threats to water utilities can be grouped into a few basic categories:
- Spearphishing using social engineering to attempt to deploy malware such as ransomware
- Insider threats from current or former employees who maintain improperly active credentials
- Exploitation of unsupported or outdated operating systems and software
- Exploitation of control system devices with vulnerable firmware versions
Utilities can shore up their defenses against cyberattacks in all of these categories with effective internal employee policies and procedures, but the last two on the list can be harder to accomplish if your workforce relies on older or outdated software and devices without access to the latest firmware updates.
What is the current state of the EPA’s guidance and CISA’s recommendations?
Ideally, the EPA wants utilities to assess their own cybersecurity readiness as part of their regular Public Water System (PWS) sanitary surveys. This isn’t a requirement, but it – or something like it – could be in the future.
The EPA issued a memorandum in March 2023 with plans to fold cybersecurity assessments into sanitary surveys, but this was temporarily halted by the 8th Circuit US Court of Appeals in July and then withdrawn in October of that year.
While you might be waiting for the guidance to develop or the guidelines to turn into official regulations, water utilities should not wait to implement cybersecurity improvements. If your utility isn’t performing any regular cybersecurity monitoring or assessments, there is no better time to correct it than ASAP.
In fact, it may be alarming to learn that less than 25% of water and wastewater operators surveyed by the EPA are currently performing these kinds of annual cybersecurity risk assessments.
Although the EPA’s attempt at encouraging momentum for cybersecurity among utilities failed in 2023, and although the US Congress hasn’t yet proposed specific national legislation, this does not mean the issue will go away.
Indeed, this has ramped up efforts by CISA and other government bodies. Recently, FBI Director Christopher Wray testified before Congress about the dangers of Chinese hackers infiltrating US infrastructure systems. Only a few days later, Iranian officials were targeted by US sanctions for attacks last year. All of this points to an increasing urgency for action around cybersecurity issues in the water sector, which means water utilities can either wait for guidance or take proactive steps to assess their risk and close holes in their systems.
Resources for assessing your level of cybersecurity
If you have IT personnel at your water utility who are tasked with watching for cybersecurity threats, we’ve collected a number of checklists that we encourage you to share with them so they can more easily determine your utility’s cybersecurity readiness:
- New for 2024: CISA, FBI and EPA released an Incident Response Guide for the Water and Wastewater Sector that we encourage you to download and peruse. It covers four stages of response: 1) preparation, 2) detection and analysis, 3) containment, eradication, and recovery and 4) post-incident action.
- The EPA provides an extensive list of resources, including a downloadable water Cybersecurity Assessment Tool and Risk Mitigation Plan Excel Template that you can use to assess your cybersecurity.
- The Cybersecurity and Infrastructure Security Agency (CISA) has a Cyber Security Evaluation Tool (CSET) which you can download and install on a PC to help assess your security posture.
- The American Water Works Association (AWWA) provides Water Sector Cybersecurity Risk Management Guidance, as well as an online Cybersecurity Assessment Tool you can use to assess your readiness and comply with §2013 of America’s Water Infrastructure Act (AWIA) of 2018.

Can the cloud help water utilities with security?
We wanted to talk to an expert with experience for the energy and utility sectors about the EPA’s mandate, so we sat down for a conversation with AWS Principal Security Industry Specialist Maggy Powell.
Consult with an expert
If you don’t have the benefit of IT personnel on staff, you may be able to tap into these expert resources:
- Consult with a CSA: CISA offers a range of cyber and physical services throughout 10 regions. You can contact your regional office and ask about consulting with a Protective Security Advisor (PSA) or Cyber Security Advisor (CSA).
- Ask a circuit rider: USDA Rural Development has contracted with the National Rural Water Association to provide circuit riders in each US state and territory who are experienced in managing issues that arise in the day-to-day operations of rural water systems. Read all about it and submit an application online.
- Guidance for smaller utilities: If your water utility serves less than 10,000 people, the AWWA’s Water Sector Cybersecurity Risk Management Guidance for Small Systems that serve less than 10,000 people can help streamline your self-assessment.
- Secure a grant: CISA and FEMA recently announced the availability of $374.9 million in grant funding for the FY 2023 State and Local Cybersecurity Grant Program. The deadline to apply is October 6.
- CISA announced a free program for water utilities. They will scan your publicly available networks and give you advice. The process is easy and you can receive results within 10 days. We’ve included their fact sheet at the bottom of this post, and you can email them to get started.
The security benefits of SaaS?
We’re building new and innovative services that don’t require users to update their desktop or device’s software. Indeed, in many respects the Software as a Service (SaaS) model – in which you access all of your data, analytics, hydraulic models, etc., via a secure browser – has the potential to help to alleviate some of the cyber risks that utilities currently face.
In addition to Autodesk certifications and compliance, these services are all powered by AWS, which we chose partly because of the enhanced security these cloud services can provide for water utilities who utilize our software. So you may find that some of the boxes in these checklists can be quickly checked off because you aren’t using installed desktop software AND aren’t sharing sensitive files over internal or “on-premises” systems.
Cybersecurity: perhaps the most important reason to update your software
If you are using desktop software, you need to ensure it’s updated.
A 2021 CISA survey found that over 80% of major vulnerabilities that surveyed facilities experienced were software flaws discovered before 2017, suggesting that a significant number of employees were not updating their software. If your utility relies on older desktop software (especially outdated legacy operating systems like Windows 7), you are more at risk for cyber incidents and you should carefully and methodically assess your security level.
2026 ‘CI Fortify’: CISA’s six-step cyber resilience framework
Recent cyberattacks on water utilities have reinforced the need to protect both IT and operational technology (OT) systems while ensuring essential services remain online. In response, CISA’s new CI Fortify guidance recommends six steps to improve operational resilience:
- Identify vital systems needed to safely deliver water and wastewater services.
- Identify critical customers and the services that must remain operational.
- Assess system criticality and establish trust levels across networks.
- Define isolation points where critical systems can be disconnected if needed.
- Build separation between operational technology and enterprise IT.
- Test isolation plans regularly to ensure critical operations can continue during an incident.
For water utilities, resilience begins with understanding your infrastructure, how assets are connected, and which systems are most critical to operations.
Stay safe and secure
Going through these checklists can be an eye-opening experience for the smallest utilities who may not have the benefit of IT personnel to guide purchasing or technical assistance needed to implement cybersecurity best practices. But it is always better to enter the cybersecurity waters with your eyes open.
Learn about Autodesk’s security practices and the steps we take to enhance security of our products on the Autodesk Trust Center.
CISA fact sheet
Editor’s note: This article’s original publication date was August 21, 2023 and is being updated whenever there is new information to share.
What is water utility cybersecurity?
Water utility cybersecurity is the practice of protecting the information technology (IT) and operational technology (OT) systems that support drinking water and wastewater operations. This includes securing SCADA systems, treatment plants, pump stations, remote monitoring equipment, and the digital infrastructure used to manage critical assets.
Why are water utilities increasingly targeted by cyberattacks?
Water and wastewater utilities are part of the nation’s critical infrastructure, making them attractive targets for cybercriminals and nation-state actors. Many utilities also operate legacy systems with limited cybersecurity resources, increasing the importance of proactive risk assessments and resilience planning.
What cybersecurity guidance should water utilities follow?
The U.S. Environmental Protection Agency (EPA) recommends that utilities conduct regular cybersecurity risk assessments and incorporate cyber risks into their overall resilience planning. More recently, the Cybersecurity and Infrastructure Security Agency (CISA) introduced a six-step framework to help utilities identify critical systems, isolate operational technology, and maintain essential services during a cyber incident.
What is the difference between cybersecurity and cyber resilience?
Cybersecurity focuses on preventing attacks through protective controls, while cyber resilience emphasizes maintaining safe operations and recovering quickly if an attack occurs. Both are essential for protecting critical water infrastructure.
How can water utilities assess their cybersecurity risk?
A good starting point is identifying critical assets, evaluating vulnerabilities across both IT and OT environments, and conducting a formal cybersecurity risk assessment. Utilities should also review network segmentation, remote access policies, asset inventories, and incident response plans to understand where improvements are needed.
How does asset management support cybersecurity?
While asset management software is not a cybersecurity solution, maintaining an accurate inventory of infrastructure assets helps utilities understand what systems they operate, how they are connected, and which assets are most critical. This information supports risk assessments, network segmentation, incident response, and operational resilience.