Water utility cybersecurity: How to assess risk and meet EPA & CISA guidance

Eric Suesz Eric Suesz February 8, 2024

Updated August 2026: This guide now includes CISA’s latest cyber resilience framework and recommendations for protecting operational technology (OT) systems.

Cybersecurity has become one of the most pressing challenges facing water and wastewater utilities. Recent attacks on critical infrastructure have highlighted the risks posed by increasingly sophisticated cyber threats, prompting renewed guidance from the EPA, CISA, and other federal agencies. Whether you’re a small utility with limited IT resources or a large regional provider, understanding your cybersecurity risks is now an essential part of protecting public health and maintaining reliable service.

This guide walks through the EPA’s recommendations, explains how to assess your utility’s cybersecurity risk, and outlines practical steps to strengthen both your cybersecurity and operational resilience.

Why water utility cybersecurity matters

A quick cybersecurity pop quiz. Which of these three events is based on an actual occurrence?

The correct answer, unfortunately, is “all of the above”. These were all actual events in California, Florida, and Kansas that were thankfully stopped in their tracks by attentive employees. To date, there has been no successful attempt by hackers to poison an American community’s water supply.

However, these types of attacks will inevitably become more sophisticated over time, which has prompted the US government to raise a cybersecurity alarm for the US’s 148,000+ public drinking water systems and 16,000+ publicly owned wastewater treatment systems.

What types of attacks might be directed at water utilities?

The specific details of how hackers might wreak havoc in the water sector vary, but the major threats to water utilities can be grouped into a few basic categories:

Utilities can shore up their defenses against cyberattacks in all of these categories with effective internal employee policies and procedures, but the last two on the list can be harder to accomplish if your workforce relies on older or outdated software and devices without access to the latest firmware updates.

What is the current state of the EPA’s guidance and CISA’s recommendations?

Ideally, the EPA wants utilities to assess their own cybersecurity readiness as part of their regular Public Water System (PWS) sanitary surveys. This isn’t a requirement, but it – or something like it – could be in the future.

The EPA issued a memorandum in March 2023 with plans to fold cybersecurity assessments into sanitary surveys, but this was temporarily halted by the 8th Circuit US Court of Appeals in July and then withdrawn in October of that year.

While you might be waiting for the guidance to develop or the guidelines to turn into official regulations, water utilities should not wait to implement cybersecurity improvements. If your utility isn’t performing any regular cybersecurity monitoring or assessments, there is no better time to correct it than ASAP.

In fact, it may be alarming to learn that less than 25% of water and wastewater operators surveyed by the EPA are currently performing these kinds of annual cybersecurity risk assessments. 

Although the EPA’s attempt at encouraging momentum for cybersecurity among utilities failed in 2023, and although the US Congress hasn’t yet proposed specific national legislation, this does not mean the issue will go away.

Indeed, this has ramped up efforts by CISA and other government bodies. Recently, FBI Director Christopher Wray testified before Congress about the dangers of Chinese hackers infiltrating US infrastructure systems. Only a few days later, Iranian officials were targeted by US sanctions for attacks last year. All of this points to an increasing urgency for action around cybersecurity issues in the water sector, which means water utilities can either wait for guidance or take proactive steps to assess their risk and close holes in their systems.

Resources for assessing your level of cybersecurity

If you have IT personnel at your water utility who are tasked with watching for cybersecurity threats, we’ve collected a number of checklists that we encourage you to share with them so they can more easily determine your utility’s cybersecurity readiness:

Can the cloud help water utilities with security?

We wanted to talk to an expert with experience for the energy and utility sectors about the EPA’s mandate, so we sat down for a conversation with AWS Principal Security Industry Specialist Maggy Powell. 

Consult with an expert

If you don’t have the benefit of IT personnel on staff, you may be able to tap into these expert resources:

The security benefits of SaaS?

We’re building new and innovative services that don’t require users to update their desktop or device’s software. Indeed, in many respects the Software as a Service (SaaS) model – in which you access all of your data, analytics, hydraulic models, etc., via a secure browser – has the potential to help to alleviate some of the cyber risks that utilities currently face.

In addition to Autodesk certifications and compliance, these services are all powered by AWS, which we chose partly because of the enhanced security these cloud services can provide for water utilities who utilize our software. So you may find that some of the boxes in these checklists can be quickly checked off because you aren’t using installed desktop software AND aren’t sharing sensitive files over internal or “on-premises” systems.

Cybersecurity: perhaps the most important reason to update your software

If you are using desktop software, you need to ensure it’s updated.

A 2021 CISA survey found that over 80% of major vulnerabilities that surveyed facilities experienced were software flaws discovered before 2017, suggesting that a significant number of employees were not updating their software. If your utility relies on older desktop software (especially outdated legacy operating systems like Windows 7), you are more at risk for cyber incidents and you should carefully and methodically assess your security level.

2026 ‘CI Fortify’: CISA’s six-step cyber resilience framework

Recent cyberattacks on water utilities have reinforced the need to protect both IT and operational technology (OT) systems while ensuring essential services remain online. In response, CISA’s new CI Fortify guidance recommends six steps to improve operational resilience:

  1. Identify vital systems needed to safely deliver water and wastewater services.
  2. Identify critical customers and the services that must remain operational.
  3. Assess system criticality and establish trust levels across networks.
  4. Define isolation points where critical systems can be disconnected if needed.
  5. Build separation between operational technology and enterprise IT.
  6. Test isolation plans regularly to ensure critical operations can continue during an incident.

For water utilities, resilience begins with understanding your infrastructure, how assets are connected, and which systems are most critical to operations.

Stay safe and secure

Going through these checklists can be an eye-opening experience for the smallest utilities who may not have the benefit of IT personnel to guide purchasing or technical assistance needed to implement cybersecurity best practices. But it is always better to enter the cybersecurity waters with your eyes open.

Learn about Autodesk’s security practices and the steps we take to enhance security of our products on the Autodesk Trust Center.

CISA fact sheet

Editor’s note: This article’s original publication date was August 21, 2023 and is being updated whenever there is new information to share.


What is water utility cybersecurity?

Water utility cybersecurity is the practice of protecting the information technology (IT) and operational technology (OT) systems that support drinking water and wastewater operations. This includes securing SCADA systems, treatment plants, pump stations, remote monitoring equipment, and the digital infrastructure used to manage critical assets.


Why are water utilities increasingly targeted by cyberattacks?

Water and wastewater utilities are part of the nation’s critical infrastructure, making them attractive targets for cybercriminals and nation-state actors. Many utilities also operate legacy systems with limited cybersecurity resources, increasing the importance of proactive risk assessments and resilience planning.


What cybersecurity guidance should water utilities follow?

The U.S. Environmental Protection Agency (EPA) recommends that utilities conduct regular cybersecurity risk assessments and incorporate cyber risks into their overall resilience planning. More recently, the Cybersecurity and Infrastructure Security Agency (CISA) introduced a six-step framework to help utilities identify critical systems, isolate operational technology, and maintain essential services during a cyber incident.


What is the difference between cybersecurity and cyber resilience?

Cybersecurity focuses on preventing attacks through protective controls, while cyber resilience emphasizes maintaining safe operations and recovering quickly if an attack occurs. Both are essential for protecting critical water infrastructure.


How can water utilities assess their cybersecurity risk?

A good starting point is identifying critical assets, evaluating vulnerabilities across both IT and OT environments, and conducting a formal cybersecurity risk assessment. Utilities should also review network segmentation, remote access policies, asset inventories, and incident response plans to understand where improvements are needed.


How does asset management support cybersecurity?

While asset management software is not a cybersecurity solution, maintaining an accurate inventory of infrastructure assets helps utilities understand what systems they operate, how they are connected, and which assets are most critical. This information supports risk assessments, network segmentation, incident response, and operational resilience.

Fill up on more of the One Water Blog

Sign up for the One Water Blog LinkedIn newsletter, and we'll keep you updated about our top stories, along with the best content we find online. We only send out a newsletter when we have something interesting to share.