Cybersecurity for Water and Wastewater Utilities
Few services matter more to a community than clean drinking water and safe wastewater treatment, yet many of the utilities that provide them run their control systems with a handful of staff and a tight budget. Attackers have noticed. The good news is that the most important protections for water and wastewater systems are practical, well understood and often inexpensive.
The reality for most utilities
Large metropolitan water authorities may have dedicated IT and security teams. Most utilities do not. A small town or rural district might have a few operators, a part-time IT contractor and an integrator who set up the SCADA system years ago and visits when something breaks.
That profile creates familiar challenges:
Limited budgets that must cover pipes, pumps, chemicals and staffing before cybersecurity.
Small teams where operators wear many hats and nobody owns security full time.
Remote assets such as lift stations, booster stations, wells, reservoirs and tanks, often connected by cellular, radio or consumer-grade internet links.
Remote access set up for convenience, so operators can check alarms from home or an integrator can support the system without travelling.
Legacy equipment that works well and is expected to run for many more years.
None of this is unusual, and none of it is a reason to give up. It simply means priorities need to be chosen carefully.
Internet-exposed HMIs and controllers
The most common and most dangerous weakness in the water sector is control equipment that can be reached directly from the internet. Researchers and government agencies have repeatedly found HMIs, PLCs and remote access tools at water utilities exposed online, sometimes protected only by a default or weak password.
This is not a theoretical problem. In late 2023, attackers compromised internet-connected Unitronics PLCs at several US water utilities and other organizations, including a booster station at the Municipal Water Authority of Aliquippa in Pennsylvania. The attackers defaced the device screens. US agencies, including CISA and the FBI, attributed the activity to cyber actors affiliated with Iran's Islamic Revolutionary Guard Corps, using the name CyberAv3ngers. The affected utility switched to manual operation, and there was no reported risk to drinking water, but the incident showed how easily exposed devices with default credentials can be reached.
Regulators are paying attention
In the United States, the Environmental Protection Agency has increased its focus on water sector cybersecurity. In May 2024, the EPA issued an enforcement alert warning drinking water systems about cyber threats. It reported that more than 70 percent of systems it had inspected since September 2023 did not fully comply with basic requirements of Section 1433 of the Safe Drinking Water Act, which requires community water systems serving more than 3,300 people to complete a risk and resilience assessment and an emergency response plan, and to keep them updated. The alert also highlighted basic weaknesses such as default passwords and shared logins.
Industry bodies offer helpful starting points. The American Water Works Association (AWWA) publishes cybersecurity guidance and a free assessment tool that helps utilities identify and prioritize controls based on how their systems are used. In Canada, the Canadian Centre for Cyber Security publishes guidance and advisories relevant to water operators, and in the US, CISA offers free services such as vulnerability scanning to water utilities.
Priority actions for small utilities

If resources are limited, focus on the steps that remove the most risk for the least effort.
Get control equipment off the public internet. Find out whether any HMI, PLC, modem or remote access tool is directly reachable online, and close it off. If remote access is needed, route it through a secured, monitored gateway.
Change default passwords on every controller, HMI, router and modem, and stop using shared accounts where possible.
Turn on multi-factor authentication for any remote access to the control system, including access by integrators and vendors.
Separate the SCADA network from the office network, so that ransomware on a billing or email computer cannot easily reach the plant.
Know what you have. Keep a simple list of SCADA components, remote sites, communication links and who has access.
Back up PLC programs and HMI projects, keep copies offline, and confirm they can actually be restored.
Update software and firmware where vendors provide fixes, starting with internet-facing and remote access components.
Write down who to call, including your integrator, your IT support, your regulator and your national cybersecurity agency.
Many of these steps cost little more than staff time. Several can be completed in a single afternoon.
Plan for manual operations
Water systems have one important advantage: operators often know how to run the plant by hand. That knowledge is a genuine security control, and it is worth protecting.
Make sure manual procedures are written down, available on paper and practised regularly. Confirm that key valves, pumps and chemical feeds can be operated locally, and that staff know how to monitor critical parameters without SCADA. Agree in advance who decides to switch to manual operation and for how long the utility can sustain it with the people available.
When the Aliquippa booster station was compromised, falling back to manual operation is what kept water flowing. Every utility should be confident it could do the same.
Building security into everyday operations
Cybersecurity in a small utility works best when it becomes part of normal routines rather than a separate project. Add a quick review of remote access accounts to monthly checklists. Ask integrators about security when scoping new work. Include a cyber scenario in emergency response exercises. Brief councils and boards in plain language, so that funding decisions reflect the risk.
Progress does not need to be perfect to be meaningful. A utility that has removed internet exposure, changed default passwords and practised manual operations is in a far stronger position than most.
How QBits Networks can help
We work with water and wastewater utilities of all sizes on practical, passive-first OT security assessments and secure remote access reviews, with recommendations sized to the budget and staff a utility actually has. We can also help with incident response readiness and awareness training for operators. Tell us what you need through our contact page and we'll scope it with you.