A number of US states have fallen victim to recent cyberattacks that target water and wastewater facilities. What began as one or two reports has evolved into a nationwide attack.
For municipalities of all sizes, these attacks offer important lessons about how to protect their services as cyberattacks advance.
Federal agencies have reported cyberattacks on water and wastewater systems in multiple states. According to public reports, attackers targeted internet-connected systems used to monitor and manage water infrastructure.
Reported impacts have included:
The good news is operators and emergency response helped prevent any major disruptions to the public water supply. Although there was no major impact, these threats show that attackers are increasingly aiming for critical infrastructure not just the typical business networks or financial data.
The recent attacks have exposed a challenge that many local governments face every day.
It's not that municipalities don't care about cybersecurity.
It's that they are often balancing cybersecurity against competing operational realities like:
Many municipalities operate with small IT departments that support:
Few small and mid-sized communities have dedicated cybersecurity teams.
Critical infrastructure systems often remain operational for decades.
Unlike standard business software, operational technology cannot always be upgraded quickly without disrupting essential services.
As a result, municipalities frequently manage both new technology and legacy systems.
Municipal budgets must cover:
Cybersecurity investments often compete with other critical priorities.
Meanwhile, cyber threats continue to grow in frequency and sophistication.
It’s easier for attackers to target organizations that have limited resources rather than the largest organizations with the strongest defenses.
In other words, the water facilities could be attacked because they are accessible and important.
Many security incidents begin with systems that organizations don't realize are exposed.
This can include:
Municipal leaders should regularly ask:
You cannot secure systems you do not know exist.
Creating and maintaining an accurate list of your technology ecosystem is one of the most important cybersecurity practices any municipality can implement.
Technology environments change constantly.
New software is added. Employees come and go. Vendors gain and lose access.
As a result, security assessments should not be viewed as a one-time project.
Security assessments help municipalities identify:
Security assessments like discoveries, vulnerability scans, and penetration tests are built to find the gasp that attackers can use to get into your system.
Penetration testing helps municipalities:
One of the most valuable lessons from recent events is that resilience matters just as much as prevention.
No organization can eliminate cyber risk entirely.
The question is not whether threats exist.
The question is how quickly an organization can respond and recover.
Municipalities should evaluate:
For many water and wastewater systems, operators can continue essential functions manually during technology outages.
Municipalities should ensure these procedures remain documented, accessible, and regularly tested.
The ability to maintain critical services during a cyber incident can dramatically reduce its operational impact.
Municipal cybersecurity has become increasingly complex.
Today's threat landscape may require expertise in:
Many municipalities cannot justify hiring specialists in each of these disciplines.
That's where external partnerships can provide value.
A co-managed approach allows internal teams to get the extra hand they need while gaining access to specialized expertise and enterprise level support.
For many local governments, this model provides a practical path to improving security without significantly hiring more full-time employees.
While every environment is unique, several initiatives consistently provide strong security value for municipalities.
Testing your environment regularly with security assessments helps identify vulnerabilities, gaps, and areas of elevated risk.
Supplementing internal teams can provide access to expertise that may otherwise be difficult to recruit or retain.
Threats don't operate on business hours. Monitoring helps organizations identify suspicious activity earlier and respond faster.
Lots of cyber incidents still start with humans like phishing attempts, compromised credentials, or social engineering attacks. Educating employees through monthly training still remains one of the most effective cybersecurity investments out there.
The recent attacks on water and wastewater infrastructure serve as a reminder that cybersecurity has become an essential component of public service delivery.
For municipalities, the challenge extends beyond preventing cyberattacks. It involves maintaining operational resilience, protecting public trust, and ensuring critical services remain available during unexpected events.
Organizations that regularly assess their security posture, test their defenses, prepare for recovery, and supplement internal expertise when needed will be better positioned to navigate an increasingly complex threat landscape.
Why are municipal water systems targeted by cybercriminals?
Water systems provide essential public services and increasingly rely on internet-connected technologies. Attackers may view smaller municipalities as easier targets because of limited staffing, aging infrastructure, and resource constraints.
How often should municipalities perform penetration testing?
Most organizations should conduct penetration testing at least annually and after significant infrastructure, application, or network changes.
What is co-managed cybersecurity?
Co-managed cybersecurity combines internal IT resources with external security expertise. This approach helps organizations improve security capabilities without hiring a large team of specialists.
Why would hackers target water systems?
Hackers may target water systems to disrupt operations, demonstrate access to critical infrastructure, gather intelligence, test vulnerabilities, or create public concern. In many infrastructure attacks, the goal is operational disruption rather than financial theft.
What damage can cybercriminals cause by changing passwords on industrial control systems?
Changing passwords on industrial control systems can lock operators out of monitoring and control platforms, reduce visibility into infrastructure operations, delay response times, and force utilities into manual operations while access is restored.
What do hackers gain by attacking water systems?
Attackers may have been seeking to demonstrate access to critical infrastructure, disrupt operations, gather intelligence, test vulnerabilities, or create public concern. In many attacks targeting critical infrastructure, operational disruption and proof of access can be more valuable than stealing data or demanding a ransom.