top of page

America’s Water Systems Are Becoming a Front Line in Cyber Conflict

ICIT Research
13 hours ago
4 min read

September 2026

Author: Michael Centrella


The recent wave of cyberattacks against water and wastewater systems across the United States should change how we think about cybersecurity. An intrusion at a water utility is a public safety problem, an infrastructure resilience problem, and a national security problem, and treating it as a matter for the IT department understates all three.


I In recent days, water systems across multiple states have reported cyber incidents, including more than 30 systems in Minnesota and nine in Michigan. Utilities in Cape May County, New Jersey, have also confirmed attacks. Federal authorities are investigating the broader campaign, while public reporting has raised the possibility of foreign involvement. Importantly, attribution remains under investigation and should not get ahead of the facts.


What is already clear, however, is that adversaries recognize something we cannot afford to overlook: America's water infrastructure represents an attractive target.


The cyber-physical line has disappeared


For years, cybersecurity discussions centered on protecting data, networks, and information systems. Water and wastewater utilities show why that definition is now too narrow. 


Operational technology controls pumps, pressure, treatment processes, valves, wells, and other physical infrastructure. When those systems are compromised, a digital intrusion can potentially produce consequences in the physical world.


Reporting on the recent intrusions describes attempts to manipulate operational technology, passwords, network settings, and automated systems. Some communities saw operational disruption, including temporary loss of water pressure and interrupted treatment operations.


 None of the cases reported so far has caused widespread public-health consequences, which is fortunate. Complacency would be the wrong lesson to draw. This is a warning.


Small communities can carry national-security consequences


One of the greatest challenges facing the water sector is its fragmentation.


The United States has thousands of public water systems, many serving relatively small communities with limited cybersecurity personnel and budgets. Unlike a major federal agency or Fortune 500 company, a small municipal utility may not have a dedicated security operations center or sophisticated cyber-defense capabilities.


Yet the operational technology running that utility may still be accessible remotely, connected to vendors, dependent upon software providers, or exposed through internet-facing infrastructure.


CISA and EPA have repeatedly warned about internet-exposed human-machine interfaces used to operate water and wastewater infrastructure. Without appropriate controls, those interfaces can potentially allow unauthorized users to view operational information and make changes capable of disrupting treatment processes.


That creates an asymmetric advantage for an adversary.


An attacker does not necessarily need to defeat the defenses of the federal government to create disruption. Finding a poorly protected controller or remote-access system serving a small American community may be enough.


We need to move from compliance to continuous resilience


Another cybersecurity checklist will not answer this. CISA, EPA, and the FBI have already published practical recommendations: reduce public-facing internet exposure, eliminate default passwords, inventory IT and operational technology assets, conduct cybersecurity assessments, back up systems, remediate vulnerabilities, and exercise incident-response plans. Every utility should be doing all of it.


But we also need to recognize a larger issue: cyber risk is dynamic while traditional risk assessment is often periodic.


A water authority can complete an assessment today and have its exposure change tomorrow because a vendor is compromised, credentials are leaked, a new internet-facing asset appears, software vulnerabilities emerge, or a third-party service changes.


Critical infrastructure therefore needs continuous visibility, not only into its own environment, but into the external ecosystem upon which it depends.


That includes understanding vendors, contractors, software providers, remote-access relationships, internet-facing assets, and other third parties that can create pathways into operational environments.


In modern critical infrastructure, protecting the organization increasingly means protecting the ecosystem around the organization. 


Cybersecurity is now part of infrastructure investment


There is also a policy lesson.


We cannot continue treating cybersecurity funding as separate from infrastructure funding.


When federal and state governments invest in modernizing drinking-water and wastewater infrastructure, cybersecurity and operational resilience should be built into those investments from the beginning.


That is particularly important for smaller municipalities.


Washington can publish excellent cybersecurity guidance, but a rural or municipal water authority still needs the resources and expertise to implement it. States can play a critical role by providing shared cybersecurity services, continuous risk visibility, technical assistance, and funding that smaller jurisdictions could never reasonably build independently.


This should become a core component of state and federal critical-infrastructure strategy.


The goal must be resilience


No cybersecurity strategy can make every water system impenetrable. The realistic objective is American critical infrastructure that is harder to attack, faster to detect an intrusion, and more resilient when an attack succeeds.


Getting there requires knowing what infrastructure exists, how much of it is exposed to the internet, and which third parties create dependencies. Operators also need to catch changes in risk before they become incidents, keep the ability to run plants manually, and have the threat visibility that larger organizations take for granted.


America's water infrastructure is essential to public health, economic activity, emergency response, and virtually every other critical infrastructure sector. CISA itself notes that water and wastewater services support the operation of critical infrastructure throughout the country.


The events of the past several days should therefore be viewed as more than isolated cyber incidents.

They are a reminder that geopolitical conflict increasingly reaches American communities through digital infrastructure.


A municipal water plant may be hundreds or thousands of miles from a battlefield, but in the modern threat environment, distance no longer provides protection.


Our cybersecurity strategy must reflect that reality.


Protecting America's water is protecting America's national security.


Michael R. Centrella

Michael R. Centrella is a nationally recognized security executive and former senior federal law enforcement leader with more than 26 years of experience protecting critical infrastructure, safeguarding national leaders, and mitigating complex cyber and transnational threats. He most recently served as Assistant Director of the U.S. Secret Service’s Office of Field Operations, overseeing the agency’s largest operational directorate, comprising more than 3,000 personnel across 162 domestic and international offices.


About ICIT

The Institute for Critical Infrastructure Technology (ICIT) is a nonprofit, nonpartisan, 501(c)3think tank with the mission of modernizing, securing, and making resilient critical infrastructure that provides for people’s foundational needs. ICIT takes no institutional positions on policy matters. Rather than advocate, ICIT is dedicated to being a resource for the organizations and communities that share our mission. By applying a people-centric lens to critical infrastructure research and decision making, our work ensures that modernization and security investments have a lasting, positive impact on society.  

Learn more at www.icitech.org.




 
 

The Institute for Critical Infrastructure Technology is a non-partisan 501(c)3 not-for-profit organization. 

EIN #47-5294309

Follow Us

  • LinkedIn
  • Youtube

Important Links

 Support

+  Privacy Policy

Get the latest news & expert opinions delivered straight to your inbox

Keeping People at the Center of Critical Infrastructure

© 2026 by The Institute for Critical Infrastructure Technology (ICIT)

bottom of page