Skip to main contentPublic Header Nav
knowledge exchange

Cyberattacks expose America’s water-system resilience gap

A person filling a reusable transparent water bottle at a kitchen faucet above a stainless-steel sink. Bottle contains measurement markings and visible water movement, highlighting everyday tap-water use and refillable hydration.

Key points

  • Cyberattacks are testing the safeguards that protect drinking water systems, particularly smaller utilities operating with limited staff, constrained budgets and aging technology.
  • Federal requirements have strengthened risk and resilience planning for larger systems, but many smaller systems fall outside those requirements and compliance challenges remain among systems that are covered.
  • Closing the gap will require more than new mandates. Utilities will also need funding, technical assistance and practical support to secure the operational technology that keeps water moving.

Cyber risk raises the stakes for prevention

Safe drinking water depends increasingly on digital systems. Utilities use connected technology to monitor water quality, operate pumps and valves, manage storage and maintain pressure throughout their networks. That connectivity can improve performance, but it also creates new points of exposure.

The risk became clear during cyber incidents reported in July 2026. Hackers reportedly used widely known credentials to bypass remote-management safeguards and target more than 100 water systems across at least 12 states, with a heavy focus on smaller utilities, according to the U.S. Cybersecurity and Infrastructure Security Agency. The most concerning targets were internet-exposed programmable logic controllers, or PLCs, which act like the operational brains of many water systems.

Diagram showing operational technology and information technology cyber risks, including network complexity, maintenance, data breaches, non-segmented networks and ransomware.
Source: Cybersecurity and Infrastructure Security Agency (CISA)

PLCs are attractive targets because they connect the digital and physical sides of a water system. Traditional information technology supports functions such as email, billing and customer accounts. Operational technology controls equipment and processes, including pumps, valves, tanks and treatment operations. A compromise involving operational technology can therefore affect physical service, not just information systems. Reported consequences included lost water pressure, flooding and the need to move portions of system operations to manual control.

Existing requirements do not reach every system

The Safe Drinking Water Act provides the primary federal framework for protecting public drinking water. Following the Sept. 11 attacks, Congress added Section 1433 to the SDWA in 2002 to move the law beyond public health compliance and toward water-system security. Congress strengthened that framework in 2018 through America’s Water Infrastructure Act, requiring community water systems serving more than 3,300 people to conduct risk and resilience assessments, develop emergency response plans and update those materials on a recurring schedule.

Two-part chart showing 19% of community water systems under mandatory cyber planning and 81% under voluntary planning.
Source: EPA

Yet recent events reveal limitations in that framework. More than 70% of the water systems inspected by the Environmenal Protection Agency since September 2023 were found out of compliance with basic risk-and-resilience assessment or emergency-response planning requirements. At the same time, systems serving 3,300 or fewer people are not subject to Section 1433’s mandatory planning provisions. These small systems represent approximately 81% of all community water systems, although they serve a much smaller share of the population.

That distinction matters because smaller utilities often have less access to cybersecurity staff, operational-technology specialists and the funding needed to modernize older equipment. Extending requirements to more systems may strengthen accountability, but mandates alone will not address these underlying capacity constraints.

For consumers, those capacity gaps raise the stakes for prevention. A recent ruling from the 5th U.S. Circuit Court of Appeals involving Jackson, Mississippi, suggests residents may not always be able to rely on the courts after drinking-water safeguards fail. The court held that Jackson residents could not bring the type of constitutional clean-water claim that residents of Flint, Michigan, were allowed to pursue in federal court. Communities may still be able to push for existing rules to be enforced, but they may have fewer legal options when those rules fail to prevent harm. That makes practical, near-term risk reduction essential.

Immediate steps can reduce exposure

The most urgent priority is to remove operational technology from direct internet exposure wherever possible. Federal authorities have also advised utilities to use secure gateways and firewalls, establish strong and unique passwords, restrict communications to authorized devices and maintain clean backups of PLC configurations.

Utilities can further improve resilience by maintaining accurate inventories of information and operational technology assets, separating business networks from control systems, and practicing manual procedures that allow essential service to continue during an incident.

These steps are practical, but implementation can be difficult for systems with small staffs and limited budgets. Smaller utilities may need shared expertise rather than standalone cybersecurity programs.

Stronger expectations must come with practical support

The water sector is developing several models for providing that support, including sector-led standards, cybersecurity circuit riders, targeted assessments and cyber-informed engineering. These approaches can help utilities move beyond written plans and address the physical equipment, remote connections and control systems on which reliable service depends.

The path forward is not to add another layer of compliance. It is to pair appropriate cybersecurity expectations with funding, technical assistance and shared services that systems can realistically use. Small utilities should address their most immediate vulnerabilities now. Larger systems should incorporate cybersecurity into long-term infrastructure planning. Industry associations, vendors and government partners should continue building shared capabilities that make specialized expertise accessible across the sector.

Takeaway

Water-system resilience increasingly depends on both physical infrastructure and digital security. Protecting safe and reliable water will require treating physical infrastructure and digital security as parts of the same investment strategy.

Disclaimer: The information provided in this report is not intended to be investment, tax, or legal advice and should not be relied upon by recipients for such purposes. The information contained in this report has been compiled from what CoBank regards as reliable sources. However, CoBank does not make any representation or warranty regarding the content, and disclaims any responsibility for the information, materials, third-party opinions, and data included in this report. In no event will CoBank be liable for any decision made or actions taken by any person or persons relying on the information contained in this report.