Water and wastewater utilities occupy a distinctive position in critical infrastructure security discussions: unlike energy or telecommunications, which are typically operated by well-resourced, consolidated providers, water utility service in most countries is delivered by a large number of small and mid-sized municipal or regional operators — many with limited dedicated cybersecurity staff, running systems that directly control the treatment and delivery of a resource whose compromise carries an unusually direct public health consequence.
Why the fragmentation of this sector is itself a security problem
A large metropolitan water utility might have security resources comparable to any enterprise IT organization. A small municipal water district serving a few thousand residents typically does not, despite running functionally similar supervisory control and data acquisition (SCADA) systems governing chemical dosing, pressure management, and treatment processes. That disparity means sector-wide security guidance has to account for an operator population whose actual capacity to implement recommendations varies enormously — a reality reflected in the EPA's approach to water sector cybersecurity, which has emphasized technical assistance and sector-specific guidance precisely because a one-size-fits-all regulatory mandate would be difficult for the smallest operators to meet without substantial external support.
What the current oversight landscape actually asks for
Water sector cybersecurity oversight in the United States has evolved through EPA guidance addressing cybersecurity as part of sanitary surveys and public water system risk assessments, informed by the broader America's Water Infrastructure Act requirements around risk and resilience assessments. The specifics of what's required have shifted over time as the regulatory approach has been refined, but the consistent theme across that evolution has been a push toward documented risk assessment of operational technology specifically, alongside the physical security and emergency-response planning water utilities have long been required to maintain.
What to look for in a security approach for this sector
OT-appropriate monitoring that doesn't require the technical sophistication of a large enterprise security team to operate, given how directly this sector's risk profile is shaped by resource-constrained operators. Tooling that demands a dedicated security operations function to extract value is a poor fit for the majority of utilities in this sector, regardless of how capable it is in principle.
Chemical dosing and treatment process control system visibility specifically, since these are the systems where an unauthorized change has the most direct public health consequence — water treatment involves precise chemical dosing (chlorine, fluoride, pH adjustment chemicals) where a manipulated setpoint isn't merely an operational nuisance but a potential public safety incident.
Remote access controls for the vendors and contractors who frequently manage SCADA systems on behalf of smaller utilities. Many water utilities outsource control system management and maintenance to specialized contractors, creating a recurring remote-access pattern into safety-relevant systems that deserves the same deliberate access governance applied to any privileged third-party access.
Software and firmware inventory for control system components with long service lives. Water treatment SCADA and PLC equipment is frequently kept in service for many years past typical IT refresh cycles, and knowing precisely what software and firmware are actually deployed — rather than what was originally installed at commissioning — is foundational to any meaningful risk assessment.
Why interconnected regional systems change the risk calculus
Water utilities increasingly share infrastructure and interconnections with neighboring systems for redundancy and emergency supply purposes — an operational resilience benefit that also means a security weakness in one utility's SCADA environment can, depending on how that interconnection is architected, potentially extend risk to a neighboring system that has no direct control over the first utility's security practices. Regional interconnection agreements increasingly need to address this shared exposure explicitly, rather than treating each utility's cybersecurity posture as entirely its own concern.
A note on scale disparity
State and regional technical-assistance programs exist partly to close the resource gap between the largest and smallest utilities; smaller operators should treat these programs as a genuine starting point rather than assuming they're on their own.
How Safeguard helps
Safeguard's continuous inventory and software supply chain visibility are built to work for organizations without a large dedicated security team, extending the same documented asset and provenance clarity to water utility operational technology that better-resourced sectors take for granted — giving smaller operators a practical path to the kind of documented risk picture that sanitary surveys and risk assessments increasingly expect.