The recent cyberattacks against municipal water systems in Minnesota and Michigan should serve as another wake-up call for the US water sector. While the incidents caused limited operational disruption and no confirmed impact to drinking water quality, they demonstrated something far more important: attackers continue to view water systems as attractive targets, and many of those systems remain vulnerable.
More than 30 community water systems in Minnesota experienced coordinated attacks against operational technology (OT), with one utility temporarily losing automated control of its treatment process. Within days, Michigan reported suspicious cyber activity affecting nine additional water systems. Additional incidents have been reported in Georgia, South Dakota and New Jersey, although they have not yet been officially confirmed as part of the same campaign.
The significance of these incidents lies less in their immediate operational impact than in what they reveal about one of America's most fragmented critical infrastructure sectors. Operational technology cybersecurity is not about protecting information — it is about protecting physical processes.
America's water sector is unique. The United States operates approximately 144,000 public water systems, the overwhelming majority of which are small community systems with limited staff, modest budgets and little access to dedicated cybersecurity expertise. Unlike large electric utilities, many community water systems rely on a single operator, an external system integrator and perhaps a part-time IT contractor to maintain critical infrastructure. This reality means cybersecurity solutions must be practical, affordable and risk-based.
Security does not begin with technology. Federal guidance consistently emphasizes fundamental practices such as removing unnecessary internet exposure, implementing multifactor authentication, maintaining accurate asset inventories, strengthening remote access, performing regular backups and developing incident response plans. The challenge for small utilities is rarely knowing what to do — it is deciding where to begin. One of the key organizations helping answer that question is the National Rural Water Association (NRWA). Through its nationwide network of affiliated state rural water associations, NRWA provides technical assistance, operator training and engineering support to thousands of small and rural drinking water and wastewater utilities forming much of the US water and wastewater infrastructure. For many communities, NRWA represents their primary source of operational support and trusted technical advice.
In 2024, the NRWA collaborated with the White House Office of the National Cyber Director (ONCD) and the US Department of Agriculture (USDA) on a study to assess the cybersecurity capacity of rural water utilities by engaging specialist Cybersecurity Circuit Riders.
Rather than expecting small utilities to interpret complex cybersecurity guidance themselves, Cybersecurity Circuit Riders perform assessments, identify practical improvements, assist with implementation and help organizations develop cybersecurity programs appropriate to their operational environment. Programs such as the Cybersecurity Circuit Rider initiative provide a mechanism for translating recognized cybersecurity standards into practical improvements.
This is where the International Society of Automation (ISA) and the ISA/IEC 62443 series of standards become particularly valuable. A common misconception is that ISA/IEC 62443 is too large or too complex for small utilities. The reality is that the standards are risk-based. They recognize that a treatment plant serving 1,000 residents should not necessarily implement the same controls as a metropolitan utility serving millions.
Rather than prescribing identical security measures, ISA/IEC 62443 provides a framework for determining what level of protection is appropriate based on operational consequences. The standards address governance, risk assessment, secure system design, vendor development practices, lifecycle maintenance and continuous improvement. This allows organizations with limited resources to prioritize investments where they will produce the greatest reduction in operational risk.
Standards alone do not improve cybersecurity — people do. ISA complements its standards with workforce development, professional training, certificate programs, conferences and technical communities that help utilities build long-term capability rather than simply achieve compliance.
No individual utility can defend itself alone. NRWA, WaterISAC, EPA, CISA, the FBI, state agencies, equipment suppliers, system integrators and organizations such as ISA each contribute an important piece of the solution. Together they form an ecosystem that helps small utilities improve resilience through practical engineering guidance, workforce development and structured risk management.
One lesson from nearly every major cybersecurity incident is that significant attacks are often followed by calls for additional regulation. While regulation has an important role in establishing minimum expectations, it is rarely the most effective mechanism for improving cybersecurity across thousands of highly diverse water systems.
Within the US water sector, there is a wide degree of variation. A cybersecurity requirement that is entirely appropriate for a metropolitan utility serving several million people may be impractical for a rural community serving only a few hundred customers. A one-size-fits-all approach risks diverting scarce resources toward demonstrating compliance rather than reducing operational risk.
The water industry has an opportunity to demonstrate that there is a better approach. Rather than waiting for additional regulatory mandates, utilities can leverage existing resources from the collaborative ecosystem of organizations mentioned above to continuously improve cybersecurity maturity.
Programs such as the NRWA Cybersecurity Circuit Rider initiative provide practical assistance, tailored to each utility’s operational environment, helping organizations identify and prioritize improvements instead of simply checking compliance boxes. Likewise, ISA/IEC 62443 encourages organizations to understand their operational risks and implement controls appropriate to their specific systems, rather than applying identical requirements everywhere.
While compliance asks, “Have we satisfied the requirement?” risk management asks, “Have we meaningfully reduced the likelihood or consequence of a cyber incident?” These rarely produce the same answer.
If the water sector can demonstrate measurable progress through voluntary adoption of recognized standards, workforce development, peer collaboration and continuous improvement, it strengthens the case that industry-led initiatives can deliver better outcomes than increasingly prescriptive regulation. More importantly, it ensures that limited resources are directed toward protecting public health and maintaining reliable water service, rather than simply producing documentation.
The Michigan and Minnesota incidents are unlikely to be the last attempts against US water infrastructure. Success should not be measured by whether every utility achieves perfect cybersecurity or perfect compliance. Instead, it should be measured by whether every utility becomes more resilient than it was yesterday.
By combining industry-led initiatives with the structured, consequence-based approach embodied in ISA/IEC 62443, utilities of every size can steadily improve their cybersecurity maturity. If the water sector embraces this culture of continuous improvement, it has an opportunity not only to strengthen its own resilience, but also to demonstrate that industry leadership, collaboration and risk-based engineering can often achieve better outcomes than prescriptive regulation alone.
The opinions and views expressed are solely those of the authors and do not necessarily reflect any official policy, position or views of the International Society of Automation (ISA), Automation.com or the ISA Global Cybersecurity Alliance (ISAGCA).
