The latest episode of Podomation, the official podcast of the International Society of Automation (ISA), looks at recent cyber incidents in the United States involving water systems. While the immediate consequences appeared limited, these events raise a pressing question: what happens when a small or rural utility, already stretched thin on resources, becomes the target of an attack?
Podomation Episode 012 – Cybersecurity for Water and Wastewater Systems: Lessons Learned invites four panelists to discuss what system operators should consider as they move to assess their risk, shore up vulnerabilities and ensure that water systems are adequately protected.
What is Podomation?
Podomation is ISA's podcast showcasing top subject-matter experts in the industrial automation community. Its guests speak on a broad range of topics that matter to automation professionals, including industry 4.0, digital transformation, manufacturing and machine control, instrumentation, connectivity, OT cybersecurity and continuous and batch processing.
Some episodes are recorded live during ISA events, and others are recorded in studio. Each podcast conversation highlights the role of automation in making the world a better place — and the impact our community has across industries.
Podomation Episode 012 – Cybersecurity for Water and Wastewater Systems: Lessons learned
This episode tackles the recent headlines around water/wastewater cybersecurity, offering real-world tips for operators tasked with protecting small or rural utilities from cyberattacks. Along with moderator Morgan Foor, the panelists address the role of standards such as ISA/IEC 62443, the impact of regulation and perhaps the most significant factor of all: operator training and preparation.
The panelists in this episode include:
- Steve Mustard, au2mation and ISA Past President
- Leo Staples, Staples Farm and ISA Past President
- Arun Rajagopal, cybersecurity consultant
- Charles Stephens, National Rural Water Association (NRWA)
As the panelists noted, the targeted systems likely already had some preparation in place that kept the situation from getting much worse. While many of the targeted systems under discussion were found to be directly connected to the internet, making them relatively easy targets, the lack of widespread public impact from these breaches suggests that some utilities had incident response strategies that proved effective. Rather than assigning blame to utilities that get breached, Mustard said, the industry should focus on providing the support needed for remediation and long-term security improvement.
Staples emphasized the importance of having a common language across teams — an invaluable step for maintaining a strong cybersecurity posture over time. The top goal is availability, as Staples said. Delivering safe, reliable water to utility customers is a critical service, and teams should make an effort to keep incident response plans top of mind with regular exercises and training.
Rajagopal suggested that cybersecurity in critical infrastructure should be treated like functional safety. Just as safety engineers ask what could go wrong and how to mitigate it, effective cybersecurity teams are applying the same discipline to digital risk. Cybersecurity failures, after all, can directly translate into operational and public health risks.
Stephens added that more than 90 percent of water systems in the US are small and rural, often lacking the budgets and dedicated staff needed for robust cybersecurity programs. A one-size-fits-all security protocol is impractical for the sector. Instead, Stephens said, cybersecurity must be built into everyday operational management in ways that are realistic for small teams to maintain.
Stephens also emphasized the National Rural Water Association's Cybersecurity Circuit Rider Program, which sends experienced personnel directly to small utilities to offer hands-on support and practical advice. This kind of direct, trusted engagement has shown promise over time in helping under-resourced systems steadily strengthen their security posture.
Listen to the full conversation
Collaboration and education go hand-in-hand with technology. Understanding the distinct challenges faced by smaller, rural systems — and providing the right kind of support — is essential to building resilience against cyber threats across water infrastructure all over the world. To hear more of the speakers’ thoughts on the cybersecurity of water/wastewater systems, please visit Podomation or search for “Podomation” wherever you listen to podcasts.
Anyone interested in understanding more about water systems cybersecurity can also register to attend the IC31C course, Cybersecurity Awareness Training for Water/Wastewater Industry Professionals, at this year’s ISA Automation Summit & Expo (ASE). The in-person version of the course will be held 26 September 2026 in Lake Buena Vista, FL. A virtual version of this course will also take place 19 October 2026. Additionally, ASE will include a panel session on the topic of cybersecurity in the water/wastewater industry. You are invited to visit the event website for the full conference agenda.
Ready for the next episode of Podomation?
Make sure to subscribe on your podcast platform of choice to get access to new episodes as soon as they’re ready. Podomation is available on Spotify, Apple Podcasts and many more. If you enjoy these discussions, please leave us a review on any of these platforms. You can also play back episodes here any time.
