• ISA provides technical resources and standards to help industrial automation professionals advance their careers and the field. We enable automation professionals worldwide to solve problems and enhance their skills by bringing people together to create new technologies and share best practices with future automation professionals.
    • Industry Insights

  • We attract over 140,000 unique automation professionals monthly, making us the premier online content provider and the only dedicated electronic magazine in the automation industry.

    Monthly Magazine

    Back
    Back
  • M logo for Automation.com Monthly. Link to current issue.

Securing America’s Water Systems: From Malicious Cyber Activity to Measurable Risk Reduction

By: Michelle Ritterskamp
Source: ISA Global Cybersecurity Alliance
21 September, 2026
4 min read
Two workers with clipboards at a water plant
Recent incidents have accelerated efforts to help water utilities improve their cybersecurity posture. One of the most significant is Project Watershed 250.

Recent cyberattacks against US municipal water systems are once again drawing attention to the cybersecurity challenges facing one of the nation’s most essential critical infrastructure sectors. In July 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) observed malicious cyber activity targeting more than 100 internet-exposed water and wastewater systems in July alone, commonly through programmable logic controllers (PLCs) connected directly to cellular modems.
Water utilities must operate continuously, often relying on a mix of modern digital systems and aging operational technology that were designed for reliability rather than today's connected threat environment. In Steve Mustard’s recent article, he shared that America’s water sector is unique, with a majority of public water systems operating with limited staff, modest budgets and little access to dedicated cybersecurity expertise.  The recent incidents have also accelerated efforts to help water utilities improve their cybersecurity posture. One of the most significant is Project Watershed 250, a six-month initiative launched in Texas on 31 August 2026 by the White House Office of the National Cyber Director, Texas Cyber Command and private-sector partners.
The pilot is intended to test whether industry partnerships can lower costs, deploy new technology and improve operators’ ability to protect their facilities. Texas Cyber Command has described Project Watershed 250 as an effort to move the sector from reactive incident response toward proactive risk reduction and resilience.

 

Understanding what cybersecurity risk means

Even with initiatives like Project Watershed 250, small systems will still need help understanding what cybersecurity risk means in the context of their operations. Without that understanding, cybersecurity can become another collection of technical recommendations or controls that utilities are expected to implement without a clear understanding of what problem each control is intended to solve.
For a water utility, the important questions are therefore not simply, “What vulnerabilities do we have?” or “How many cybersecurity controls have we implemented?” They are questions such as: Could this weakness interrupt water treatment? Could it affect chemical dosing? Could an operator lose visibility or control? Could it compromise water quality, prevent distribution, damage equipment or create a risk to public health?
Each measure should address an identified risk by reducing the likelihood of an event, limiting its potential operational consequences, improving detection and response, or increasing the system’s ability to recover.
A risk-based framework such as ISA/IEC 62443 is sometimes viewed primarily through the lens of standards compliance. Its greater value in this context is the structured, risk-based approach it provides for industrial automation and control system cybersecurity.
The standards do not assume that every water facility faces identical risks or should implement identical cybersecurity measures. A small rural treatment facility and a major metropolitan water system can have dramatically different architectures, resources, threats and potential consequences. ISA/IEC 62443-3-2 provides a structured approach to cybersecurity risk assessment, including defining the system under consideration, evaluating risk, partitioning systems into zones and conduits and establishing target security levels.
This helps answer fundamental questions: What are we protecting? What could happen if it is compromised? Which pathways could an attacker use? What level of security is appropriate? ISA/IEC 62443-3-3 provides system security requirements organized around seven foundational requirements: Identification and Authentication Control, Use Control, System Integrity, Data Confidentiality, Restricted Data Flow, Timely Response to Events and Resource Availability.
Together, these concepts can help move an assessment from simply identifying vulnerabilities toward determining whether the security capabilities needed to address actual operational risk are present and effective.
What does this risk-based approach look like in practice? A project conducted for South West Water in the United Kingdom provides one example. 
South West Water wanted to introduce real-time rainfall information into its SCADA environment to improve operational decision-making and alarm triage. The operational benefits were clear, but bringing an external data source into a critical OT environment also introduced cybersecurity considerations.
Rather than treating the project simply as a technology integration, an ISA/IEC 62443-based cybersecurity assessment was used to evaluate the architecture and associated risks, establish security requirements and identify appropriate compensating controls.
According to the project case study, the approach provided South West Water with a repeatable, standards-based methodology that can be applied to future OT initiatives. Their project will bring continued success long from now if cybersecurity becomes an operational discipline rather than a one-time project. 
For America's water sector, the challenge now is ensuring that limited cybersecurity dollars, personnel and technology are directed toward the risks that matter most.
That means moving beyond counting cybersecurity activities and beginning to measure outcomes: fewer exploitable pathways, stronger controls around critical assets, better operational resilience and faster recovery when incidents occur. Risk-based frameworks such as ISA/IEC 62443 can provide the structure needed to make that transition.

 

Join us to Continue the Conversation at ISA Automation Summit & Expo

 

Prior to the start of the upcoming 2026 ISA Automation Summit & Expo in Orlando, Florida on Saturday, 26 September, Steve Mustard will dedicate an entire day of training on this topic. Cybersecurity Awareness Training for Water/Wastewater Industry Professionals (IC31C) with 0.7 CEU credits with be taught by Steve.
Learning Objectives

  • Identify the recommended standards and best practices for cybersecurity within the water/wastewater industry
  • Identify your organization’s cybersecurity risks using risk analysis techniques
  • Explain the essential and enhanced cybersecurity controls used in the water/wastewater industry
  • Identify questions to ask vendors and contractors about security issues to fully understand issues and what is provided

To register to attend, visit the training website. A virtual session will also be conducted on Monday, 19 October 2026. 
If a full-day course is not an option for you, but you are attending ASE, do not miss the Monday, 28 September panel at 10:45 – 11:30: Cybersecurity in US Water Systems: Lessons from the Recent Incidents with Moderator Marco Ayala and panelists, Steve Mustard, Chad Paxson, Graham Nasby and John DeGour.

 

Other Resources:

 

 

 

 

Previous Column Article Next Column Article
Advertisement

Trending Articles

Advertisement

Related Articles

View all Articles and News
Advertisement
Advertisement