In late July 2026, U.S. water and wastewater utilities reported a sharp rise in cyberattacks aimed at OT devices. These incidents targeted internet-facing components used in operational control, not traditional IT systems, and involved unauthorized remote access to PLCs to change settings and degrade monitoring and control.
Water and wastewater (WWS) services are critical to public health and infrastructure. The sector's size and variety — nearly 50,000 community water systems and more than 16,000 wastewater systems, with most utilities being small and resource constrained — make uniform cybersecurity difficult. A small subset of utilities serves a large share of the population, while the majority operate on limited budgets and staffing.
How digital transformation changed the attack surface
What happened in the July 2026 incidents
NIST's National Cybersecurity Center of Excellence (NCCoE) launched a "Cybersecurity for the Water and Wastewater Sector" project in 2022 with utilities, technology providers, and associations to identify priority challenges and practical mitigations. The NCCoE published NIST SP 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access), which demonstrates how to implement secure remote access for OT environments.
Practical implications for utilities
- Treat connectivity as a design requirement. Network and remote-access features should include built-in security controls rather than being bolted on later.
- Manage risk across people, processes, and technology. Policies, access controls, authentication, staff training, and incident response are as important as device hardening.
- Apply guidance like SP 1800-45 to secure remote access paths to PLCs, SCADA, and HMIs to reduce exposure of internet-facing components.
- Prioritize measures that enable faster detection, containment, and recovery to limit service disruption when incidents occur.
Adapting to different utility sizes
Large utilities often have more resources to implement comprehensive security programs. Small utilities, which make up the majority, face resource constraints and need adaptable, scalable approaches. The NCCoE project emphasized developing practical solutions that can be tailored across a wide range of utility sizes and technical capabilities.
Even with effective cybersecurity, a utility may still face attacks. The goal is to reduce the chance of unauthorized access, shorten detection and response time, limit operational impact, and restore safe water service faster. Implementing secure remote access and enterprise-wide risk management improves operational resilience and helps protect public health services.