Nist iconNistOct 1, 2026 ~6 min source read

Securing Water and Wastewater Operational Technology Environments

Recent attacks targeting operational technology in U.S. water and wastewater systems show connectivity must be designed and operated with security as a core priority. NIST’s NCCoE offers practical guidance, including SP 1800-45 for secure remote access.

Securing Water and Wastewater Operational Technology Environments

Share this story

Send the public story page.

Useful takeaways from this story.

Threat actors in July 2026 specifically targeted internet-facing OT components and remotely accessed programmable logic controllers (PLCs) to alter settings and disrupt operations.

Effective protection requires managing risk across people, processes, and technology, and designing connectivity with security as a primary requirement rather than an afterthought.

NIST NCCoE published NIST SP 1800-45 to demonstrate secure remote access for OT and help utilities limit impact, respond faster, and restore operations.

In late July 2026, U.S. water and wastewater utilities reported a sharp rise in cyberattacks aimed at OT devices. These incidents targeted internet-facing components used in operational control, not traditional IT systems, and involved unauthorized remote access to PLCs to change settings and degrade monitoring and control.

Water and wastewater (WWS) services are critical to public health and infrastructure. The sector's size and variety — nearly 50,000 community water systems and more than 16,000 wastewater systems, with most utilities being small and resource constrained — make uniform cybersecurity difficult. A small subset of utilities serves a large share of the population, while the majority operate on limited budgets and staffing.

How digital transformation changed the attack surface

What happened in the July 2026 incidents

NIST's National Cybersecurity Center of Excellence (NCCoE) launched a "Cybersecurity for the Water and Wastewater Sector" project in 2022 with utilities, technology providers, and associations to identify priority challenges and practical mitigations. The NCCoE published NIST SP 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access), which demonstrates how to implement secure remote access for OT environments.

Practical implications for utilities

  • Treat connectivity as a design requirement. Network and remote-access features should include built-in security controls rather than being bolted on later.
  • Manage risk across people, processes, and technology. Policies, access controls, authentication, staff training, and incident response are as important as device hardening.
  • Apply guidance like SP 1800-45 to secure remote access paths to PLCs, SCADA, and HMIs to reduce exposure of internet-facing components.
  • Prioritize measures that enable faster detection, containment, and recovery to limit service disruption when incidents occur.

Adapting to different utility sizes

Large utilities often have more resources to implement comprehensive security programs. Small utilities, which make up the majority, face resource constraints and need adaptable, scalable approaches. The NCCoE project emphasized developing practical solutions that can be tailored across a wide range of utility sizes and technical capabilities.

Even with effective cybersecurity, a utility may still face attacks. The goal is to reduce the chance of unauthorized access, shorten detection and response time, limit operational impact, and restore safe water service faster. Implementing secure remote access and enterprise-wide risk management improves operational resilience and helps protect public health services.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app