
Municipal water systems have become front-line targets in a geopolitical contest most of their operators never signed up for. Three cyber incidents in early August make the point concrete, even though none has been publicly tied to a compromise of water treatment controls.
In California, malicious software disrupted Suisun City’s information technology systems, including 911 routing and police and fire dispatch, forcing the city to rely on Solano County for dispatch support. In Oklahoma, Coweta’s off-site police, fire and 911 systems stayed available while the city recovered from a ransomware attack, along with its website and third-party billing portal. In Wisconsin, Washburn County took county technology offline and routed calls through 911 while assessing and restoring affected systems.
None of these incidents has been identified as a compromise of water controls, operational technology, or the systems that manage physical processes. That distinction matters, but it shouldn’t be read as reassurance. Water utilities don’t operate in isolation from the broader municipal technology environment, and disruption to that environment can cripple how operators communicate, access information, serve customers and recover from an incident, even when the treatment process itself never goes down.
An attacker does not have to reach a pump or controller to disrupt the people, information and processes that keep water service functioning.
These incidents point to two categories of water infrastructure weak spots: technical access points (internet-facing devices, firewalls, virtual private networks) and operational dependencies (communications, identity, billing, records). Defenders need to understand the paths attackers can enter through in municipal environments, which systems are reachable from that foothold, and which dependencies could affect essential services if they become unavailable.
Water operations depend on systems outside the plant
Pumps, valves, programmable logic controllers, and chemical dosing systems remain essential cybersecurity priorities because manipulating them could affect physical operations. However, the people responsible for those systems don’t solely rely on the technology inside the treatment environment. They need workstations and laboratory data, along with maintenance records, customer accounts, vendor connections and municipal identity systems to keep day-to-day operations flowing.
A utility may retain physical control of treatment operations while losing access to systems its staff and customers use every day. Coweta’s externally hosted billing portal remained available while city systems were affected. At Suisun City’s reopened water counter, customers could pay by cash or check while card processing remained unavailable. Neither city reported a compromise of treatment controls, yet both illustrate how architecture shapes the customer impact of a cyber incident.
Pumps, valves, programmable logic controllers, and chemical dosing systems remain essential cybersecurity priorities because manipulating them could affect physical operations
Importantly, just because a treatment process is continuing to run at a water utility, it does not mean the systems that support the people running it cannot fail around them.
Suisun City relied on county dispatch and Washburn County directed calls through 911 routing, demonstrating the value of regional support and alternate communications when internal systems are compromised. Water utility continuity plans should account for the same problem and inform operators how they will communicate, retrieve current information and maintain essential functions when the primary municipal network is down.
The 11-day median leaves little time to respond
Research published by Securin tracks 1,935 vulnerabilities affecting water and wastewater systems, up from roughly 1,800 earlier this year. Of those, 242 have public exploits and 43 have been observed in active attacks.
This is not a story about unknown vulnerabilities. It is a story about known ones that nobody closed in time.
Utilities should prioritize flaws that are externally reachable, exploitable and connected to systems whose loss could disrupt operations. Timing makes that prioritization urgent: the median time from disclosure to observed in-the-wild exploitation is just 11 days. For a smaller utility, that window can disappear before anyone notices it opened. Much of it gets consumed identifying the affected product, locating the device, confirming its version, assessing internet exposure, consulting the vendor and arranging maintenance, all without interrupting service.
A periodic assessment captures conditions at a single moment, but the environment doesn’t hold still until the next one. Devices, configurations, internet exposure and exploit activity all shift in between. Severity scores compound the problem: they don’t establish whether an affected system is publicly reachable, whether working exploit code exists, or what an attacker could reach after gaining access. Those are the conditions that actually determine which vulnerability needs attention first, and they’re exactly what a scanner alone won’t tell you.
Initial access often begins at the edge
In documented water-sector intrusions examined by Securin, initial access frequently occurred through internet-facing devices, firewalls, virtual private networks and remote-access services rather than through direct attacks on plant-floor controls. These systems sit at the network edge and connect utilities with vendors, remote personnel, distributed facilities and the public internet.
A compromised controller can cause serious operational damage, but attackers often need another way in first. An exposed firewall, poorly protected remote-access service or weak credential can provide that foothold. Weak network separation can then allow an attacker to move toward more sensitive systems. An intrusion may also remain within the information technology environment and still disrupt communications, billing, records or employee access.
An intrusion may also remain within the information technology environment and still disrupt communications, billing, records or employee access
This is the part of the attack surface that can be easiest to underestimate. The plant floor is visible as critical infrastructure. The firewall, VPN or remote-access service sitting several steps away may look more like ordinary IT, even though it can become the path to the systems that keep water operations running.
This pattern does not establish how the incidents in Suisun City, Coweta or Washburn County began, because their public notices do not identify the initial access route. It does, however, show why utilities must examine internet-facing systems before an exposure leads to a broader disruption.
Resilience requires continuous visibility
Utilities need to know which assets, remote-access services and vendor connections are exposed to the internet. Public exposure that is no longer needed should be removed, while required access should use multifactor authentication, unique credentials and controlled pathways to keep them protected. Vulnerability priorities should account for working exploits, active attacks, internet exposure and the operational effect of losing the affected system. Meanwhile, critical information technology, operational systems, communications, customer services and backups should be separated so that one compromise does not disable every function. Off-site capabilities and manual procedures also need to be tested under conditions in which the primary network is unavailable.
A common challenge for many smaller utilities is that, while they understand what good cybersecurity looks like, they don’t always have the people, time and visibility to continuously maintain it. Recovery requires a lot of resources. Responders must identify the original access route, remove malicious persistence, rotate compromised credentials, rebuild affected systems from a known-good state and confirm that remediation closed the attacker’s path. Restoring a clean backup while leaving that route open can recreate the same exposure.
With a median of 11 days between disclosure and observed exploitation, smaller utilities may not have the resources to identify, prioritize and remediate every emerging exposure on their own. Suisun City’s reliance on county dispatch shows how regional capability can preserve an essential service when local systems are disrupted.
Suisun City’s reliance on county dispatch shows how regional capability can preserve an essential service when local systems are disrupted
The same model could apply to cybersecurity. A shared state or regional capacity could continuously monitor public-facing assets and alert utilities when vulnerabilities are weaponized or actively exploited. It could also provide remediation and recovery support, including verification that a completed fix actually closed the exposure. Local operators would retain authority over operational decisions, while gaining access to technical capabilities that may be difficult to maintain independently. This is not to replace inside expertise, but to extend it where needed.
A cyber incident can disrupt water service without ever physically reaching a pump or programmable logic controller. Suisun City, Coweta and Washburn County show what happens when municipal technology becomes unavailable, and they’re a warning, not an anomaly. For water utilities, true resilience isn’t just knowing whether treatment controls remain operational. It’s understanding the broader digital environment those controls depend on: what’s exposed, which exposures an attacker can use, what those paths can reach, and whether remediation actually closed them.
Communications, identity, records, billing and remote access aren’t peripheral to water security. They are the operational environment that determines how far a cyber incident can travel and how fast a utility can recover. We will keep shining a light on these gaps until cybersecurity becomes a true priority across the water sector.
