The problem

Critical infrastructure, chronically under-defended.

America's drinking water and wastewater systems are targets of active nation-state and criminal cyber campaigns. The systems most at risk are also the least resourced — the small and rural utilities that serve most of the country.

Water and wastewater are uniquely vulnerable.

Critical infrastructure — water, electricity, transportation, even military bases — is under sustained attack from state-sponsored actors and cybercriminals. Water and wastewater systems are especially exposed: an EPA study found over 70% of inspected water systems in 2024 failed to meet basic cybersecurity standards. Because water systems interconnect with other critical sectors, a successful attack could cascade into hospitals, power stations, and military bases. With more than 90% of U.S. water systems classified as small (serving 10,000 people or fewer) and often rural and under-resourced, water remains an especially attractive target.

Utilities run a mix of business IT (billing, email, SCADA workstations) and operational technology (PLCs, HMIs, chemical dosing controls) that was never designed to be exposed to the modern internet — but often is.

Four root causes.

Each of these is a structural barrier — not a failure of any single utility or operator.

01

De-prioritized by funding

Cybersecurity competes with pipe replacement, treatment upgrades, and staffing on already-thin utility budgets. It routinely loses.

02

No local capacity

Most small systems have no dedicated IT staff, let alone a security team. The operator wears every hat.

03

Slow federal response

Regulatory and grant timelines move in years. Attackers move in minutes.

04

A trust gap

Outside cyber experts often don't understand water operations — and operators, rightly, don't hand keys to strangers.