Drinking water and wastewater systems are increasingly at risk of malicious cyber activity. Since July 27, 2026, water and wastewater systems in at least seven states have reported malicious cyber activity to the FBI, with more than thirty coordinated attacks occurring in Minnesota alone. Several plants across Minnesota reported plant outages, communication failures, and locked automated controls, leading to cities like Braham to request that residents reduce their water usage until operations resumed.
Who’s At Risk?

Over 30 Minnesota water utilities were targeted in a coordinated cyber-attack via remote access of Rockwell MicroLogix 1400 and 1600 Controllers. Photo Credit © Corina Ciocirlan’s Images via Canva.com (left) and RockwellAutomation.com (right)
While these particular attacks impacted only a specific type of operational technology, called a programmable logic controller (PLCs), any hardware or software that is remote controlled or connected to a network carries a cybersecurity risk. Operational technologies like SCADA (supervisory control and data acquisition systems) are responsible for monitoring and automating the daily operations of water and wastewater systems. When impacted by cyberattacks, treatment and distribution devices such as sensors, valves, pumps, and motors can be affected, and sensitive data can be breached. Water storage, building management systems, and fire detection systems can also be impacted.
The Weakest Link
Updating system components like PLCs, drives, and software can improve security capabilities, but they are not a silver bullet for preventing cyberattacks. That’s because people remain the weakest link in the cybersecurity chain. In 2024 alone, over 90% of cybersecurity incidents were linked to phishing emails, weak or limited password protections, and internet-exposed publicly accessible operating systems. Without cyber-secure behavior on part of staff and other personnel, even the most advanced technologies can fall victim to hackers.
Cybersecurity Culture
Investment in cyber-secure behavior is a key component to preventing malicious cyberactivity and reducing the impact, cost, and time spent recovering from an attack. For small systems, this means making cybersecurity a responsibility of all personnel, rather than that of a single staff person. Utilities with a strong cybersecurity culture commonly discuss cybersecurity policies, incentivize cyber secure behavior, and empower all personnel to be responsible for system security.
Voluntary and regulatory cybersecurity standards are increasing, and water utility managers and operators are faced with increasing pressure to establish cybersecurity programs, designate personnel, and conduct reporting. By focusing on cybersecurity culture, managers and operators can proactively strengthen the security of their system. Practicing cyber awareness early allows water and wastewater systems to stay ahead of state or federal amendments, making cybersecurity measures easier to adopt and implement when they’re mandated in the future. Here are three ways to cultivate a culture of cyber awareness so your system stays ready.

The first step to cultivating a culture of cyber awareness is to establish a Culture Leader, a responsible staff person who demonstrates best practices and promotes cyber secure attitudes. Photo Credit: © momcilog via Canva.com
Three Ways to Create a Culture of Cyber Awareness
- Designate A Culture Leader: A culture leader is responsible for sharing best practices or lessons learned. The culture leader activates recurring conversations about cyber awareness and sets an example for cybersecure attitudes and behavior. The culture leader is “bilingual” and uses non-technical language that resonates with all personnel. Ideally, they are a member of management, not a technical staff person.
- Incentivize Behavior and Knowledge: Organizational behavior is elevated by leadership, and personnel who demonstrate good cyber behavior are highlighted as “heroes.” In a more developed cybersecurity culture, employees are formally evaluated based on their cybersecurity performance. Operators are encouraged or required to complete cybersecurity training as part of their Continuing Education Units (CEUs).
- Conduct Drills and Exercises: Organizations regularly assess their cyber resilience by rehearsing cyberattacks and practicing manual controls. Technical and non-technical personnel are clear on cybersecurity protocols and procedures, including incident reporting. A physical copy of the Cybersecurity and Infrastructure Security Agency (CISA) Tabletop Exercise Manual is available at the utility and is referenced often for “cyber-drills” or tabletop exercises.
Take The First Step
As cyber threats to water and wastewater systems continue to grow, a utility’s strongest defense is a workforce that understands and practices cyber-secure behavior every day. By fostering a culture of cyber awareness through leadership, cyber-secure attitudes, and regular preparedness exercises, water and wastewater systems can strengthen resilience, reduce risk, and better protect the critical services our communities depend on.
Don’t wait for a cyber incident or new regulations to build your cyber-resilience. Request free, customized support now from our team of experts at https://efcnetwork.org/get-help/. EFCN offers technical assistance to water and wastewater systems, with a commitment to small, rural and tribal systems that are most vulnerable to cyber risks.
More Cybersecurity Insights From EFCN:
Cybersecurity: How to Start – Environmental Finance Center Network
Additional Resources:
2024 Roadmap to a Secure and Resilient Water and Wastewater Sector | US EPA (https://www.epa.gov/waterresilience/2024-roadmap-secure-and-resilient-water-and-wastewater-sector)
EPA Cybersecurity for the Water Sector | US EPA (https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector)
Water and Wastewater Cybersecurity | CISA (https://www.cisa.gov/water)
Cybersecurity & Guidance – American Water Works Association (https://www.awwa.org/resource/cybersecurity-guidance/)
