MORE TOPICS | Cybersecurity
Rough Water Ahead
Artificial intelligence and the new face of water system risk.
Jack Danahy | NuHarbor Security
Water systems have always been critical infrastructure, but for most of their history, threatening them required physical access. Pumps, valves and treatment systems sat behind locked doors, and the computers controlling them connected to nothing outside those walls.
That description no longer fits most American water utilities. A decade of remote monitoring, AI-assisted maintenance, contractor portals and automated reporting has connected previously isolated systems to the internet. The efficiency gains are meaningful, but the systems that enable them also leave utilities more exposed.
A new generation of AI-accelerated tooling is changing the likelihood and speed of exploits and is now a new addition to resiliency planning. AI-accelerated exploits of code at industrial scale are now within reach, and the cost to do so has dropped by an order of magnitude in five years.
Water systems sit at the intersection of these two developments. They are evolving to a more interconnected attack surface, and AI tools have stripped away the skill, time and cost once required to threaten it. That demands a different approach to water system cybersecurity.

| IMAGE 1: Pumps are a critical component in water and wastewater treatment plants and must be protected from cyber threats. Implementing cyber hygiene and best practices within IT networks can protect water and wastewater management systems from cyberattacks. (Photo credit: Adobe Stock)
The Wall That Came Down
AFor most of their history, water systems ran on isolated computers in an operational technology (OT) environment that included the hardware and software that opens valves, measures pressure and flow and lets operators watch a system from one screen. Utilities avoided connecting OT to the untrusted internet, and isolation and airgaps were fundamental to the security model.
In the same organization, standard information technology (IT) ran billing, email and regulatory reporting. IT connected to the internet. OT did not, and different groups, with different charters and expectations, often ran IT and OT separately.
That gap no longer exists in most modern water systems. Remote monitoring, AI-assisted maintenance and real-time reporting all require a blended IT and OT environment.
The U.S. Government Accountability Office made this point in May testimony before Congress. Its report on the nation’s 170,000 water systems named IT/OT convergence as a primary driver of vulnerability and noted that the Environmental Protection Agency (EPA) lacks the authority to require any minimum cybersecurity standard across those systems.1 There is no requirement to address these gaps, and the result is not funding, consensus or pressure to do so.
Artificial Intelligence on Both Sides
Two AI-driven developments are defining the change attack landscape.
The first comes from adversaries. AI tools have lowered the skill once required to attack industrial control systems, and attackers are capitalizing. In April, the EPA joined the FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) in a joint advisory documenting active exploitation of internet-exposed operational technology by Iranian-affiliated groups. These groups wiped configurations, disrupted physical system monitoring and forced utilities into manual operations.2 Manual operations only suffice until a utility faces a combined set of events that overrun the staff’s capability to cover.
The second development comes from inside utilities’ own procurement decisions. In June, the EPA and the Water Information Sharing and Analysis Center documented cases where AI providers requested full historical logs from supervisory control and data acquisition (SCADA) systems including flow rates, storage levels and equipment run-times.3 That data has real value for legitimate AI applications, but it is also a detailed map of every fragile point in a water system.
Consider that the American Water Works Association’s 2026 State of the Water Industry Report found that 49% of utilities have no active policy governing AI use,4 and nearly half the sector has no framework to enforce appropriate access and exposure through these new systems.

| IMAGE 2: Safe drinking water and reliable wastewater treatment are essential to public health, community resilience and daily life. Good cybersecurity posture means taking a comprehensive view of all IT and OT systems. (Photo credit: Adobe Stock)

| IMAGE 3: Monitoring assets for malicious activity is essential to ensuring systems are not compromised. (Photo credit: Adobe Stock)
The Failure That Looks Like Nothing
A dangerous cyberattack on a water utility does not need to be dramatic. An attacker who gains access to a SCADA network does not need a visible event to cause real harm. Locking operators out of remote access forces manual operations on a system expected to run automatically, while that loss of remote control creates situations that no single operator can manage firsthand.
Similarly, an attacker who subtly degrades sensor accuracy can cause operators to misread conditions across a transmission main. Undetected overpressure damages infrastructure, and undetected underpressure can mask a failure that has already happened. Either way, the water is moving, but the operator cannot trust what the system says about it.
What Utilities Can Do Now
Map the exposure: In June, the National Cybersecurity Center of Excellence published National Institute of Standards and Technology (NIST) Special Publication 1800-45, a free, lab-tested guide for securing remote access to operational technology, covering utilities of every size, including those without a dedicated cybersecurity team.5
Govern AI access to operational data: The EPA’s cybersecurity procurement checklist gives utilities a vendor evaluation framework. Every AI platform with access to SCADA data deserves that evaluation. Good governance just requires a decision about what data leaves the system and under what conditions.
Practice the failure before it arrives: The EPA and CISA offer free tabletop exercises built for water systems.6 Running the scenario, control locked, on manual and at peak demand before the incident happens is the most cost-effective preparedness investment a small utility can make.
Ultimately, Resilience Pays for Itself
These three actions require resources, and leaders must justify that cost to boards, councils and ratepayers. A recent industry analysis makes that case directly: Cybersecurity resilience is not an expense. It is an investment with a measurable financial return.
A cybersecurity upgrade framed as risk avoidance competes for budget against pipes and pumps, and it often loses. Framed as a resilience investment with a calculable return, it competes on equal terms.
The financial sector is pricing this in. Credit agencies, bond brokers and insurers increasingly factor in digital resilience. The insurer FM recently issued nearly $1 billion in resilience credits, lowering premiums for clients who invest in preparedness.7
A utility that secures its operational technology, governs AI access to its data and rehearses its incident response protects more than its water supply. It protects its bond rating and its insurance costs.
References
- U.S. Government Accountability Office, GAO-26-109159, Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector (May 2026).
- EPA/FBI/CISA/NSA Joint Cybersecurity Advisory on Iranian-Affiliated Cyber Attacks on Water Systems (April 2026).
- EPA/WaterISAC Advisory on Safeguarding Sensitive Operational Information (June 2026).
- American Water Works Association, 2026 State of the Water Industry Report (April 2026).
- NIST Special Publication 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (June 2026).
- EPA Cybersecurity Incident Response Plan Template (October 2025).
- Andy Bochman, “For Water Utilities, Resilience Pays,” Journal AWWA, June 2026 (David White/Axio quote, resilience ROI framing, FM resilience credits).
Jack Danahy is executive security advisor for NuHarbor. He may be reached at jack@danahy.com. For more information, visit nuharbor.com.
In This Issue

