September 15, 2026
Executive Summary
Recent cyber activity involving water and wastewater systems underscores the need to connect operational technology (OT) cybersecurity to operational consequences in the water utility sector. While reducing internet exposure, strengthening access controls, and addressing vulnerabilities remain essential, reducing risk effectively also requires understanding how affected equipment functions within the broader water and wastewater treatment process. Internet-exposed programmable logic controller (PLC) vulnerabilities can pose different risks depending on system architecture, safeguards, instrumentation, procedures, and operator response.
By applying cybersecurity methods such as threat modeling alongside engineering risk techniques, utilities can better assess loss of function and trust in operating information and shared digital dependencies — and prioritize targeted, cost-efficient actions that help protect critical services.
How can utilities connect cyber events to operational consequences and strengthen resiliency?
Reliable access to drinking water and wastewater services is fundamental to a functioning and healthy society; increasingly, it is an issue of national security as well. Per warnings from the Cybersecurity and Infrastructure Security Agency (CISA), water and wastewater utilities may be targets for cyberattacks on programmable logic controllers (PLCs) and related operational technology (OT) systems, which enable monitoring and controls for water and wastewater operations and quality.
Why are water and wastewater utilities at risk?
Aging infrastructure and control systems, including smaller or less sophisticated systems, can contribute to a water or wastewater utility's cyber vulnerabilities. So can remote equipment maintenance, configuration changes that are not coordinated with downstream treatment impacts, and staff who may be unfamiliar with advanced PLC functions. The consequences of a breach, ranging from plant flooding or raw sewage overflows to loss of process control and ongoing water quality issues — including, for drinking water systems, system flushing, boil-water advisories, or do-not-use orders that extend beyond the cyberattack itself — can harm public health and confidence in a utility's critical services.
It's common for water and wastewater utilities to perform cybersecurity assessments after systems are fielded and operational. Assessments typically focus on identifying vulnerabilities and understanding exposure at the asset level, such as an externally accessible controller, an unsupported operating system, weak authentication, or an unpatched device. Simply identifying a vulnerability, however, does not establish its potential consequence to the utility, risking lost insight into how a component-level weakness could affect critical system functions.
How can water and wastewater utilities take a more effective approach?
Utility engineering analyses that draw from both domain-specific and cybersecurity expertise often begin from another perspective. Foundational methods such as failure modes and effects analysis (FMEA) consider how failures of components or functions can affect the performance of the larger system. These analyses consider not only known failure history but also credible ways components or functions could fail. Ideally, knowledge of vulnerabilities and consequences across other sectors and industries can enhance how threats are identified that may not have been previously considered and set the stage for more advanced modeling.
To examine cyber risk through an engineering lens, water and wastewater utilities can begin with the adverse operational conditions they seek to prevent — for example, a loss of pressure or process control, improper treatment, or an inability to verify a critical process parameter.
Operators can then trace the systems and functions that could contribute to a negative outcome, identify the safeguards in place to prevent or mitigate that outcome, and assess what could happen if those safeguards fail, including safety, financial, and reputational risks. In a cyber context, this analysis means considering the relationship between a cyber event, a resulting loss or manipulation of a function, the effect of that functional loss or manipulation on the treatment system, and the response of engineered safeguards and operators.
An FMEA approach also adds operational context that may not be apparent from the severity of a vulnerability alone. For example, two facilities using the same PLC model with the same vulnerability may have very different risk profiles. At one facility, independent process instrumentation may provide operators with reliable information indicating whether the control system is unavailable; physical interlocks may constrain unsafe process conditions; and personnel may routinely exercise local operating procedures, enabling protections that help prevent unsafe conditions or maintain operations if a threat is detected.
At the second facility, process visibility and control may rely more heavily on the same digital systems affected by the vulnerability, limiting awareness and efforts to prevent serious safety, reliability, and financial impacts before they occur. Essentially, the technical weakness of the PLC may be identical, but the potential consequences of its compromise are not. The surrounding system determines whether a given failure condition can occur, how far it can propagate, and how effectively the facility can respond.
Understanding external hazards and their variability is critical, as total loss can be amplified when a cyber event coincides with peak demand or extreme weather. Optimally, an engineering-based utility assessment could leverage additional analyses to quantify risk or model the full scale of a cyber threat's impacts relative to potential concurrent factors.
What does it mean to lose function as well as trust in system data?
Cyber-induced failure conditions can also differ from the equipment failures traditionally considered in reliability analyses. While some instrument failures result in observable evidence, a compromised digital system may continue to operate and provide information that appears to be credible. As a result, an operator may encounter difficulties that extend beyond the simple loss of a controller or display — for example, when equipment remains available but its output can no longer be assumed to represent physical processes accurately.
Understanding cascading cyber impacts is particularly important in control environments where operators rely on instrumentation and human-machine interfaces (HMIs) to understand water and wastewater operational conditions and determine appropriate actions. If an HMI reports that a valve is closed, the response to an abnormal condition may depend on whether that indication can be independently confirmed. Similar questions arise for process measurements such as level, flow, pressure, and chemical concentration.
For critical functions, determining how operators establish the current status of a process is useful if portions of the control environment become untrustworthy. Independent verification may involve redundant instrumentation, local indications, physical inspections, or other means of confirming important conditions, bringing a cyber assessment together with ground-truth engineering insights and domain expertise. Importantly, a comprehensive analysis isn't limited to asking whether an automated system can continue operating; it includes asking whether personnel retain sufficient reliable information to understand and control the treatment process and critical equipment.
Evaluating whether redundancy is truly independent
Water and wastewater utilities commonly use redundant equipment and alternate operating paths to reduce the consequences of component failures. A second pump, backup controller, alternate communications path, or redundant instrument may provide meaningful protection against a mechanical or electrical failure, but cybersecurity can complicate assumptions about redundancy. The key question is whether a backup is independent of the same cyber failure modes that could affect the primary function.
Although safety and reliability analyses often consider common-cause failures, they may not identify cyber-specific shared dependencies unless supported by a structured cybersecurity analysis. Under a cyber scenario, dependencies can create common failure mechanisms across systems that otherwise appear independent.
For example, primary and backup controllers may be configured from the same engineering workstation or administered using the same credentials. Communications systems that appear independent at the physical layer may use common remote-access or identity infrastructure. Multiple devices may rely on the same software, configuration management environment, or external service. These relationships do not make the redundant design ineffective; they mean that the independence assumed for one class of failure may not necessarily apply to another.
Conventional reliability analysis and cybersecurity analysis can complement one another by assessing not only whether backup capability exists but whether the primary and backup functions remain sufficiently independent under the potential failure conditions. For example, an architectural drawing may document physical separation between two systems, while an examination of digital and administrative dependencies may identify connections that are not evident from the design.
Extending existing engineering assumptions to cyber conditions
Engineering evaluations depend on assumptions about system behavior, which are commonly addressed through design requirements, inspection, maintenance, testing, and operating procedures. A standby pump is assumed to start when the primary pump stops operating as expected. An alarm is expected to reach the operator.
Increasingly, modern utility system operations also depend on assumptions about digital functions. Controller logic is assumed to reflect the approved configuration. Information displayed to an operator is assumed to correspond to actual process conditions. Recovery files are assumed to be correct and available.
A thorough cybersecurity assessment examines those assumptions explicitly. For some facilities, this evaluation may be performed by analyzing architecture, failure modes, operating procedures, and system dependencies. In other cases, exercising an operational scenario may provide additional information. For example, a facility might consider how operators would respond if a critical controller or HMI became unavailable or if its information could no longer be trusted. The purpose is not necessarily to simulate a sophisticated cyberattack but determine whether the engineering and operational capabilities expected to limit consequences remain available when the initiating failure is cyber rather than mechanical.
Dealing with real challenges of cyber risk model development and reporting
The difficulties of creating accurate, defensible, and decision-ready models for utility cybersecurity risk are not just conceptual; they are rooted in well-documented properties of cyber loss data that challenge the assumptions underpinning most models. Consequences can easily be amplified for water or wastewater utilities that are already dealing with aging assets and constrained resources.
A few critical areas to keep in mind include:
- Systemic and interconnected exposure: Cyberattacks rarely happen in isolation because utilities rely on common vendors, platforms, or providers; a single vulnerability can trigger simultaneous outages across an entire sector. However, assumptions of independence are pervasive in risk models, mostly because they drastically simplify the analysis. Assuming cyber events are independent can severely underestimate both the likelihood of events and their impacts.
- Limited and biased data: Cyber incidents are historically underreported and inconsistently recorded, leaving organizations with sparse, incomplete datasets. Minor events are often ignored, while catastrophic events are extremely rare. In addition, combining data from different sources often amplifies these biases rather than fixing them, making it difficult to establish a reliable baseline for risk. Even the taxonomies of what "counts" as an event shift over time due to regulatory guidance, internal priorities, or other factors.
- A constantly shifting risk landscape: Cyber threats, defensive technologies, and regulatory requirements evolve faster than traditional risk models can adapt. Attacker methods and target environments change so rapidly that historical loss data quickly become outdated. Relying strictly on past data (time, place, asset base, OEM, architecture, etc.) to predict future cyber losses is inherently limited.
- Extreme impact potential (tail risk): Cyber losses are driven by rare, severe events rather than routine, minor incidents. In critical sectors like water and wastewater treatment, a worst-case scenario — such as a facility shutdown or contamination event — can cause widespread harm and loss of public confidence. Because historical data contain very few of these extreme events, a single new incident can dramatically skew financial risk projections. Utilities need to clearly understand both the relevance and the stability of their tail risk.
- Mitigation quantification: Beyond the challenges of estimating cyber risk exposure, utilities can benefit from rigorous understanding of how effective commensurate mitigations and controls are, supported by established engineering and analytical methods (e.g., SME calibration, Lens Models), to justify capital investments. Many of these methods can be implemented quickly and efficiently.
As part of good governance and analytical practices, utilities can establish robust, independent risk management and validation practices for the models they use to communicate risk to stakeholders and their boards. Applying best practices provides confidence that models provide relevant and reasonable estimates of cyber losses with clearly communicated uncertainty, documented assumptions, and defensible and repeatable processes. A strong analytical approach can embrace the significant uncertainties associated with cyber risk rather than avoid them.
Using operational risk to inform cybersecurity priorities
None of these considerations replace fundamental operational technology (OT) cybersecurity practices. Utilities can continue to reduce unnecessary external exposure, control remote access, strengthen authentication, maintain appropriate network segmentation, and address vulnerabilities according to risk.
A risk-based engineering approach can, however, help focus on the cybersecurity characteristics that are most likely to impact plant operation. Eliminating an unnecessary external connection may interrupt a direct pathway to a critical control function, for example, but greater risk reduction could come from providing independent process indication, separating recovery resources from the operational environment, or addressing a shared dependency between primary and backup functions.
By establishing a stronger technical basis for prioritization, risk-based engineering analyses connect the cybersecurity conditions to the functions the utility is trying to protect. These analyses help make cybersecurity part of normal engineering decision making: system modifications can be reviewed for new digital dependencies, redundant designs for common cyber failure mechanisms, and emergency procedures for whether required information and control capabilities would remain available during a cyber-induced disruption.
Recent CISA warnings about PLC-targeting in the water sector reinforce the importance of basic OT cybersecurity controls and show why asset-level findings are only part of operational risk. A more complete assessment considers how a cyber-induced failure could propagate through the physical system, which safeguards are expected to limit its effects, and whether those safeguards remain effective when digital systems are unavailable or unreliable.
What Can We Help You Solve?
Exponent's cybersecurity and utilities experts help organizations connect cyber vulnerabilities to operational consequences across water and wastewater systems. By assessing threats, safeguards, hardware, software, and data pathways, we help utilities protect critical services, improve resilience, and prioritize risk-reduction efforts in high-consequence operating environments.
Water Consulting
Exponent's multidisciplinary scientists bring decades of experience and unparalleled water resources expertise to guide complex, high-stakes decision-makin...
Cybersecurity Consulting
Learn how Exponent's computer scientists, data scientists, and security experts can help make systems safer and more secure.
Wastewater Consulting
Unparalleled technical expertise to help municipal and industrial operations manage risk, resolve issues, and move forward with confidence.
Hydropower Consulting
Harness hydroelectric power to support a successful sustainable energy transition strategy
Insights