Water system cyberattacks: How municipalities can protect critical infrastructure
- Public water systems have experienced a rash of cyber incidents. Attackers are targeting internet-facing industrial control devices that operate critical infrastructure.
- Municipalities face unique cybersecurity challenges, including limited budgets and staffing, aging technology, increased connectivity and a lack of mandated cybersecurity standards.
- Attackers commonly exploit vulnerabilities in systems exposed to the internet, employee mistakes and physical security weaknesses to access municipal networks. Once on the internal network, they can move through the environment, disrupt operations, steal data or disrupt critical infrastructure systems such as water treatment and pumping stations.
- A proactive cybersecurity strategy is essential and should include network segmentation, continuous monitoring, secure remote access, penetration testing, multi-factor authentication, employee training and well-tested incident response and disaster recovery plans.
Municipal water systems have become a prime target for cyberattacks. In July, the FBI and the EPA warned that attackers targeted water and wastewater utilities in at least seven states. In Minnesota, more than 30 community water systems were targeted.
In these incidents, internet-exposed industrial control devices that operate critical infrastructure were targeted. By accessing these devices remotely, attackers were able to change passwords and network settings, disrupting visibility and control of critical equipment. The attacks have resulted in some flooding and a loss of water pressure.
The water system cyberattacks are a reminder that municipalities and the critical infrastructure they manage are common targets for malicious actors. Keep reading to learn more about the threats facing local governments and for cybersecurity best practices that can mitigate the risk of an attack.
Why are municipalities vulnerable to cyberattacks?
Like any organization, municipalities face a constant threat of cyber incidents. But they often have to manage that risk with fewer resources.
Several factors make local governments vulnerable to attacks, including:
- Limited budgets and staffing: Municipal IT teams are often asked to manage complex environments with constrained funding and limited cybersecurity experience.
- Lack of regulatory requirements: Many industries, including some utilities like the electric grid, must comply with stringent federal cybersecurity requirements. But there are no federal standards municipalities must meet. This lack of regulatory oversight can result in cybersecurity being underprioritized.
- Aging infrastructure: Critical systems may rely on decades-old technology that was designed for operational efficiency rather than cybersecurity. In many cases, outdated software may no longer be able to be patched, creating additional vulnerabilities.
- Growing connectivity: Water treatment plants, power systems and traffic management systems increasingly use internet-connected tools for monitoring and remote management, creating more potential entry points for attackers.
- Disjointed operations: Municipal departments often manage technology independently, making consistent cybersecurity governance more difficult.
What makes water systems especially vulnerable?
Water systems are particularly susceptible to cyberattacks for several reasons, including:
- Water utility personnel often lack the cybersecurity knowledge needed to secure increasingly complex operational technology environments.
- Many water systems rely on outdated software and hardware that may no longer be supported by manufacturers. These systems often cannot be easily upgraded because newer operating systems may not be compatible with critical control equipment.
- Water infrastructure is often spread across large geographic areas, making it harder to maintain consistent security practices and oversight.
- Remote management tools may lack security controls, leaving weaknesses that attackers can exploit.
Why are municipalities common targets?
Cybercriminals, especially those from adversarial nations, target municipalities because successful attacks can create immediate and highly visible disruptions. Interrupting water service, electricity, transportation systems or public communications can affect thousands of residents at once.
Beyond disruptions to daily life, politically motivated attackers are looking to sow discontent within our communities and nation. If water isn’t running or is unsafe to drink, or if other utilities aren’t functioning as expected, it can cause political unrest.
Who is behind attacks on municipalities?
Two common perpetrators of cyberattacks directed at local governments are:
- Nation-states: Public infrastructure often attracts interest from foreign adversaries looking to gather intelligence, disrupt services or test capabilities against critical infrastructure. Multiple federal agencies have warned that foreign cyber actors continue to target U.S. infrastructure.
- Ransomware groups: These are organized cybercriminal syndicates that lock or encrypt a victim’s computer systems and data, then demand large payments to restore access. Many ransomware groups are fronted by national adversaries.
What methods are used to attack municipalities?
Common attack methods that municipalities need to be aware of and prepared to defend against include:
Exposed internet-facing systems
A common attack path is to exploit known vulnerabilities in systems directly accessible from the public internet. This can include remote access portals, industrial control systems, servers, firewalls or other devices that are accessible from outside the municipal network.
Cybercriminals continuously scan the internet for systems running outdated software or misconfigured services. A vulnerable device left exposed is an easy target for an attacker. Once inside, they may steal data, move laterally through the network, deploy ransomware or attempt to gain access to critical infrastructure systems.
Social engineering
Social engineering attacks trick employees into revealing sensitive information, sharing credentials or bypassing security controls. Phishing emails remain one of the most common examples. An attacker may pose as a trusted vendor, coworker or government agency to convince an employee to click a malicious link, open an infected attachment or enter login credentials into a fraudulent website.
With valid credentials, attackers can often access the same systems and data that employees do. If additional security weaknesses exist within the network, they may be able to escalate privileges and gain access to more sensitive systems.
Physical attacks
Physical access remains a serious cybersecurity risk, especially for municipalities that manage numerous facilities and remote infrastructure locations.
Attackers can attempt to connect unauthorized devices directly to the network. Methods include plugging specialized hacking tools into a computer or an unused network port, installing a rogue wireless access point or leaving infected USB drives where employees are likely to find them.
Once a malicious device is connected behind the municipal firewall, attackers may be able to establish remote access, monitor network activity or steal credentials without immediately being detected.
What steps should municipalities take to improve cybersecurity?
There are many elements to a strong cybersecurity posture. Actions your municipality can take to improve its defenses against cybersecurity include:
Segment industrial control systems from office networks
Your industrial control system (ICS) environments need to be separated from your office networks. Network segmentation prevents attackers who gain access to an employee workstation or email account from moving laterally into critical infrastructure systems.
Implement continuous security monitoring
Real-time monitoring can help identify and alert you to any suspicious behavior and potential attacks, so you can investigate and respond before a security event escalates into a major disruption. Security monitoring can be handled internally with a dedicated security operations team, or through a third-party vendor.
Review and secure remote access
Remote access is often a necessity for municipal operations, but it can also become a major vulnerability if not properly managed. Municipalities should regularly review all remote access pathways, remove unnecessary connections and enforce strong controls over systems accessible from outside the organization’s facilities. Access should be limited to approved users and approved devices, with ongoing monitoring of remote connections to identify unusual activity.
Penetration testing
Penetration testing provides a proactive way to identify vulnerabilities by simulating real-world attack scenarios before they are exploited. These assessments can reveal exposed systems, weak configurations, inadequate access controls and other issues that may not surface during routine IT operations. Regular testing helps municipalities validate whether security controls are working as intended.
Strong authentication controls
Multi-factor authentication (MFA) and strong password requirements remain foundational defenses against credential theft and unauthorized access.
Adopt a cybersecurity framework
A formal framework provides structure for building and maintaining a cybersecurity program. NIST CSF can be an effective starting point because it focuses on core cybersecurity outcomes and risk management. For more detailed technical guidance, municipalities can use the CIS Critical Security Controls or DISA Security Technical Implementation Guides (STIGs). Using an established framework helps organizations prioritize efforts, measure progress and ensure security initiatives align with industry best practices.
Patch and update systems
Establish a process for regularly updating operating systems, applications, network devices and security tools. Legacy systems that cannot be patched should be identified, documented and protected through compensating controls such as network isolation, restricted access or enhanced monitoring.
Invest in employee training
Human error is the biggest cybersecurity vulnerability. It’s essential to provide your staff with regular training on how to recognize suspicious emails, verify unusual requests and report potential incidents. Promoting skepticism can help employees pause and validate requests before taking actions that could compromise security.
Maintain secure backups
Backups remain one of the most effective defenses against ransomware. Municipalities should maintain secure, regularly tested backups of critical systems and data. Backups should be immutable, meaning they cannot be modified. This helps ensure clean recovery options remain available even if production systems become compromised.
Develop and test incident response plans
If a cyber incident occurs, there needs to be a plan in place to prevent confusion and further mistakes that compound the issue. Municipalities should have a documented incident response plan that clearly outlines roles, responsibilities, communication procedures and escalation paths. Regular tabletop exercises help staff practice their response, identify gaps and build confidence so they can act quickly during an actual event.
Create a disaster recovery strategy
An incident response plan focuses on managing the attack itself, but you also need a roadmap for restoring operations afterward. A disaster recovery plan should define recovery priorities, acceptable downtime, backup restoration procedures and contingency operations. For critical services like water and wastewater treatment, planning for operational continuity needs to be a priority.
Hire outside help
Many cities and towns lack the budget to hire a cybersecurity professional. External advisors can help assess security posture, identify vulnerabilities, validate compliance with security frameworks, implement monitoring solutions and support remediation efforts. Third-party services can provide municipalities with capabilities that are difficult or costly to maintain internally, allowing them to strengthen security without significantly expanding staff.
How Wipfli can help
Wipfli helps municipalities strengthen cyber resilience through comprehensive security assessments, penetration testing and security posture reviews. Our team can help identify vulnerabilities, validate network segmentation, develop incident response and disaster recovery plans, conduct tabletop exercises and provide security engineering support to remediate identified risks.
We also offer managed security monitoring and cybersecurity awareness training to help municipalities better protect critical infrastructure and essential public services. Start a conversation.
Improve your city’s cybersecurity