Skip to content

Cybersecurity

Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure

Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

3 min read
Water treatment plant with SCADA systems and field IoT sensors

Water as a Cyber Target

In 2021, an operator attempted to increase sodium hydroxide levels in the drinking water of Oldsmar, Florida, to over 100 times the safe level, through remote access to an HMI system. Fortunately, an on-site operator noticed the anomalous cursor movement on the screen and intervened. But the incident revealed something many already suspected: water infrastructure is vulnerable, connected, and often managed with security tools far less sophisticated than the risk warrants.

The water/wastewater sector presents a combination of factors that makes it particularly exposed: critical infrastructure for public health, often very dated OT systems, limited budgets, technical staff specialized in hydraulic processes but not in cybersecurity, and a progressive remote connectivity introduced to reduce operational costs.

The Typical Architecture: SCADA, HMI, Field IoT Sensors

A modern water plant is a complex OT environment. At its center are SCADA systems that monitor and control the entire cycle: capture, treatment, distribution, wastewater collection, and purification.

Typical components include:

  • PLCs and RTUs distributed across pumping stations, dosing plants, and along the distribution network.
  • Local and remote HMIs that allow operators to supervise and intervene in processes.
  • Water quality sensors measuring pH, chlorine, turbidity, and other parameters in real time.
  • SCADA telecontrol systems aggregating data from remote stations distributed across the territory.
  • LPWAN and cellular networks for communication with remote devices where fiber does not reach.

Many of these systems are years or decades old. Communication protocols are often proprietary or old versions of industrial standards that do not include authentication. Updates are rare due to the need to validate every change in a system that cannot afford downtime.

The Incidents That Opened Eyes

Beyond Oldsmar, several episodes in recent years have brought attention to the sector. In Europe, several water utility operators have been hit by ransomware that blocked management systems without directly compromising physical processes. In the Middle East, state-sponsored actors have probed water infrastructure as part of broader reconnaissance campaigns.

The main concern is not always immediate damage. An actor with persistent access to a water control system could simply observe for months, map processes, identify moments of operational vulnerability, and act only at a wider moment of crisis. Deterrence, in these cases, comes from detection capability, not prevention.

The European Regulatory Framework and NIS2

NIS2 includes the distribution and treatment of drinking water among essential sectors, as well as the collection, treatment, and distribution of wastewater. Obligations apply to operators exceeding the size thresholds defined by the directive.

For operators subject to NIS2, this means: adopting proportionate cyber risk management measures, implementing incident response procedures, notifying significant incidents to the competent authority within 24 hours, and ensuring supply chain security.

National transposition of NIS2 in many European countries has included the development of sector-specific guidelines for water, but practical implementation remains uneven. Many small local operators, who technically fall within the directive's scope, have not yet started a structured compliance program.

From Visibility to Response

For a water operator wanting to build a realistic OT security program, the path always starts from the same question: what do I have on the network?

The fundamental step is a complete inventory of OT assets, including remote field devices. In water environments this is often more difficult than in a manufacturing plant because the infrastructure is geographically distributed across a large territory, with pumping stations and measurement points scattered in physically isolated locations.

Once the inventory is available, the next step is traffic baseline: understanding which communications are normal in the environment and configuring monitoring to detect deviations. In water OT, where processes are cyclical and predictable, traffic anomalies are high-value diagnostic signals.

The third pillar is remote access management. Water plants depend heavily on remote telecontrol — it is their reason for existing as distributed infrastructure. Securing these accesses with MFA, just-in-time access, and session recording is probably the intervention with the best cost/benefit ratio in terms of risk reduction.

The goal is not perfect security, which does not exist. It is to reduce the probability of a serious incident, and to ensure that when something does happen, you know what is occurring in time to intervene.

The MON5 Angle

For a water utility, the path described in these pages — inventory first, then baseline, then access control — aligns with MON5's three-step methodology. DISCOVER inventories OT assets even across geographically distributed infrastructure, with passive discovery that does not disturb pumping stations and telecontrol. PROTECT adds continuous monitoring: in water processes, which are cyclical and predictable, ML anomaly detection makes deviations particularly visible.

The ANALYZE phase also supports NIS2 compliance, which for the water sector is an obligation, not a choice. To start the journey with limited resources, the entry point is a modular OT assessment.

Related articles

Railway network architecture with SCADA and signalling systems

Cybersecurity

Railway Cybersecurity: Specific Challenges and a Regulatory Approach

Railway networks are becoming more connected and more exposed. An analysis of systems at risk, the regulatory framework and defence strategies for an often overlooked critical infrastructure.

3 min read
Comparison of OT monitoring platforms on an ICS network with evaluation criteria side by side

Cybersecurity

What Is the Best OT Cybersecurity Platform for ICS Networks? Selection Criteria

There is no single best OT cybersecurity platform — there is the right one for your ICS network, your protocols, and your maturity level. Concrete criteria for choosing without being guided by marketing.

4 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

Learn more about the regulation: NIS2

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna