Aerial view of wastewater treatment plant showing cyber attacks on water utilities

Why Water Utility Attacks Show You Can’t Trust a Compromised Network

The recent cyberattacks targeting water utilities across the U.S. demonstrate that today’s bad actors are often trying to sow as much operational chaos as possible. Recent incidents involving internet-connected operational technology (OT), ransomware and unauthorized access to municipal water systems have demonstrated how fast a cyberattack can undermine public confidence, strain critical services and pressure organizations into making high-stakes decisions with incomplete information.

While securing OT environments and reducing exposure to internet-facing systems remain important, the biggest lesson extends beyond critical infrastructure. Organizations cannot effectively manage a cyber crisis using the same networks, communication platforms and systems that may already be compromised.

Trust goes first

The moment attackers establish a foothold inside an organization’s systems, confidence in the environment instantly erodes.

Security teams may ask: Can email still be trusted? Are collaboration platforms being monitored? Have privileged accounts been compromised? Can security teams rely on identity systems, logs or administrative tools to accurately reflect what is happening?

During the first hours of an incident, few of those questions can be answered with certainty. Still, in many cases, organizations continue coordinating executive discussions, legal guidance, technical investigations and business decisions using the very infrastructure under investigation. That introduces unnecessary operational risk before containment can even start.

The coordinated attacks against more than 30 Minnesota community water systems in July show how quickly operational trust can disappear. Utilities shifted to manual operations after attackers targeted internet-connected control systems as a precaution, even though drinking water remained safe. The immediate challenge was ensuring operators, executives, regulators, and emergency responders could coordinate using information with integrity as the situation unfolded.

Organizations should plan for the assumption that internal communications, credentials and administrative systems may all be suspect until proven otherwise.

That means establishing trusted, out-of-band communications before an incident occurs so leadership, responders, legal counsel and external partners can continue collaborating safely and responsibly. Communications with various stakeholders should be compartmentalized where needed, while progressing the response together. This helps control who sees what and when. Finally, organizations must keep detailed records of what happened, who was involved and how it was handled.

Incident response must be planned and practiced

Responses often fail because dozens of stakeholders have to make critical decisions under intense time pressure with little to no practice prior or realistic plans in place.

The moment an incident hits shouldn’t be the first time a team is dealing with one. In complex organizations, success depends as much on how people work together as the technology they use. To get the best result, organizations must go beyond a static incident response plan. They need adaptive playbooks that evolve as new information emerges, which have been previously validated through realistic tabletop exercises involving both technical and business teams.

Coordination challenges emerged, for example, during the August cyberattack on Suisun City, California. As the city shut down critical IT systems to preserve evidence, leaders had to coordinate emergency services, legal counsel, federal investigators and public communications while many normal business systems remained unavailable. This highlights how cyber response is a business continuity exercise involving far more than the security team.

Incident response needs close collaboration, and every stakeholder should have access to accurate information, documented decisions and a shared understanding of priorities.

What real readiness looks like

Organizations have invested heavily in prevention, monitoring and detection, but sophisticated bad actors are usually pretty confident that if they just keep trying, they will eventually gain access. Not to mention, AI agents will often do whatever it takes to achieve their set goal, even if that means going rogue. To match the determination of the adversaries and agents and minimize the damage they cause, organizations need to reduce the cost and impact of the incident and get back to business as usual as quickly as possible.

That requires asking different preparedness questions:

  • How will executives communicate if corporate email cannot be trusted?
  • Where will legal, security and external responders coordinate sensitive decisions?
  • How will the organization preserve documentation needed for regulatory reporting, legal review and post-incident analysis?
  • Who owns business decisions while technical teams are still determining the scope of compromise?

These are governance and cybersecurity questions. Cyber reporting continues to expand across jurisdictions with different requirements for each, so preparing for the right reporting for each one is critical. Organizations must be prepared to document decisions, preserve evidence and demonstrate why actions were taken based on the information available at that moment to streamline this process. Organizations that answer these questions before an incident are better positioned to respond decisively when every second and decision matters most.

Building resilience before the next incident

The recent attacks against water utilities underscore that resilience is no longer defined solely by preventing attacks but by maintaining trusted operations after compromise. That means establishing out-of-band communications, bringing business leaders and external partners into incident response planning, developing adaptive playbooks, validating them through realistic tabletop exercises and ensuring governance processes can meet evolving regulatory demands.

While water utilities face unique operational challenges, the same principles apply across healthcare, manufacturing, financial services, retail, higher education and government. Regardless of industry, recovery ultimately depends on trusted communications, disciplined governance and coordinated decision-making once attackers (or rogue agents) gain a foothold. Organizations that build these capabilities before a crisis will be far better positioned to make confident decisions and recover quickly when the next incident inevitably occurs.