Securing Cyber Resilience in Water and Wastewater Systems

Cyber Risks in Water
The water sector—covering drinking water supply and wastewater treatment—is a critical part of national infrastructure. Cyberattacks on water systems can lead to disruptions in water supply, contamination risks, environmental hazards, and financial losses. As water facilities become more digitised, the risk of cyber threats targeting Industrial Control Systems (ICS), SCADA networks, and remote access points continues to grow. Recent incidents, including the 2026 coordinated attack on Minnesota water utilities, show that these threats are no longer theoretical—attackers are actively targeting PLCs and remote access points at water facilities today.
Regulatory Pressure: Strengthening Security Standards
Governments and industry bodies worldwide have introduced stricter cybersecurity regulations, such as NIS2, NERC CIP, IEC 62443, and the Cyber Resilience Act (CRA), requiring strong authentication, access control, and resilience against cyber threats. Water utilities must comply with these standards to prevent attacks, avoid legal penalties, and ensure uninterrupted operations.
Notable Attacks on the Water Industry

2026: Minnesota Water Systems Attack
A coordinated cyberattack compromised PLCs at over 30 Minnesota water utilities in July 2026, forcing several sites into manual operation. US authorities have linked the activity to Iranian-affiliated actors, matching a wider pattern of PLC exploitation flagged in a CISA advisory.

2026: Cal Water Targeted by Iran-Linked Hackers
California Water Service disclosed unauthorised access linked to the Iran-linked Handala group, part of a wider wave of attacks on US water infrastructure in 2026. The incident highlights the risk of attackers pivoting from IT into OT environments within water utilities.

2021: Oldsmar Water Treatment Cyberattack
Hackers gained remote access to a Florida water treatment plant and attempted to alter the chemical levels in the water supply, potentially endangering thousands of residents. Fortunately, the attack was detected in time, preventing serious consequences.
Benefits of OT Auth Solutions
To comply with regulations and protect against cyber threats, water utilities must implement strong authentication and access control measures for their operational environments. swIDch’s OT authentication solutions—PLC OTAC and OTAC Trusted Access Gateway (TAG)—provide a secure, scalable, and network-independent approach to safeguarding critical water infrastructure.
Why OT Authentication is Essential for the Water Industry
Regulatory Compliance
Security for Remote & Unattended Sites
Many water treatment plants, pumping stations, and reservoirs operate in remote locations. PLC OTAC generates dynamic authentication codes that do not require a network connection, preventing unauthorised access even in air-gapped environments.
Secure Remote Access for Critical Operations
Protection Against OT Cyber Threats
How OT Auth solutions work
Traditional authentication methods in the water industry rely on passwords, network-based authentication, or VPNs, which are vulnerable to cyberattacks such as credential theft, phishing, and replay attacks. swIDch’s OT authentication solutions eliminate these risks by generating dynamic, unidirectional authentication codes that work even in offline environments.
How It Enhances Security in Drinking & Wastewater Management:
🔹 Prevents unauthorised access to SCADA, ICS, and remote monitoring systems—even in air-gapped environments.
🔹 Eliminates reliance on network connectivity, reducing exposure to cyber threats such as man-in-the-middle attacks.
🔹 Requires no additional hardware, making it a cost-effective and easily deployable solution.
By adopting swIDch’s OT authentication solutions, water utilities can enhance cybersecurity resilience, comply with industry regulations, and prevent operational disruptions caused by cyber threats.
Water Security FAQs
-
Water utilities increasingly rely on internet- and cellular-connected PLCs to manage remote pumping stations, water towers, and treatment equipment. Many of these devices still rely on default credentials or static authentication, making them attractive targets for state-affiliated and opportunistic threat actors alike. Strong, dynamic authentication at the PLC level closes this gap without requiring network connectivity.
-
Water treatment plants and pipelines are critical infrastructure vulnerable to cyber threats. Strong authentication helps prevent unauthorised access and tampering.
-
Yes, they integrate seamlessly with SCADA environments, ensuring secure authentication without disrupting operations.
-
By eliminating the risks of credential theft and unauthorised access, it strengthens the cybersecurity posture of water utilities.
Award Highlights