Some companies see cybersecurity as a cost center. We see things a little different. LEARN MORE >

Our seasoned Chief Information Security Officers bring strategic guidance to your leadership team, helping you right-size your cybersecurity operations.


A full suite of manage solutions from our US-based Security Operations Center (SOC)—staffed 24x7x365 by a full team of experienced analysts.


You can count on our IR team to contain the damage from a cyberattack, investigate the origins of the breach and build better protections for the future.


Why Inversion6

With an abundance of solutions and providers, the task of choosing the right option is critical and can sometimes be overwhelming.

Contact Us
BLOG

Why U.S. Water Systems Remain Vulnerable

Here’s How to Start Fixing the Problem

city scape with code above it

Key Takeaways

  • At least a dozen states have reported OT cyberattacks on water utilities. Minnesota alone has had more than thirty facilities affected.
  • The EPA's 2023 cybersecurity review requirement was withdrawn after states and industry groups sued, leaving assessments a "strong recommendation."
  • Wisconsin offered free, federally funded assessments to 600+ municipal facilities. Two registered in two years.
  • That refusal is rational. A list of findings with no staff or budget to fix them converts an invisible threat into a documented liability while changing nothing on the ground.
  • Milwaukee proves the work can be done. Ahead of the RNC it took months, not years, because there was attention, a deadline and resources.
  • Three changes matter more than any mandate: fund remediation instead of assessment, fund cybersecurity circuit riders, and ask for less.

As we've covered at Inversion6, water and wastewater utilities in at least a dozen states have now reported cyberattacks on their operational technology. Minnesota alone has had more than thirty facilities affected.

As the former CISO for the state of Wisconsin, I spent two years trying to address this problem. I mostly failed. Here's why.


Why Isn't Cybersecurity Assessment Required For Public Water Systems?

I became Wisconsin's CISO in 2023. That same year, the Environmental Protection Agency (EPA) made a rule requiring a cybersecurity review as part of the sanitary surveys each state already conducts on public water systems. States and water industry groups immediately sued, arguing the agency had exceeded its authority and mandatory audits would impose a heavy cost on small towns and private operators.

So, the EPA withdrew the rule, instead making cybersecurity assessments a "strong recommendation."


What Happened When Wisconsin Tried Voluntary Assessments?

Next, we tried persuasion. Working with the CIO and CISO at the Wisconsin Department of Natural Resources, we asked facilities to let the state help them assess where they stood. We didn't want to punish anyone. We just wanted to give operators good documentation they could use to build a case for more funding and resources.

Most said no, even to "free" federally funded assessments via CISA. Wisconsin has more than 600 municipal water and wastewater facilities, and thousands more that are local or privately held. When I left the CISO role two years later, exactly two had registered for the voluntary assessments.


Why Would An Operator Refuse A Free Security Assessment?

I didn't like it, but I understand the reasoning behind their refusal.

These operators are not ignorant or indifferent to these risks. What they told me, in so many words, is that a list of findings they had no staff or budget to fix was not actually assistance. In their mind, it was just more liability.

Once a vulnerability is documented; someone must answer for it. If the money to address it doesn't exist, then an assessment simply converts an invisible threat into a visible problem, while changing nothing on the ground.

Bottom line, who wants to highlight a problem when there's nobody willing to pay for the solution?


Has This Work Ever Been Done Successfully?

It's frustrating because I know this work can be done, because I've seen it happen. In preparation for the Republican National Convention in Milwaukee, local water and wastewater facilities were tested and controls were put in place. It took months, not years and it happened because there was federal attention, an immovable deadline and resources behind it.

Obviously, we can't create a national political convention in every county across our county.

However, we can do more to make remediation much more realistic as we move forward.


What Three Changes Would Improve Water System Security?

Here's three changes would matter more than any mandate.

  • Fund remediation, not assessment.
    Grant programs that pay someone to identify problems, without paying to fix them, produce paperwork and little else. We directed $18.5 million in State and Local Cybersecurity Grant Program subawards in Wisconsin, and I saw clearly what that money can and cannot do. The matching funds and sustainability requirements discouraged many would be applicants. In fact, assessment dollars without remediation dollars are worse than nothing, because they teach operators that engaging with the process creates more exposure while relieving none of their pain.
  • Share the workforce.
    Rural water systems already rely on circuit riders, technical staff who serve many utilities across a region rather than one. The model exists and the sector understands it, so why not fund cybersecurity circuit riders and let them work across jurisdictional lines. It may be the only realistic way to give a rural plant with two employees access to someone who knows how to secure a controller
  • Ask for less.
    Four tangible actions can prevent most of what we're reading about in the headlines: Do not expose controllers the public internet and cellular services without validating prudent controls are in place, replace end of life equipment, remove and or change default credentials; harden configuration settings, keep offline copies of project files / control logic; and, test the manual fallback procedure so that it exists before anyone needs it. These are all fundable, achievable and verifiable.


I hope these latest attacks prove to be the warning shot that inspires action.

The people running these plants are not the problem. For years they have been asked to document risks that nobody has been prepared to help them remediate.

So far, they have largely refused; and that's a rational response given the circumstances.

To change their answer, we need to change what we're offering.


More in this series


Turn findings into a funded plan.

Inversion6's CISO advisory practice helps organizations right-size security investment to actual risk — building a roadmap where remediation is budgeted, not just documented.

LEARN MORE →