Group Purchasing
Group Purchasing

Critical Cybersecurity for Safer Water Management

Critical Cybersecurity for Safer Water Management (PDF, 3.69MB)Published: 28 Jan, 2025
Created by:
Dean Parsons
Dean Parsons

Critical Cybersecurity for Safer Water Management, published by SANS Institute in January 2025, analyzes data from a 2024 industrial control system/operational technology (ICS/OT) cybersecurity survey focused on the water and wastewater sector. Written by Dean Parsons, the survey examines how water utilities protect critical engineering components like pumping stations, treatment facilities, and SCADA systems, measuring adoption of the SANS Five ICS Cybersecurity Critical Controls against real-world incidents including the Oldsmar, Aliquippa, and American Water attacks.

Key findings:

  • 39% of water facilities are unable to operate manually during an attack or are unsure whether they can
  • 71% of water facilities have limited or no ICS/OT network monitoring capabilities
  • 26% of facilities reported at least one security incident involving their control system in the past year
  • Only 58% of respondents have a dedicated ICS/OT incident response plan
  • 41% of ICS/OT security incidents traced back to a compromise that started in IT and spread into the OT network
  • Over half (52%) of respondents said traditional IT security tools cause disruption when applied to ICS/OT environments
  • 47% cited difficulty integrating legacy ICS/OT technology with modern IT systems as a top challenge
  • Only 49% of respondents have a formal remote access policy, while 35% rely on informal policies
  • 61% of water facilities have tested and confirmed they can operate in manual mode without traditional SCADA HMI or DCS workstations
  • Nearly 30% of organizations allocate only 0–10% of their cybersecurity budget to ICS/OT-specific needs
  • 41% of respondents said ICS/OT or engineering, not IT or the CISO, controls the ICS/OT cybersecurity budget

Across every control area measured, the survey points to the same structural gap: water utilities are more exposed through their IT networks than their OT environments directly, yet incident response, monitoring, and remote access programs remain unevenly built out. The facilities with the strongest cyber-informed engineering mindset are the ones where ICS/OT or engineering teams, not general IT or security leadership, drive both policy and budget decisions. The survey draws on responses from water and wastewater sector professionals split roughly evenly between OT/ICS engineering operations, IT enterprise support, and converged IT/OT roles, with cybersecurity policy most often set by CIO/CTO (24%) or CISO/CSO (21%) leadership.

FAQ

Meet Your Author

Dean Parsons
Dean Parsons

Dean Parsons

Principal Instructor

Dean Parsons, CEO of ICS Defense Force, teaches ICS515 and co-authors ICS418, emphasizing ICS-specific detection, incident response, and security programs that support OT operations—aligning practitioners and leaders on clear, defensible action.

Read more about Dean Parsons