Group Purchasing
Group Purchasing

Critical Cybersecurity for Safer Water Management

Critical Cybersecurity for Safer Water Management (PDF, 3.69MB)Published: 28 Jan, 2025
Created by:

Critical Cybersecurity for Safer Water Management, published by SANS Institute in January 2025, analyzes data from a 2024 industrial control system/operational technology (ICS/OT) cybersecurity survey focused on the water and wastewater sector. Written by Dean Parsons, the survey examines how water utilities protect critical engineering components like pumping stations, treatment facilities, and SCADA systems, measuring adoption of the SANS Five ICS Cybersecurity Critical Controls against real-world incidents including the Oldsmar, Aliquippa, and American Water attacks.

Key findings:

  • 39% of water facilities are unable to operate manually during an attack or are unsure whether they can
  • 71% of water facilities have limited or no ICS/OT network monitoring capabilities
  • 26% of facilities reported at least one security incident involving their control system in the past year
  • Only 58% of respondents have a dedicated ICS/OT incident response plan
  • 41% of ICS/OT security incidents traced back to a compromise that started in IT and spread into the OT network
  • Over half (52%) of respondents said traditional IT security tools cause disruption when applied to ICS/OT environments
  • 47% cited difficulty integrating legacy ICS/OT technology with modern IT systems as a top challenge
  • Only 49% of respondents have a formal remote access policy, while 35% rely on informal policies
  • 61% of water facilities have tested and confirmed they can operate in manual mode without traditional SCADA HMI or DCS workstations
  • Nearly 30% of organizations allocate only 0–10% of their cybersecurity budget to ICS/OT-specific needs
  • 41% of respondents said ICS/OT or engineering, not IT or the CISO, controls the ICS/OT cybersecurity budget

Across every control area measured, the survey points to the same structural gap: water utilities are more exposed through their IT networks than their OT environments directly, yet incident response, monitoring, and remote access programs remain unevenly built out. The facilities with the strongest cyber-informed engineering mindset are the ones where ICS/OT or engineering teams, not general IT or security leadership, drive both policy and budget decisions. The survey draws on responses from water and wastewater sector professionals split roughly evenly between OT/ICS engineering operations, IT enterprise support, and converged IT/OT roles, with cybersecurity policy most often set by CIO/CTO (24%) or CISO/CSO (21%) leadership.

FAQ

Not all of them: 39% of water facilities are unable to operate manually during an attack or are unsure whether they can, while 61% have tested and confirmed manual operation capability without traditional SCADA or DCS systems. 

Only 58% have a dedicated ICS/OT incident response plan, meaning more than 40% are unprepared or unsure they have one, despite 26% of facilities reporting at least one control system security incident in the past year.

The most common attack vector, cited in 41% of incidents, was a compromise that started in the IT network and spread into the ICS/OT environment, rather than a direct attack on control systems themselves. 

Over half (52%) of water sector respondents said traditional IT security tools and methods are not designed for control systems and can cause operational disruptions when applied to ICS/OT environments. 

Not consistently: nearly 30% of organizations allocate only 0–10% of their total cybersecurity budget to ICS/OT-specific needs, though 40% reported a minor budget increase and 19% a significant increase over the past two years. 

 Not universally: only 49% of water facilities have a formal remote access policy, leaving a substantial gap even though MFA is considered a critical defense against the stolen-credential attacks common in ICS/OT breaches. 

Meet Your Author

Dean Parsons
Dean Parsons

Dean Parsons

Principal Instructor

Dean Parsons, CEO of ICS Defense Force, teaches ICS515 and co-authors ICS418, emphasizing ICS-specific detection, incident response, and security programs that support OT operations—aligning practitioners and leaders on clear, defensible action.

Read more about Dean Parsons