Skip to content

Water Utilities Are Running on Email Alerts and Phone Calls to Defend Critical Infrastructure

WaterISAC's partnership with Cyware is designed to change that: but automated intelligence alone won't protect utilities that lack the staff to act on it.

Securing U.S. critical infrastructure is challenging, and water infrastructure is one of the hardest of the critical infrastructure sectors to protect. U.S. water treatment infrastructure includes 50,000-plus utilities, most of them small operations without dedicated IT staff, let alone skilled cybersecurity staff; each water utility is a viable target. This is among the core challenges the WaterISAC (Information Sharing and Analysis Center) has been working to address.

On September 30, the communications and information-sharing organization for the water and wastewater sector announced a partnership with Cyware to automate the threat intelligence pipeline that currently runs through ad hoc email and phone calls. It’s an enhancement for our analysts, explained Tom Dobbins, executive director at the WaterISAC. "Our goal is to provide a high-quality threat intelligence platform that helps our analysts deliver more real-time insights to our members," Dobbins added.

Currently, the WaterISAC shares threat intelligence like every other cross-sector entity, and that’s generally by email or phone, explained Tom Stockmeyer, managing director, government and critical infrastructure at threat intelligence platform provider Cyware. "A threat spotted in the electric or gas sector could take weeks to reach a water utility through those channels," Stockmeyer said. The Cyware platform aims to replace that manual effort with an automated rules engine that enables real-time, bidirectional sharing across water, electric, and gas sectors, which already share many of the same industrial control systems and programmable logic controllers.

The need for rationalized threat intelligence

The WaterISAC selection followed a unanimous recommendation from a member task force and unanimous board approval. WaterISAC currently serves more than 600 member utilities and, through a partnership with the National Rural Water Association, supports roughly 30,000 smaller utilities nationwide. The phased threat intelligence platform implementation targets essential functionality in approximately 60 days, with broader capabilities deployed over six to seven months and an eventual adoption target of 95 to 98 percent across the membership.

The rationalized threat intelligence feed couldn’t come at a better time for the water sector, as it has been heavily targeted in recent years. For instance, in November 2023, Iranian-linked hackers associated with Cyber Av3ngers, a group tied to Iran's Islamic Revolutionary Guard Corps, compromised a programmable logic controller at the Municipal Water Authority of Aliquippa, Pennsylvania, targeting Unitronics equipment because it is Israeli-made.

CISA, the FBI, EPA, and NSA issued a joint advisory in December warning of a broader pattern of similar intrusions. In early 2024, pro-Russian hacktivist groups hit water systems in several small Texas communities, including Muleshoe, forcing manual operations. That September, Arkansas City, Kansas, switched its water treatment facility to manual control after detecting a cybersecurity incident. Also in 2024, American Water Works, the largest regulated water and wastewater utility in the United States, disclosed a cyberattack that took its customer portal offline, though the company said operations were not disrupted.

More recently, in July 2026, a coordinated cyberattack hit more than 30 community water systems across Minnesota, taking one plant temporarily offline and forcing others to switch to manual operations; the kind of multi-utility, opportunity-based disruption that WaterISAC's collective defense model is designed to detect and contain before it cascades.

Throughout it all, U.S. intelligence officials repeatedly warned that Volt Typhoon, a Chinese state-sponsored threat actor, had pre-positioned itself inside American critical infrastructure, including water systems, likely for contingency disruption rather than immediate attack.

The platform benefits beyond the threat intelligence

The volume of threat data flowing into the WaterISAC is a significant challenge, and the platform will synthesize and help to prioritize that data into actionable intelligence. "If someone receives 150 advisories, nobody's going to read them all," Stockmeyer said. "With that many alerts, they're just going to walk away and turn off their computer," he said, and explained that the platform's job for the water sector is to surface which advisories matter to a specific utility and deliver them with enough context to act on.

For Dobbins, the efficiency gain from automating curation and bulletin production will free analysts to do higher-order tasks. "If I can have analysts not spending time writing materials and doing analysis, I can have them learning through more webinars, more live discussions, be out on the road more," he said. 

That outreach and education is essential, says Dobbins, as giving utilities faster intelligence only solves half of the water sector's cybersecurity puzzle. "It's great to be able to give intelligence," Dobbins said. "But if your audience doesn't know what to do with that intelligence, it's the equivalent of telling someone there's a train coming down the tracks, as opposed to grabbing the switch and moving the train to another track," he explained, referring to the dearth of cybersecurity expertise coming throughout the water sector.

That gap drives the three big current WaterISAC initiatives: improved real-time intelligence delivery, a tailored learning-management platform for distance education, and cybersecurity field personnel who visit small utilities to walk operators through basic cybersecurity hygiene, check default credentials on industrial controllers, and identify the most pressing gaps. 

Collective defense works when the intelligence reaches the defender in time to matter, and the defender knows what to do with it. WaterISAC is building toward both conditions at the same time. The first is a technology problem with a straightforward technology fix; the second is a workforce and education challenge that takes longer to solve, but the work is underway.

Related:

Water Utility Attacks in Multiple States Show the Cost of One Old Vulnerability
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.
Project Watershed 250 Targets Water Cybersecurity
Dragos CEO Robert M. Lee has repeatedly warned that under-resourced water utilities cannot defend themselves against growing cyber threats alone. A new federal-state-industry initiative in Texas aims to start closing that gap.
Pilot Program to Boost Water Utility Cybersecurity Falls Short
The tens of thousands of at-risk water utilities across this country are still out there — now slightly more aware of how exposed they are, which isn’t exactly progress.

Latest