Protecting America's Water Infrastructure
The Minnesota Attacks Are a Warning. The Next Attack May Not Be.
For years, cybersecurity experts have warned that America's water and wastewater infrastructure represents one of the nation's most attractive targets for cyber adversaries. Last week's coordinated attacks against multiple water systems in Minnesota—and the subsequent reports of similar activity expanding to additional states—demonstrate that this threat is no longer theoretical. It has arrived.
Fortunately, there have been no reports that drinking water has been contaminated or that public health has been compromised. Utility operators, state agencies, and federal partners responded quickly, often shifting affected facilities to manual operations while investigating the incidents. But these events should not be measured only by their immediate impact. They should be viewed for what they represent: a coordinated attempt to disrupt one of America's most essential critical infrastructure sectors.
Federal agencies—including the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command—have already warned that malicious actors are actively targeting internet-connected operational technology (OT), including programmable logic controllers (PLCs) used to control pumps, valves, chemical treatment systems, and other industrial processes across critical infrastructure sectors.
For water utilities, this changes the conversation.
Cybersecurity can no longer be viewed solely as an information technology issue. It has become an operational resilience issue.
Every water utility exists to deliver one of society's most fundamental services safely and reliably. Every cyber intrusion therefore becomes more than a technology event—it becomes a matter of public trust, public safety, and operational continuity.
The Threat Is Growing More Sophisticated
The recent attacks highlight a broader reality.
Nation-state cyber campaigns are increasingly focused on operational technology rather than traditional enterprise networks. Their objective is not simply to steal information, but to disrupt operations, undermine confidence, and create uncertainty.
Water and wastewater utilities present attractive targets because many operate aging infrastructure that has gradually become connected to modern networks. Remote monitoring, distributed facilities, internet-connected PLCs, and limited cybersecurity staffing create an environment where determined adversaries can exploit weaknesses if they remain unaddressed. Federal guidance continues to emphasize reducing internet exposure of OT systems, strengthening authentication, improving segmentation, and preparing for manual operations when necessary.
Today's Threats. Tomorrow's Challenge.
While utilities respond to today's operational threats, another challenge is already approaching.
Quantum computing has the potential to fundamentally change the cybersecurity landscape by rendering many of today's widely deployed public-key cryptographic algorithms vulnerable. Although cryptographically relevant quantum computers have not yet arrived, the migration to quantum-resistant security architectures will require years of planning, assessment, and implementation.
Critical infrastructure cannot afford to wait until that day arrives.
Unlike many technology refresh cycles, cryptographic modernization cannot be accomplished overnight. Water utilities operate assets with life cycles measured in decades, making long-term security planning especially important.
The organizations that begin preparing now will be far better positioned than those forced to react later.
Operational Resilience Must Become the New Standard
Protecting water infrastructure is no longer simply about installing another cybersecurity product.
It requires a comprehensive approach that protects operational communications, strengthens industrial control environments, improves visibility into cyber risk, modernizes cryptographic protections, and ensures that utilities can continue operating safely even while under attack.
The question is no longer whether critical infrastructure will continue to be targeted.
The question is whether organizations will be prepared before they become the next headline.
A Call to Action
The events unfolding across multiple states should serve as an inflection point for the entire water sector.
Boards, executive leadership, operations teams, cybersecurity professionals, engineering firms, and technology partners all share responsibility for strengthening the resilience of the nation's water infrastructure.
Preparation begins with understanding where operational technology is exposed, evaluating existing cryptographic protections, assessing long-term quantum readiness, and building a roadmap that addresses both today's nation-state threats and tomorrow's quantum-enabled risks.
America's water infrastructure is among our most valuable strategic assets.
Protecting it requires thinking beyond the next cyber incident—and preparing for the next generation of cyber threats before they arrive.