Skip to content
Global Data Specialists
Back to InsightsWater and Wastewater

SCADA Cybersecurity for Water Utilities

What AWIA, EPA inspections and the 2023–2024 attacks on water systems mean for a utility's SCADA network, and where to start on an existing system.

Updated

What the Law Requires

Section 2013 of America's Water Infrastructure Act of 2018, which amended Section 1433 of the Safe Drinking Water Act, requires every community water system serving more than 3,300 people to complete a risk and resilience assessment and an emergency response plan, certify both to EPA, and review them every five years. The assessment must cover the system's electronic, computer and other automated systems. For most utilities, that means SCADA.

In May 2024, EPA issued an enforcement alert reporting that more than 70 percent of the water systems it had inspected since September 2023 did not fully comply with Section 1433. Some had critical vulnerabilities, including default passwords that had never been changed and single logins shared by staff. EPA said it would increase inspections and take enforcement action where necessary.

What the Recent Attacks Show

In November 2023, cyber actors affiliated with Iran's Islamic Revolutionary Guard Corps took control of a Unitronics PLC at a booster station of the Municipal Water Authority of Aliquippa, Pennsylvania. The joint advisory that followed from CISA, the FBI, NSA and EPA found that the targeted controllers were reachable from the internet and still used default passwords.

In September 2024, Arkansas City, Kansas, switched its water treatment plant to manual operation after a cyberattack. The city reported that the water stayed safe and service was not disrupted while the plant ran manually.

At Aliquippa, the attackers needed no advanced exploit: the controller was on the open internet with its default password. At Arkansas City, running the plant by hand kept water service going while the automated systems were restored.

Where to Start on an Existing System

Begin with an inventory of every path into the control network: remote-access software, vendor connections, cellular modems at remote sites and links to the business network. Controllers, RTUs and HMIs shouldn't be reachable directly from the internet. Remote access should pass through one controlled route, with an individual account and multi-factor authentication for each operator and vendor.

Replace default and shared passwords on controllers, HMIs and radios, separate the control network from business IT, and keep a log of who connects. Keep offline copies of PLC, RTU and HMI programs, test a restore, and practice running critical sites manually. These steps follow the Top Cyber Actions for Securing Water Systems fact sheet that CISA, EPA and the FBI published in February 2024.

Where GDS Fits

GDS designs and upgrades SCADA networks for water utilities, including segmentation between the control network and IT, remote-access arrangements, user permissions and backups of controller and HMI applications. We coordinate that work with the utility's IT staff. The risk and resilience assessment and emergency response plan remain the utility's documents; we supply the control-system information and changes they call for.

Sources: EPA on AWIA Section 2013; EPA enforcement alert, May 2024; CISA advisory AA23-335A; City of Arkansas City statement (via WaterWorld).

Key Focus Areas

  • No direct internet exposure for PLCs, RTUs or HMIs
  • Individual accounts and multi-factor authentication for remote access
  • Segmentation between the control network and business IT

Implementation Checklist

  • List every connection into the control network, including vendor and cellular links
  • Change default passwords on controllers, HMIs and radios
  • Test a restore of PLC, RTU and HMI backups, and drill manual operation