a NIST blog
Recent cyberattacks on the U.S. water and wastewater systems (WWS) sector are highlighting the escalating threat to our nation’s critical infrastructure and the practical challenges of securing it. These incidents underscore an important challenge: the connectivity that utilities depend upon must be designed and operated with security as a core priority rather than a secondary consideration. They also provide a critical insight — that effective cybersecurity protections require a broad-based understanding and management of risks across people, processes, and technologies throughout the enterprise. Utilities with effective cybersecurity protections may still experience service disruptions during a cyberattack, but they are better equipped to respond quickly, limit the impact, and restore operations faster. This helps maintain operational resilience in delivering safe water essential to public health and national infrastructure.
The NIST National Cybersecurity Center of Excellence (NCCoE) has been addressing these challenges. In 2022, we launched the “Cybersecurity for the Water and Wastewater Sector” project, bringing together participants from the WWS sector (utilities, industry experts, technology providers, and associations) to understand the priority challenges and develop practical guidelines to address them. Recently, the NCCoE published NIST SP 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access) to demonstrate the implementation of secure remote access. Below, we’ll discuss how this publication can help utilities improve their security in light of the recent cyberattacks.
Current Challenges
In late July 2026, WWS utilities across the U.S. reported a significant increase of cyberattacks. These attacks were not aimed at traditional information technology (IT) systems — but instead were specifically directed at operational technology (OT) devices that are used to manage the physical processes involved in treating and storing water supplies. Alerts from CISA, the FBI, and the EPA provided evidence of threat actors specifically infiltrating internet-facing components commonly used in OT environments. In these instances, programmable logic controllers (PLCs) were remotely accessed in an unauthorized manner, with the intent to change settings, reduce monitoring and control capabilities by staff, and disrupt system operations.
To understand why the WWS sector is increasingly becoming targeted critical infrastructure, it is helpful to consider some unique features of the sector itself, the ongoing digital transformation providing many of the benefits of modern operations, and associated risks that are being introduced by this transformation.
About the WWS Sector
The size, scale, and complexity of the U.S. WWS sector all make securing its infrastructure a challenge. The U.S. has nearly 50,000 community water systems (public systems that supply water year-round to communities having populations greater than 25 individuals) and more than 16,000 wastewater treatment systems, which range widely in terms of size and complexity. While 1% of all utilities are very large and in total serve nearly half the U.S. population, more than 80% of them are small and each serve 3,300 people or less. These smaller, lower-capacity utilities tend to be much more resource constrained, particularly with cybersecurity. Larger, more complex utilities tend to have the resources and staffing to better address cybersecurity challenges. These wide ranges in size, capability, and cybersecurity readiness further underscore the need for approaches that can be adapted across all sector utilities.
The Digital Transformation of the WWS
Many consider utilities in terms of the physical plant made up of treatment systems, pumps, pipes, and tanks. But behind this physical infrastructure, there are staff monitoring and controlling system operations from computers or handheld devices. WWS personnel now have real-time visibility into what is happening across the entire system, including equipment and stations that may be miles away from the central treatment plant. These capabilities are accomplished by an underlying digital infrastructure, connecting physical systems via networked components such as supervisory control and data acquisition (SCADA), PLCs, and human-machine interfaces (HMIs).
This digital transformation over the last few decades has led to an increase in efficiencies, improvements in operations, and reductions in costs. Work that used to be manually intensive and required on-site personnel is now highly automated and can be managed remotely. Personnel can now access real-time information on system operations and perform troubleshooting activities, like monitoring remote pump stations, measuring water quality, or analyzing data to identify and resolve issues. Larger and more complex utilities also have automated feedback and process loops across OT systems, enabling one system to access controls of other systems without humans in the loop to manage or control the interaction. However, as we will see next, these improvements have also introduced unforeseen cybersecurity challenges.
Cybersecurity Challenges
The hallmark feature of the digital transformation is connectivity. For some WWS utilities, their systems and devices in the OT environment are exposed to external networks and the internet, allowing accessibility to authorized users from any location. However, these devices can now also be easily found by threat actors using scanning tools to identify those with known vulnerabilities. They can then attempt to exploit these vulnerabilities to gain unauthorized access to devices and systems in the OT environment, or even network segments further out into the utility’s ecosystem.
Unauthorized access can result from a wide range of vulnerabilities and weak security practices, allowing threat actors an opportunity to easily breach defenses. As we mentioned earlier, it is imperative that utilities consider risks across their entire enterprise to adequately understand and manage them. However, in the context of these recent WWS cyberattacks, we will explore the technical risks behind the reported unauthorized access of OT devices and highlight mitigations discussed in our publication.
From a technical perspective, OT environments are at risk if the networks used for connectivity lack protections such as firewalls, segmentation, jump host servers, or highly protected demilitarized zones (DMZs). Also, risks are introduced when the OT devices themselves are not designed, installed, or updated with security as a priority. Examples of these include hardware and systems with outdated firmware, use of credential sharing or default passwords, misconfigured settings, or unpatched software. Together, these factors all contribute to an increase in the utility’s ‘attack surface’ and can lead to vulnerable components being exposed and subject to cyberattacks. For example, in the aforementioned recent attacks, the evidence points to malicious actors gaining access to internet-facing PLCs with poor security configurations, then managing to change the passwords and IP addressing of the units to lock out authorized users.
The important question then becomes — how can this access to internal OT environments and devices be better protected from unauthorized threat actors? Generally speaking, utilities in the sector are being encouraged to improve their cybersecurity posture by maintaining an accurate inventory of assets to know what devices are on the network, reducing internet exposure by minimizing public-facing systems, and improving the security of systems absolutely required to be accessed remotely. While some utilities may attempt to remove all devices from external network connectivity completely (referred to as ‘air gap’), others requiring limited internet-based connectivity for operations and support are working to protect the accessibility of their OT environments and networks. Next, we’ll look more closely at the concept of “secure remote access” to explain how this can be accomplished.
Basics of Secure Remote Access for OT
NIST defines remote access as “access to organizational systems (or processes acting on behalf of users) that communicate through external networks.” An example is shown in the figure below. This access can be user-initiated access by an employee, vendor, contractor, consultant, or an automated external system that is authorized to perform work or monitor conditions without being physically present on site. In OT environments, remote access allows the user to interact directly with the controls of the physical systems for support, troubleshooting, diagnostics, and management.
However, not all remote access is inherently secure. The practice of securing remote access involves many factors, typically by implementing security controls. Security controls are usually deployed in a layered approach and include combinations of technical and administrative solutions. Examples of technical controls include encryption of data and network traffic, multifactor authentication (MFA) to validate user identity, segmentation to separate OT networks from the enterprise ecosystem, specialized jump or bastion servers to manage network traffic reaching OT assets, and network visibility tools that provide logging and monitoring of access. Examples of administrative controls include establishing access control lists to limit which users can reach an asset, enforcing least privilege to minimize permissions, reviewing logs for accountability, and establishing supporting governance policies.
These security controls can all work together in the unique settings of OT environments for any WWS utility. However, given the specific needs of each utility as related to their operational complexity, capacity, and resources, it may be difficult to know exactly which security controls to implement and how they work together to provide a more comprehensive security posture, and for secure remote access in particular. This is where demonstration architectures can help. Practical, step-by-step reference material can clarify how controls are adapted to work together in securing OT environments. And this is exactly what is being developed at the NCCoE, as we describe below.
NIST NCCoE Guidelines for Secure Remote Access in WWS Utilities
As part of ongoing work over the past few years, the NCCoE has been working with WWS collaborators — including small, medium, and large utilities — and technology companies to identify critical sector-wide cybersecurity challenges and their mitigations. In our recent publication, NIST SP 1800-45,Cybersecurity for the Water and Wastewater Sector: Build Architecture Operational Technology Remote Access, we provide practical guidelines demonstrating how WWS utilities across a wide range of sizes and capacities can implement technologies for secure remote access to OT systems. The publication demonstrates several example approaches for securing remote access using commercially available technologies. Utilities can use these example approaches to help in the evaluation of their own security practices and inform the design of more secure approaches appropriate to their operational needs, environments, and resources.
Together with our collaboration partners, we built reference architectures in our NCCoE laboratory to demonstrate how technologies and standards can be applied within OT environments typically found among WWS utilities. For utilities with on-premise OT networks, there is a conventional architecture using a traditional approach with firewalls and a remote access server. For smaller resource-constrained utilities, we provide an approach using cloud-based remote access utilizing an external service provider. For larger utilities that may have direct machine-to-machine communication (without a human in the loop), we demonstrate an example of system-to-system remote access.
The first example demonstrates how firewalls and a remote access server can be configured in a conventional network to provide protection to OT resources. In this instance, remote users initiate a connection to a server via a web browser over HTTPS, which is directed through firewalls to add additional restrictions on ports and protocols. The remote access server was enabled to define role-based access control to manage how each user can interact with assets in the OT environment.
The second example highlights how cloud-based secure remote access can be utilized, particularly in resource-constrained or low-capacity environments. This example includes a cloud security provider that provides user access management and activity logging, so that authentication and authorization are managed in the cloud-hosted control plane. This allows remote users (after identity management is accomplished) to connect to the OT environment via a secure communication channel using tokens. Logging information is collected and stored in the cloud for further analysis.
The third example describes a scenario of system-to-system remote access, where there is automated data exchange of process information between two OT systems without user interaction. This increasingly common use case is where automation (implemented with sensors, control systems, or actuators) is used among geographically dispersed assets, requiring communication across externally managed infrastructure. In this implementation, hardware encryption devices are implemented at each of two remote sites. These encryption devices establish an authenticated session with each other, providing a protected connection that allows encrypted process data generated in one OT environment to pass across the network to the other OT environment in a secure manner.
How NIST Guidelines Can Help the WWS Sector
Many WWS sector organizations, together with federal agencies, are providing a wide range of tools, best practices, and support in helping utilities improve their cybersecurity practices. At the NCCoE, we are building on this by providing reference architectures and example demonstrations, showing the “how-to” steps of implementation. Our intent is that these practical resources will help reinforce sector recommendations and give utilities a clearer path forward on how to effectively implement protections in their own unique OT environments.
An important insight reinforced through the course of our work with collaborators in the WWS sector is that secure remote access is one important consideration within a broader approach to managing security. To accomplish this, we encourage all utilities to refer to the NIST Cybersecurity Framework (CSF) 2.0 as a holistic framework to understand and mitigate cybersecurity risks across people, process, and technologies. Additionally, NIST SP 800-82r3, Guide to Operational Technology (OT) Security provides general guidelines on securing OT environments while addressing their unique performance, reliability, and safety requirements. These resources can assist utilities in taking an enterprise-wide, risk-based approach to cybersecurity. They also help to establish foundational governance frameworks in addition to technical fixes, address other considerations (such as detection, prevention, response, and recovery), and support resilient operations across the WWS sector.
Looking Ahead
Beyond this effort, the NCCoE is focusing on a related and persistent challenge faced by organizations operating OT assets, including WWS providers: accurately identifying and managing OT assets. Our secure remote access guidelines work well if providers have a complete inventory of their OT systems. OT operators cannot protect what they do not know about. Secure remote access is about who can reach assets; asset visibility establishes what those assets are, where they are, how they’re configured, and what needs to be secured. The ability of any critical infrastructure operator to identify and manage all the assets across its enterprise is vitally important in establishing secure environments.
To address this, we are launching a new project on OT Asset Management and Visibility. Soon, we will issue a call for collaborators — asset owners, operators, and technology providers — to work with the NCCoE to demonstrate effective techniques for asset management in OT environments, including automated and manual asset discovery, inventory management, configuration management, and change management processes. Learn more here and join the OT Community of Interest to stay informed of this work.