IMF keeps 2026 global growth near 3% as regional gaps widenEnergy AI data-centre demand reshapes power investment plansUkraine UN records highest monthly civilian casualty total since 2022Markets gold trades near $4,400 as investors weigh rates and riskIMF keeps 2026 global growth near 3% as regional gaps widenEnergy AI data-centre demand reshapes power investment plansUkraine UN records highest monthly civilian casualty total since 2022Markets gold trades near $4,400 as investors weigh rates and risk
Cybersecurity

Water Utilities and Power Grids Face New Wave of Attacks as IT and Operational Systems Converge

Regulators and security researchers say attacks targeting the industrial control systems behind water treatment, electricity and manufacturing plants have grown more frequent, as decades-old operational technology gets connected to modern networks faster than it can be secured.

AnalysisBy Insight Media Editorial Desk14 August 20269–11 min read

A control room monitor displaying industrial control system network diagrams

What happened?

Cybersecurity agencies in several countries have issued fresh warnings this year about attacks targeting operational technology, the specialised industrial control systems that run water treatment plants, electrical substations, manufacturing lines and other critical infrastructure. The US Cybersecurity and Infrastructure Security Agency and its counterparts in the UK, Australia and several EU member states have jointly and separately flagged a rise in reconnaissance activity and, in a smaller number of confirmed incidents, actual intrusion attempts against these systems, many of which were originally designed decades ago without cybersecurity as a design consideration and have since been connected to broader corporate networks and, in some cases, the internet.

Several water utilities in the US and Europe have disclosed unauthorised access attempts to control systems over the past year, most caught before causing operational disruption, according to disclosures reviewed by industry monitoring groups, but security researchers say the trend points to a growing and under-resourced vulnerability across sectors that most people rarely think about until something fails.

Key points

  • CISA and international partners have warned of rising reconnaissance and intrusion attempts against industrial control systems.
  • Water utilities in the US and Europe have disclosed several unauthorised access attempts to control systems over the past year.
  • Much operational technology running critical infrastructure was designed decades ago without built-in cybersecurity protections.
  • The convergence of IT and OT networks, driven by demand for remote monitoring and efficiency, has expanded the attack surface.
  • State-linked actors, notably groups associated with China and Russia, have been named by Western agencies as being pre-positioned within some critical infrastructure networks.

What we know

CISA, alongside the US Environmental Protection Agency, has issued guidance this year specifically addressing cybersecurity gaps at water and wastewater utilities, a sector the agencies describe as particularly exposed given the large number of small, resource-constrained municipal operators that often lack dedicated cybersecurity staff. Similar warnings have come from the UK's National Cyber Security Centre and the EU Agency for Cybersecurity, both of which have highlighted the risks posed by legacy operational technology increasingly connected to corporate IT networks for remote monitoring and data analytics purposes.

US officials, including statements from the FBI and CISA, have previously named state-linked groups, including one referred to in public advisories as Volt Typhoon and associated with China, as having gained and maintained access within US critical infrastructure networks, reportedly for potential future disruptive use rather than immediate espionage, a posture officials have described as pre-positioning. Russian-linked groups have similarly been associated by Western intelligence agencies with reconnaissance and, in some documented cases, disruptive attacks against energy infrastructure in Ukraine and, less directly, in NATO member states.

Background

Operational technology refers to the hardware and software used to monitor and control physical industrial processes, distinct from the information technology systems, such as email servers and corporate databases, that most cybersecurity discussion has traditionally focused on. For most of their history, OT systems in sectors like water treatment and power generation were physically isolated, or 'air-gapped,' from corporate IT networks and the internet, a design choice that provided a meaningful, if imperfect, layer of security simply by limiting remote access.

Over roughly the past 15 years, the drive for operational efficiency, predictive maintenance and remote monitoring has led many utilities and manufacturers to connect previously isolated OT systems to broader corporate networks, and in some cases directly or indirectly to the internet, a trend generally described as IT-OT convergence. This has delivered genuine operational and cost benefits, but it has also dramatically expanded the potential attack surface for systems that, security researchers repeatedly emphasise, were frequently designed with multi-decade operational lifespans and little to no consideration of modern cybersecurity threats, and which are often far harder and more expensive to patch or replace than conventional IT equipment given the operational disruption that taking a control system offline can cause.

Detailed analysis

The particular vulnerability of the water sector illustrates the broader challenge well. The US has roughly 50,000 community water systems according to EPA figures, the vast majority of them small municipal utilities serving limited populations with correspondingly limited budgets for cybersecurity investment. Unlike the electricity sector, which has faced mandatory cybersecurity standards enforced by the North American Electric Reliability Corporation for over a decade, water utilities in the US have historically operated under a more fragmented, largely voluntary regulatory framework for cybersecurity, though this has been the subject of ongoing policy debate and legal challenges over the scope of EPA authority to mandate specific cybersecurity requirements.

Security researchers who study industrial control system vulnerabilities note that many of the confirmed intrusion attempts against water utilities documented over the past two years have involved relatively unsophisticated techniques, such as exploiting default or weak passwords on internet-exposed human-machine interfaces, rather than highly sophisticated custom malware, suggesting that basic cybersecurity hygiene, rather than exclusively advanced defences, could meaningfully reduce the attack surface if consistently applied. This is a somewhat reassuring finding in one sense, since it suggests relatively achievable improvements could meaningfully reduce risk, but also a sobering one, since it indicates that current baseline defences across much of the sector remain quite weak.

The pre-positioning activity attributed to state-linked actors within US critical infrastructure represents a qualitatively different and more concerning category of threat than opportunistic criminal intrusion, according to assessments from the US intelligence community's periodic threat assessments. Rather than seeking immediate financial gain or data theft, this activity is assessed as being oriented toward establishing persistent access that could be activated to cause disruption during a future crisis or conflict, a posture that complicates traditional cybersecurity response models built around detecting and remediating active, ongoing attacks rather than dormant access that may not be used for months or years.

Why it matters

Disruption to water treatment, electricity or other critical infrastructure has direct and potentially severe consequences for public health and safety, well beyond the financial or reputational harm typically associated with corporate data breaches. A successful attack that compromised chemical dosing controls at a water treatment plant, for instance, could pose an immediate public health risk rather than simply an information security or financial concern, a distinction that has driven a somewhat different regulatory and investment approach in critical infrastructure cybersecurity compared with general corporate IT security.

The geopolitical dimension adds further weight to the issue. Western intelligence assessments describing pre-positioned access within critical infrastructure by state-linked actors suggest these vulnerabilities are viewed by some adversarial states as a lever that could be pulled during a future crisis, potentially to degrade a country's ability to respond to or sustain itself through a broader conflict, a scenario that elevates critical infrastructure cybersecurity from a sector-specific operational concern to a matter of broader national security planning.

What happens next?

Regulatory efforts to strengthen critical infrastructure cybersecurity requirements are continuing across multiple jurisdictions, though progress has been uneven and often contested, particularly in sectors like US water utilities where regulatory authority and funding for smaller municipal operators remain constrained. The EU's Network and Information Security 2 Directive, which expands cybersecurity obligations across a broader range of critical and important sectors, continues to be transposed into national law across member states, a process that has taken longer than originally envisioned in several countries.

Security researchers expect continued disclosure of both criminal and state-linked intrusion attempts against operational technology over the coming year, and industry groups are pushing for increased federal and, in Europe, EU-level funding to help smaller utilities and municipal operators afford the security upgrades that larger, better-resourced operators have more readily implemented.

Insight Media Opinion

The security gap in critical infrastructure operational technology is one of the more genuinely underappreciated risks in the current threat landscape, precisely because it does not generate the kind of headline-grabbing data breach stories that dominate cybersecurity coverage. A ransomware attack on a hospital's billing system is alarming; a successful intrusion into the control systems managing a city's water chemical dosing is a different order of risk entirely, and the gap between how much attention each receives is not proportionate to the relative danger involved.

The finding that many confirmed intrusions have relied on basic security failures, such as weak or default passwords on internet-exposed systems, should be a source of both mild reassurance and considerable alarm. It means meaningful risk reduction is achievable without exotic new technology, but it also means that years after these vulnerabilities were first flagged by security researchers, basic protections remain inconsistently applied across a sector responsible for a genuinely essential public service. Governments should treat funding for smaller utilities' cybersecurity upgrades as core infrastructure investment, not a discretionary add-on, given both the public health stakes and the documented interest of state-linked actors in exactly this kind of soft target.

Related Insight Media stories

Sources & further reading

Every claim above can be traced to the documents below.

Author

Insight Media Editorial Desk — original reporting, explainers, analysis and practical guides, researched against primary documents and credible independent reporting. Developing stories are updated when significant new verified information becomes available.

Related stories