Cybersecurity Advisory

Increased Cyber Threats Targeting Utilities

Due to a recent increase in cybersecurity threats that target utilities, the Cybersecurity & Infrastructure Security Agency (CISA) urges water and wastewater systems to take steps to protect their Internet-connected infrastructure from outside interference.

Programmable logic controllers (PLCs) are especially at risk, with unprotected, remote cellular connected SCADA devices or those reading lift stations being some of the most vulnerable.

“These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections.”

CISA

Read the full report

Support for Small Systems

NRWA has created the National Rural Water Cybersecurity Center to feature initiatives and resources specifically geared towards small systems. Visit their resource page to learn more about which program is the best fit for your utility’s unique situation.

Additional Resources

There are multiple ways to report a cyber incident:

  1. Contact CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-729-2472
  2. Use CISA’s online Incident Reporting System
  3. Contact your local FBI field office

When preparing a report, record the following details:

  • Date, time, and location of the incident
  • Type of activity
  • Number of people affected
  • Type of equipment used for the activity
  • Name of the submitting company or organization, and a designated point of contact

Take this with you

Download a print-ready copy of this advisory to share with your board, operators, and IT staff.

PDF · Updated August 19, 2026