AWIA Was Never Enough. The Latest Water Utility Attacks Prove It.

The cyberattacks against water utilities reported over the past week have generated a familiar response. Questions about attribution. Discussions about foreign adversaries. Renewed calls for additional funding. And, inevitably, renewed conversations about compliance.

Those conversations miss the point.

Whether these attacks ultimately trace back to Iranian actors or another threat group is important for national security, but it is almost irrelevant to the lesson the water sector should take away.

The attackers reportedly exploited exposed operational technology, changed passwords, altered network configurations, and disrupted operators’ ability to manage treatment systems. These were not highly sophisticated attacks against impossible-to-defend environments. They succeeded because basic operational security weaknesses still exist across far too many utilities.

AWIA Was Never Designed to Secure OT

For years, the industry has looked to the America’s Water Infrastructure Act (AWIA) as the cornerstone of cybersecurity preparedness. It was an important step forward when it became law. It required utilities to perform risk and resilience assessments and develop emergency response plans.

But we should stop pretending that AWIA was ever designed to secure operational technology. It wasn’t. AWIA asks utilities to identify risks. It does not require them to eliminate them.

Today, many utilities can legitimately say they have completed their AWIA requirements while still operating internet-accessible PLCs, maintaining flat operational networks, relying on legacy remote access methods, lacking meaningful OT monitoring, and operating with little ability to detect an adversary before operations are disrupted. That is not a failure of the utilities. It is a limitation of the framework.

Compliance and security have never been the same thing. Unfortunately, much of the water sector continues to treat them as though they are.

Compliance Is Not Risk Reduction

I have spent years working with industrial environments across multiple critical infrastructure sectors. One lesson appears repeatedly. Organizations rarely fail because they do not know cybersecurity best practices. They fail because compliance becomes the objective instead of risk reduction.

When success is measured by completing documentation instead of reducing operational exposure, predictable things happen. Risk assessments become paperwork. Emergency response plans become shelf documents. Budgets prioritize passing inspections rather than improving resilience. Technical debt accumulates because there is no regulatory requirement forcing meaningful remediation.

We Already Know What Needs to Be Done

The reality is that we already know what many water systems need. Operational technology should not be directly reachable from the public Internet. Remote access should be tightly controlled, monitored, and engineered specifically for industrial environments. Asset inventories should include every controller, HMI, engineering workstation, and communications path. Operational networks should be segmented based on process risk, not convenience. Continuous monitoring should extend into OT environments rather than stopping at the IT firewall.

These are not revolutionary ideas. Federal agencies have been recommending these practices for years. The unfortunate reality is that recommendations do not create accountability. AWIA certainly does not.

Rethinking Cybersecurity Maturity

The water sector needs to rethink how it defines cybersecurity maturity.

Completing an assessment is not maturity.

Submitting documentation is not maturity.

Passing an audit is not maturity.

Reducing attack surface is maturity.

Building resilient architectures that continue operating safely during cyber incidents is maturity.

AI Has a Role, But It Isn’t the Answer

Artificial intelligence will undoubtedly become part of this conversation. Used responsibly, AI can improve operational visibility, identify abnormal east-west communications, reduce alert fatigue, and support predictive maintenance. It should never become a substitute for sound engineering. Technology cannot compensate for poor architecture, and AI cannot compensate for governance failures.

It’s Time to Move Beyond Compliance

The water sector deserves credit for the progress it has made since AWIA became law. Many utilities have invested in governance, planning, and resilience that simply did not exist a decade ago.

But if water systems can still be disrupted through well-understood attack paths, then our definition of security is not aligned with reality.

AWIA established a baseline and critical infrastructure deserves more than a baseline. Checking the box was always intended to be the beginning of cybersecurity. Somewhere along the way, it became the finish line.

It is time for the water sector to move beyond compliance and start measuring success by something that actually matters: whether an attacker can disrupt operations in the first place.

Prev
Shares