Water/WastewaterICS/OTCTICritical Infrastructure

CTI for Water Utilities: Building Intelligence Around Treatment and Distribution

Jason Faulhefer July 28, 2026 8 min read

Share this post

Water and wastewater systems run lean, span hundreds of unmanned sites, and lean heavily on remote access. Generic threat feeds do not help them. Here is what a working intelligence program looks like for a utility that treats and moves water.

Water and wastewater utilities occupy an uncomfortable position in critical infrastructure. They are essential, they are regulated, and they are consistently the least funded operational technology environment in the sector. A mid sized utility may serve two hundred thousand people with a control systems staff of two, several hundred remote sites, and a SCADA network built in stages across three decades.

That reality shapes everything about how threat intelligence has to work here. A feed of nation state actor names and malware hashes does not tell a utility operator whether tomorrow morning is going to be a problem.

What actually gets attacked

Public reporting from the last several years shows a consistent pattern, and almost none of it involves bespoke ICS malware.

  • Internet exposed HMIs and PLCs reachable with default or trivial credentials. The Unitronics incidents in late 2023 were the clearest example: opportunistic actors scanning for a specific vendor device on a specific port, then defacing whatever answered.
  • Remote access into the SCADA network through vendor VPN appliances, unmanaged jump hosts, or cellular routers at lift stations and booster pumps.
  • IT side ransomware that stops the business of running the utility. Billing, laboratory information systems, work order platforms, and historians go down, and operations shift to manual because nobody can verify what the plant is doing.
  • Chemical dosing and setpoint tampering as the theoretical worst case, still rare in practice but the scenario that regulators and boards ask about first.

The threat model is not exotic. It is exposure, credentials, and remote access.

Priority intelligence requirements that fit a utility

Generic PIRs produce generic collection. These are written for the way a water system is actually built and operated.

  1. Which of our internet facing assets expose a control system protocol, vendor web interface, or remote access service? Scoped to every treatment plant, lift station, tank site, and well field, not just the corporate perimeter.
  2. What vendors and integrators hold remote access into our SCADA or process network, and has any of them been breached? Include the SCADA platform vendor, the instrumentation integrator, the chemical feed supplier, and the managed IT provider.
  3. Which vulnerabilities in our specific installed base are being exploited in the wild? Not the full CISA ICS advisory stream. The subset that matches your PLC families, HMI software versions, radio and cellular gateways, and historian.
  4. What activity are actors showing against water and wastewater specifically, including hacktivist and opportunistic groups? Sector targeting shifts fast and often follows geopolitical events rather than technical opportunity.
  5. Are our operator, vendor, or contractor credentials appearing in infostealer logs or breach dumps? This is the highest value, lowest cost collection a small utility can run.
  6. If our IT environment is encrypted tomorrow, what operational visibility do we lose and for how long? The intelligence question behind every ransomware tabletop.

Collection sources that are worth the effort

A two person team cannot run twelve feeds. Prioritize sources that answer the requirements above.

  • WaterISAC advisories and member reporting, which are sector specific rather than generic.
  • CISA ICS advisories, filtered aggressively against an accurate asset inventory. Without the inventory, this source is noise.
  • Your own external attack surface, rescanned on a schedule. Shadow connectivity appears at remote sites through cellular modems installed by contractors who were solving a legitimate problem.
  • Credential exposure monitoring across utility domains, operator personal accounts used for vendor portals, and integrator accounts.
  • Honeypot and decoy telemetry using protocol accurate sensors. Modbus, DNP3, and vendor style HMI decoys show you what is scanning your address space and how quickly, which is far more grounded than a global feed.
  • Vendor and integrator security notices, tracked as a named collection stream rather than whatever lands in someone's inbox.

Turning intelligence into plant floor action

Intelligence that stops at the report has failed. In a utility, the handoff usually goes to three audiences, and each needs a different product.

Operations and maintenance staff need a short, plain statement of what changed and what to watch. If an exploited vulnerability affects a specific PLC family, the useful output is which sites have that model, what abnormal behavior would look like on the HMI, and who to call.

The IT and network side needs the technical detail: affected versions, detection logic, firewall or access control changes, and remote access rules to tighten.

The general manager and the board need risk framing tied to service delivery and regulatory exposure. America's Water Infrastructure Act risk and resilience assessments, state primacy agency expectations, and cyber insurance questionnaires all pull from the same underlying facts. Reuse the analysis rather than writing it three times.

A realistic maturity path

For a utility starting from nothing, the sequence matters more than the tooling.

  1. Build an asset inventory that is good enough to filter advisories. Vendor, model, firmware version, site, and whether it is remotely reachable.
  2. Establish external exposure monitoring and fix what it finds. Most utilities are surprised by at least one result in the first pass.
  3. Stand up credential exposure monitoring for utility and vendor identities.
  4. Write four to six PIRs, review them quarterly, and retire the ones that stop producing decisions.
  5. Add protocol aware detection and decoy sensors once you have somewhere to send the alerts and someone to act on them.
  6. Exercise the ransomware and manual operations scenario annually with operations staff present, not just IT.

The takeaway

Water utilities do not need more threat data. They need a small number of well written questions, a handful of collection sources tied directly to those questions, and a disciplined path from finding to action on the plant floor. Intelligence in this sector is measured by whether a plant operator changed something on a Tuesday morning because of what an analyst found on Monday.

Share this post

See it in action

Want intelligence that drives decisions, not noise?