Search
Generic filters
How CIS Benchmarks Help Protect Water Utilities From Cyberattacks
October 2, 2026

Securing the Pathways Between IT and OT at America’s Water Utilities

If our nation’s water and wastewater utilities were looking for a good reason to align with CIS Benchmarks in their cybersecurity programs, the summer of 2026 gave it to them. At least 12 states were hit in what has been described as a coordinated attack by threat groups with suspected links to Iran.

This issue became particularly visible when 39 water systems across Minnesota and Michigan reported targeted attacks in late July and early August. Since then states from Texas to Pennsylvania are tightening security, Senators are introducing new legislation and government agencies are issuing warnings.

Thus far, drinking water and public health has remained safe across the USA’s 152,000 drinking water systems, but the attacks have shown us just how vulnerable our water supply is.

The summer 2026 water sector attacks, by the numbers

States hit in the summer 2026 campaign
0 +
Water systems in Minnesota and Michigan reporting attacks
0
U.S. drinking water systems at stake
0

How IT and OT Work Together for SLED Cybersecurity

Most water and wastewater utilities in the US are operated and overseen by the state, local and education (SLED) sector of government.

These utilities use two primary types of technology.

  Information Technology

Information technology (IT) encompasses the computers, servers, networks, applications and identity systems used to support the organization.

  Operational Technology

Operational technology (OT) covers the systems that monitor and control physical processes, such as sensors, PLCs, SCADA systems, human-machine interfaces (HMIs), industrial computers and related equipment.

Historically, IT and OT were more isolated. But today, utilities are increasingly connected to IT networks and remote-access systems that support OT operation.

That convergence creates a growing cybersecurity risk. An attacker does not necessarily have to compromise a programmable logic controller (PLC) or SCADA system directly if they can first gain access through a poorly secured workstation, server, remote-access host or other IT system connected to the operational environment.

Every connection between IT and OT creates a potential pathway for hackers to exploit.

Engineer at a workstation connected to a PLC cabinet at the IT and OT boundary of a wastewater plant
Engineering workstations sit right on the line between IT and OT, which makes them a priority for hardening.
Water utility field crew manually operating a valve at a pumping station after control systems went offline
When control systems go offline, crews fall back to running equipment by hand.

What happened

In recent attacks, hackers were able to access internet-facing PLCs and other control computers and change their IP addresses and passwords. This resulted in a loss of control functionality, which the utilities countered by shutting down the affected technologies and sending workers out into the field to operate equipment manually.

Additional Security Challenges for Water Utilities

Some utilities depend on equipment that has been operating for years or even decades. Older systems may not have modern security capabilities. Patching may require extensive testing or coordination with the equipment manufacturer. A reboot that is routine in an office environment may be unacceptable in a system responsible for a continuous physical process.

There may also be vendor restrictions, warranty considerations or compatibility requirements that prevent operators from making configuration changes freely. In short, traditional IT security practices do not always translate cleanly to OT.

The goal isn’t to apply every modern security control directly to every OT device. The goal is to reduce the pathways an attacker can use to reach that OT. The greater challenge for many SLED organizations, however, is that they have limited cybersecurity staff and limited budgets to harden systems and rethink how workers and collaborators interact with their networks. Because it lends itself well to automation, CIS Benchmarks can provide a practical, efficient starting point for securing critical systems.

Where CIS Benchmarks Fit in Water and Wastewater Utilities

CIS Benchmarks provide a roadmap for securely configuring operating systems, cloud platforms, network devices and other technology products. Developed by the Center for Internet Security (CIS), they provide prescriptive, consensus-based recommendations developed by global cybersecurity experts.

They are also one of the few such frameworks that can be automated to scan, remediate, validate and report on the hardening processes used, thereby easing the burden on staff and budgets while minimizing the attack vectors to reaching your OT.

For a water utility, that makes CIS Benchmarks particularly useful for systems such as:

Utility AssetPotential Role at IT/OT BoundaryApplicable CIS Benchmarks for OS or application
Engineering workstationsEngineers configure and maintain operational systemsWindows/Linux workstation CIS Benchmarks, Level 1 or Level 2
Operator/HMI workstationsOperators monitor and interact with processesApplicable OS/application CIS Benchmarks
Historian serversCollect and store operational dataWindows/Linux Server CIS Benchmarks
SCADA support serversSupport supervisory control applicationsApplicable server/application CIS Benchmarks
Jump boxesControlled pathway for administrative or remote accessApplicable server/OS CIS Benchmarks, with strict access controls
Remote-access hostsProvide vendor or operator connectivityApplicable OS/application CIS Benchmarks plus access hardening
Domain controllersProvide identity and authentication servicesWindows Server Domain Controller CIS Benchmarks
Management serversAdminister systems across the environmentApplicable server CIS Benchmarks

CIS Benchmarks commonly distinguish between Level 1 and Level 2 recommendations. Level 1 generally represents practical security configuration intended to provide strong protection without significantly impairing system functionality. Level 2 applies more stringent settings intended for systems requiring higher security.

Why hardening levels matter

This matters because aggressive hardening that breaks an operational application is not a successful security program. Different levels and flexibilities in policy mean you can establish the appropriate hardened configurations for the IT systems that have access to operational environments. Where direct hardening isn’t possible, network segmentation, access controls and other compensating measures can help reduce risk.

How CIS Controls, CISA and EPA Guidance Work Together

CIS Benchmarks should not be viewed as a replacement for the cybersecurity guidance already available to water utilities, rather they are a practical implementation layer.

CISA’s Cross-Sector Cybersecurity Performance Goals (CPGs) provide a prioritized set of cybersecurity practices intended to help critical-infrastructure organizations reduce risk. EPA has incorporated that approach into its water-sector cybersecurity guidance and their cybersecurity checklist for drinking-water and wastewater systems was derived from the CISA CPGs.

CIS Benchmarks complement these resources by providing technology-specific configuration guidance. CIS Controls also have published mappings to the NIST Cybersecurity Framework. NIST SP 800-82 offers OT-specific guidance for organizations that need to go deeper.

All these approaches work together to secure systems, with each serving a different purpose in providing a path from cybersecurity strategy to actual system configuration:

From strategy to configuration

Building a Phased Hardening Program on a Lean Budget

Trying to harden everything at once can overwhelm a small SLED cybersecurity team. A phased approach is more manageable.

This last issue of drift is where many cybersecurity programs break down. When it comes to baselines, what’s true today is not necessarily true tomorrow. Which presents an issue for small teams who may be responsible for hundreds or thousands of systems while also handling help desk requests, infrastructure upgrades, emergency incidents, vendor relationships and daily operations.

Manually checking every configuration isn’t sustainable. Neither is maintaining compliance through spreadsheets and screenshots. And the problem becomes even more complicated in segmented or disconnected environments where cloud-dependent security tools may be difficult or impossible to deploy. This is why automation is increasingly important to CIS Benchmarks implementation.

Harden the Path to Your OT

ConfigOS scans, remediates and continuously enforces CIS Benchmarks on the workstations, servers and jump boxes that touch your operational environment — even in air-gapped networks.

Automating CIS Benchmarks Enforcement

Unified automation can turn CIS Benchmarks from a periodic compliance exercise into an operational security process. From a single console, you can scan systems, remediate configuration issues, report results and, where approved and appropriate, continuously sustain security baselines.

SteelCloud’s ConfigOS platform, for example, is designed for environments where connectivity may be restricted, such as classified, air-gapped and cloud. A solution like this can scan and remediate thousands of endpoints per hour, while reducing the manual effort associated with hardening. The linked guide outlines a phased path to CIS Benchmarks implementation in 100 days.

SLED IT security team reviewing a CIS Benchmarks compliance dashboard in a municipal server room
Automated enforcement keeps baselines intact on the systems that bridge IT and OT.

Scalable automation can ease the workload for a lean cybersecurity team. Instead of repeatedly finding and fixing the same configuration problems by hand, security personnel can establish an approved baseline and automate its enforcement.

Protecting Infrastructure with CIS Benchmarks for Water Utilities

The recent attacks against water utilities are a reminder that cybersecurity isn’t simply about protecting data. A cyberattack against a utility can potentially affect physical processes, public services and public safety.

While you may not be able to harden the OT itself, you can harden supported IT systems that have access to it by applying CIS Benchmarks. You can make the path to your critical infrastructure harder to traverse. And you can automate the enforcement of your configurations so that security doesn’t disappear the moment the next software update or emergency change occurs.

Some practical and simple steps you can do today are to research CIS Benchmarks automation solutions, see how they fit into your budget and schedule a ConfigOS demo to see how much easier baseline hardening can be when manual methods are set aside. From there, you’ll have the information you need to implement CIS Benchmarks and provide a secure foundation for all your compliance efforts.

Protect the Systems That Reach Your Water Infrastructure

Automate CIS Benchmarks hardening across the IT systems that border your OT — without adding headcount.

Frequently Asked Questions

Water and utility systems provide essential public services, making them attractive targets for attackers seeking disruption or influence. Their increasingly connected IT and OT environments can also create opportunities to reach operational systems through remote access, workstations and other connected infrastructure.

IT includes computers, servers, networks, applications and identity systems used to support business and administrative functions. OT includes systems such as SCADA, PLCs, sensors and HMIs that monitor and control physical processes.

CIS Benchmarks are primarily technology-specific configuration recommendations, so their applicability depends on the operating system, application or device involved. Where legacy OT cannot safely be modified, utilities can focus CIS hardening on the IT systems surrounding the OT environment and use segmentation and other compensating controls to reduce risk.

CIS Controls provide prioritized cybersecurity practices, while CIS Benchmarks provide specific configuration guidance for technology systems. CISA’s CPGs and EPA’s water-sector guidance establish broader cybersecurity priorities, but all are interconnected.

The key is to move beyond periodic assessments and manual remediation toward continuous monitoring and automated enforcement. Establish prioritized baselines, document exceptions, automate remediation where appropriate and continuously check for configuration drift. Automation is essential for enabling small teams to do more with less.

Share This Resource: