Securing the Pathways Between IT and OT at America’s Water Utilities
If our nation’s water and wastewater utilities were looking for a good reason to align with CIS Benchmarks in their cybersecurity programs, the summer of 2026 gave it to them. At least 12 states were hit in what has been described as a coordinated attack by threat groups with suspected links to Iran.
This issue became particularly visible when 39 water systems across Minnesota and Michigan reported targeted attacks in late July and early August. Since then states from Texas to Pennsylvania are tightening security, Senators are introducing new legislation and government agencies are issuing warnings.
Thus far, drinking water and public health has remained safe across the USA’s 152,000 drinking water systems, but the attacks have shown us just how vulnerable our water supply is.
The summer 2026 water sector attacks, by the numbers
How IT and OT Work Together for SLED Cybersecurity
Most water and wastewater utilities in the US are operated and overseen by the state, local and education (SLED) sector of government.
These utilities use two primary types of technology.
Information Technology
Information technology (IT) encompasses the computers, servers, networks, applications and identity systems used to support the organization.
Operational Technology
Operational technology (OT) covers the systems that monitor and control physical processes, such as sensors, PLCs, SCADA systems, human-machine interfaces (HMIs), industrial computers and related equipment.
Historically, IT and OT were more isolated. But today, utilities are increasingly connected to IT networks and remote-access systems that support OT operation.
That convergence creates a growing cybersecurity risk. An attacker does not necessarily have to compromise a programmable logic controller (PLC) or SCADA system directly if they can first gain access through a poorly secured workstation, server, remote-access host or other IT system connected to the operational environment.
Every connection between IT and OT creates a potential pathway for hackers to exploit.
What happened
In recent attacks, hackers were able to access internet-facing PLCs and other control computers and change their IP addresses and passwords. This resulted in a loss of control functionality, which the utilities countered by shutting down the affected technologies and sending workers out into the field to operate equipment manually.
Additional Security Challenges for Water Utilities
Some utilities depend on equipment that has been operating for years or even decades. Older systems may not have modern security capabilities. Patching may require extensive testing or coordination with the equipment manufacturer. A reboot that is routine in an office environment may be unacceptable in a system responsible for a continuous physical process.
There may also be vendor restrictions, warranty considerations or compatibility requirements that prevent operators from making configuration changes freely. In short, traditional IT security practices do not always translate cleanly to OT.
The goal isn’t to apply every modern security control directly to every OT device. The goal is to reduce the pathways an attacker can use to reach that OT. The greater challenge for many SLED organizations, however, is that they have limited cybersecurity staff and limited budgets to harden systems and rethink how workers and collaborators interact with their networks. Because it lends itself well to automation, CIS Benchmarks can provide a practical, efficient starting point for securing critical systems.
Where CIS Benchmarks Fit in Water and Wastewater Utilities
CIS Benchmarks provide a roadmap for securely configuring operating systems, cloud platforms, network devices and other technology products. Developed by the Center for Internet Security (CIS), they provide prescriptive, consensus-based recommendations developed by global cybersecurity experts.
They are also one of the few such frameworks that can be automated to scan, remediate, validate and report on the hardening processes used, thereby easing the burden on staff and budgets while minimizing the attack vectors to reaching your OT.
For a water utility, that makes CIS Benchmarks particularly useful for systems such as:
| Utility Asset | Potential Role at IT/OT Boundary | Applicable CIS Benchmarks for OS or application |
|---|---|---|
| Engineering workstations | Engineers configure and maintain operational systems | Windows/Linux workstation CIS Benchmarks, Level 1 or Level 2 |
| Operator/HMI workstations | Operators monitor and interact with processes | Applicable OS/application CIS Benchmarks |
| Historian servers | Collect and store operational data | Windows/Linux Server CIS Benchmarks |
| SCADA support servers | Support supervisory control applications | Applicable server/application CIS Benchmarks |
| Jump boxes | Controlled pathway for administrative or remote access | Applicable server/OS CIS Benchmarks, with strict access controls |
| Remote-access hosts | Provide vendor or operator connectivity | Applicable OS/application CIS Benchmarks plus access hardening |
| Domain controllers | Provide identity and authentication services | Windows Server Domain Controller CIS Benchmarks |
| Management servers | Administer systems across the environment | Applicable server CIS Benchmarks |
CIS Benchmarks commonly distinguish between Level 1 and Level 2 recommendations. Level 1 generally represents practical security configuration intended to provide strong protection without significantly impairing system functionality. Level 2 applies more stringent settings intended for systems requiring higher security.
Why hardening levels matter
This matters because aggressive hardening that breaks an operational application is not a successful security program. Different levels and flexibilities in policy mean you can establish the appropriate hardened configurations for the IT systems that have access to operational environments. Where direct hardening isn’t possible, network segmentation, access controls and other compensating measures can help reduce risk.
How CIS Controls, CISA and EPA Guidance Work Together
CIS Benchmarks should not be viewed as a replacement for the cybersecurity guidance already available to water utilities, rather they are a practical implementation layer.
CISA’s Cross-Sector Cybersecurity Performance Goals (CPGs) provide a prioritized set of cybersecurity practices intended to help critical-infrastructure organizations reduce risk. EPA has incorporated that approach into its water-sector cybersecurity guidance and their cybersecurity checklist for drinking-water and wastewater systems was derived from the CISA CPGs.
CIS Benchmarks complement these resources by providing technology-specific configuration guidance. CIS Controls also have published mappings to the NIST Cybersecurity Framework. NIST SP 800-82 offers OT-specific guidance for organizations that need to go deeper.
All these approaches work together to secure systems, with each serving a different purpose in providing a path from cybersecurity strategy to actual system configuration:
From strategy to configuration
- CISA CPGs indicate which high-priority cybersecurity outcomes an organization should pursue
- EPA guidance tells you how those priorities apply specifically to water and wastewater systems
- NIST outlines how an organization can structure a broader cybersecurity and OT risk-management program
- CIS Controls reveal which prioritized security practices the organization should implement
- CIS Benchmarks tell you how specific systems should be configured
- Automation simplifies how those configurations are implemented and maintained consistently
Building a Phased Hardening Program on a Lean Budget
Trying to harden everything at once can overwhelm a small SLED cybersecurity team. A phased approach is more manageable.
Build an inventory
You cannot secure systems you don’t know exist. Start by identifying the systems that have access to operational environments, including engineering workstations, operator workstations, servers, jump boxes and remote-access systems.
Identify the IT/OT boundary
Prioritize systems that can communicate with or administer OT. Keep in mind that not every endpoint represents the same risk. A compromised office printer is a problem. A compromised engineering workstation with privileged access to a SCADA environment is potentially a much bigger problem.
Establish a baseline
Apply CIS Benchmarks to supported operating systems and applications where appropriate. For a resource-constrained organization, CIS Controls Implementation Group 1 (IG1) provides a logical starting point. CIS describes IG1 as “essential cyber hygiene” and the on-ramp to the broader CIS Controls.
Document exceptions
Utilities will encounter systems that cannot safely accept a particular configuration. Don’t ignore those exceptions. Document them, identify the reason, assess the residual risk and establish compensating controls such as segmentation, restricted access or enhanced monitoring.
Maintain the baseline
Hardening a system once doesn’t mean the system remains hardened. Software updates, emergency changes, new accounts, vendor maintenance and troubleshooting can all introduce configuration drift. Your process should continuously verify your systems remain aligned with the approved baseline.
This last issue of drift is where many cybersecurity programs break down. When it comes to baselines, what’s true today is not necessarily true tomorrow. Which presents an issue for small teams who may be responsible for hundreds or thousands of systems while also handling help desk requests, infrastructure upgrades, emergency incidents, vendor relationships and daily operations.
Manually checking every configuration isn’t sustainable. Neither is maintaining compliance through spreadsheets and screenshots. And the problem becomes even more complicated in segmented or disconnected environments where cloud-dependent security tools may be difficult or impossible to deploy. This is why automation is increasingly important to CIS Benchmarks implementation.
ConfigOS scans, remediates and continuously enforces CIS Benchmarks on the workstations, servers and jump boxes that touch your operational environment — even in air-gapped networks.
Automating CIS Benchmarks Enforcement
Unified automation can turn CIS Benchmarks from a periodic compliance exercise into an operational security process. From a single console, you can scan systems, remediate configuration issues, report results and, where approved and appropriate, continuously sustain security baselines.
SteelCloud’s ConfigOS platform, for example, is designed for environments where connectivity may be restricted, such as classified, air-gapped and cloud. A solution like this can scan and remediate thousands of endpoints per hour, while reducing the manual effort associated with hardening. The linked guide outlines a phased path to CIS Benchmarks implementation in 100 days.
Scalable automation can ease the workload for a lean cybersecurity team. Instead of repeatedly finding and fixing the same configuration problems by hand, security personnel can establish an approved baseline and automate its enforcement.
Protecting Infrastructure with CIS Benchmarks for Water Utilities
The recent attacks against water utilities are a reminder that cybersecurity isn’t simply about protecting data. A cyberattack against a utility can potentially affect physical processes, public services and public safety.
While you may not be able to harden the OT itself, you can harden supported IT systems that have access to it by applying CIS Benchmarks. You can make the path to your critical infrastructure harder to traverse. And you can automate the enforcement of your configurations so that security doesn’t disappear the moment the next software update or emergency change occurs.
Some practical and simple steps you can do today are to research CIS Benchmarks automation solutions, see how they fit into your budget and schedule a ConfigOS demo to see how much easier baseline hardening can be when manual methods are set aside. From there, you’ll have the information you need to implement CIS Benchmarks and provide a secure foundation for all your compliance efforts.
Protect the Systems That Reach Your Water Infrastructure
Frequently Asked Questions
Why are water and utility systems such frequent cyberattack targets?
Water and utility systems provide essential public services, making them attractive targets for attackers seeking disruption or influence. Their increasingly connected IT and OT environments can also create opportunities to reach operational systems through remote access, workstations and other connected infrastructure.
What is the difference between IT and OT in a utility environment?
IT includes computers, servers, networks, applications and identity systems used to support business and administrative functions. OT includes systems such as SCADA, PLCs, sensors and HMIs that monitor and control physical processes.
Can CIS Benchmarks be applied to OT and SCADA systems?
CIS Benchmarks are primarily technology-specific configuration recommendations, so their applicability depends on the operating system, application or device involved. Where legacy OT cannot safely be modified, utilities can focus CIS hardening on the IT systems surrounding the OT environment and use segmentation and other compensating controls to reduce risk.
How do CIS Benchmarks and Controls align with CISA and EPA guidance?
CIS Controls provide prioritized cybersecurity practices, while CIS Benchmarks provide specific configuration guidance for technology systems. CISA’s CPGs and EPA’s water-sector guidance establish broader cybersecurity priorities, but all are interconnected.
How can a small SLED IT team maintain alignment with CIS Benchmarks over time?
The key is to move beyond periodic assessments and manual remediation toward continuous monitoring and automated enforcement. Establish prioritized baselines, document exceptions, automate remediation where appropriate and continuously check for configuration drift. Automation is essential for enabling small teams to do more with less.
Resource Library
Recent Resources
- How CIS Benchmarks Help Protect Water Utilities From Cyberattacks
- SteelCloud Announces Daniel Merlau to Advisory Board
- SERIES: A Peek Inside ConfigOS MPO Key Features – Shield Update with Commander
- USE CASE: Centralizing and Automating CIS Benchmarks Hardening Across 20+ Community Colleges
- The Educator’s Guide to CIS Benchmarks Adoption