Skip to main content America 250 AI Economy Institute Cybersecurity Sustainability Microsoft on the Issues AI for Good Lab Communities Customer Security and Trust Energy, Connectivity, and Sustainability Open Data Trusted Technology Reports Hub US AI Diffusion Report Global AI Diffusion Report Environmental Sustainability Report Microsoft Digital Defense Report Microsoft Impact Summary Responsible AI Transparency Report Microsoft 365 Azure Copilot Windows Surface XBOX Deals Small Business Support Windows Apps Outlook OneDrive Microsoft Teams OneNote Microsoft Edge Moving from Skype to Teams Computers Shop XBOX Accessories VR & mixed reality Certified Refurbished Trade-in for cash XBOX Game Pass Ultimate PC Game Pass XBOX games PC games Microsoft AI Microsoft Security Dynamics 365 Microsoft 365 for business Microsoft Power Platform Windows 365 Small Business Digital Sovereignty Azure Microsoft Developer Microsoft Learn Support for AI marketplace apps Microsoft Tech Community Microsoft Marketplace Software companies Visual Studio Microsoft Rewards Free downloads & security Education Gift cards Licensing Unlocked stories View Sitemap
Policy Experts

How security fundamentals safeguard critical water infrastructure

As cyberattacks increasingly target small, under-resourced water utilities, a new program designed to make cybersecurity accessible, actionable, and free is helping frontline staff focus on the everyday behaviors and basic controls that stop many attacks before they start.

This video has no sound.

This video has no sound.

Share

Attackers are throwing out a wide net, hoping to catch people who don’t have basic protections in place.

Lessie Skiba,
Deputy Managing Director,
Cyber Readiness Institute

A group of cyberattackers looking to sow disruption targets the US. Where do they aim? New York City? Los Angeles? 

Not quite. Instead, think Aliquippa, Pennsylvania, population 9,000. Or Muleshoe, Texas, home to about 5,000 residents. In these and many other small towns and cities across the US, cyberattackers have tried to disrupt communities by targeting their water supply.  

“We go to our sink every morning to brush our teeth, and we assume the water is clean and it’s safe,” says Sasha Koff, Managing Director at the nonprofit Cyber Readiness Institute (CRI). “It’s something that we take for granted. For a bad actor, it’s a very easy way to affect a population.” 

Cyberattacks typically wreak havoc on digital systems. But at a water utility, a network breach can move quickly into the physical realm. Online systems can give an attacker access to operational technology—physical equipment like pumps, sensors, and chemical treatment systems.  

Breaching a regional utility might affect a relatively small population, but Kevin Reifsteck, Director for Cybersecurity Policy at Microsoft, explains that nation-state actors, or cyberattackers acting on behalf of a foreign government, are often motivated to attack these utilities.   

“One goal of nation-state actors is to create some kind of societal panic,” Reifsteck says. Affecting the operations of critical infrastructure like water and energy utilities is a particularly effective way to do that. And it’s not a US-specific issue. Around the world, cyberattacks on critical infrastructure are increasingly common in times of geopolitical unrest.  

An illustration of the United States, with an overlaid box that says, according to the US Environmental Protection Agency, 97% of the nation’s 156,000 public water systems serve fewer than 10,000 customers

Local utilities make prime targets because of their size. Most US water utilities are tiny operations: According to the US Environmental Protection Agency (EPA), 97% of the nation’s 156,000 public water systems serve fewer than 10,000 customers. “They typically don’t have the revenue to support dedicated IT or cybersecurity staff,” Reifsteck says. Often, one person manages everything from HR to IT.  

As a result, many of these facilities fall behind on cybersecurity. In 2024, the EPA found that 70% of utilities inspected by federal officials failed to meet standards meant to prevent breaches. These challenges are not unusual among small businesses, but at water utilities, the threats—and the consequences—are severe.  

What utilities may not realize is that the most impactful cyber protections they need are well within reach. Microsoft recently partnered with CRI, the Center on Cyber and Technology Innovation, and the Foundation for Defense of Democracies to pilot a free cyber readiness program for water utilities to understand how accessible, behavior-focused cybersecurity training could improve cyber defenses at water utilities.  

The results show that surprisingly uncomplicated solutions are effective—and they shine a light on what’s needed to protect critical infrastructure for the long term. 

The impact of a breach

The most alarming consequences of a cyberattack on a water utility come when hackers manage to take control of physical systems. 

A diagram showing the physical infrastructure a cyber actor in the digital realm can attack: human-digital interface, PLC, industrial equipment, and households

In a 2021 attack on a water facility in Oldsmar, Florida, a hacker gained remote access to water treatment systems and attempted to increase levels of sodium hydroxide, or lye, in the drinking water supply. Lye is typically used in very small amounts to control acidity, but the cyberattack sought to increase the chemical content from 100 parts per million to 11,100, which could be poisonous. A 2024 attack on a small Texas water facility caused a tank to overflow before it was taken offline. In April 2026, the US Cybersecurity and Infrastructure Security Agency issued a warning detailing specific attacks on programmable logic controllers, which control pumps and chemical flows as well as gather operational data at utilities.  

In some cases, like a 2024 attack on American Water, the utility is able to contain impact to digital systems such as billing and customer service portals by taking its operational technology offline, but even that causes significant disruption. 

There are also attacks that don’t cause immediate problems but pose future threats. Reifsteck points out that some hackers simply get into systems and observe—what he calls “prepositioning.” It’s a common phenomenon anywhere in the world where tensions might one day lead to conflict. For example, Microsoft has tracked a group called Volt Typhoon that is known for carrying out long-term, data-collecting cyber intrusions on utilities and other types of critical infrastructure in the US. 

In 2015, UN member states agreed to a set of norms for responsible conduct in cyberspace, including an agreement not to support cyberactivity that intentionally damages or hinders the operation of critical infrastructure. Today, some organizations, such as the Oxford Process on International Law Protections in Cyberspace, advocate creating a similar norm to address prepositioning.

Foundational cybersecurity thwarts bad actors 

Although breaches like these are becoming more common, many small utilities are not fully aware of the scale of the threat they face. “Just like a small business doesn’t think they have data anyone else would want, a small utility doesn’t think that they’re going to be a target of an attack,” says Lessie Skiba, Deputy Managing Director at CRI. “But attackers are throwing out a wide net, hoping to catch people who don’t have basic protections in place.” 

CRI’s cyber readiness training aims to keep utilities from getting caught in that net—and that’s not about spending lots of time and money, but making sure solid foundations are in place. 

Skiba points out that most breaches result from human error, and CRI’s program puts particular emphasis on teaching people to recognize phishing attempts and social engineering. The program also covers secure file storage and transfer, which is especially important at small organizations that often rely on thumb drives to share files.  

Utilities in the pilot program were also required to create strong password policies—international cybersecurity best practices recommend that passwords contain a minimum of 15 characters—enable multifactor authentication, and keep software updated. Some systems at utilities have older software with technical vulnerabilities that hackers can exploit, and if they can’t be updated or replaced, CRI recommends utilities disconnect them from the internet so they can continue to use them but attackers cannot remotely access them. 

Crucially, all participants created an incident response plan. “Knowing what to do if and when an incident occurs is really what cyber readiness is,” Skiba says. 

Given the severity of the threat, these solutions might seem basic, but the reality is, these fundamentals can provide effective protection against cyberattackers seeking an easy target.  

CRI’s program helps utilities put core cyber hygiene measures in place and reduce their most immediate risks. After completion, utilities are encouraged to continue building on that foundation, gradually maturing their cybersecurity practices to address more complex threats, strengthen operational resilience, and better protect the communities that depend on them.

But a lack of time and resources still proved to be a challenge during the pilot phase of the program. CRI and Microsoft found that it was difficult for staff at small utilities to complete the training on their own, but hands-on help from a CRI coach made a critical difference. “It’s just like going to the gym and having a trainer,” says CRI’s Koff. “Utilities need a coach to provide that consistent support.” 

For Reifsteck, this points to the need for partnerships between the public and private sectors. The results of the pilot program show how important it is for governments to publish cybersecurity guidance and best practices, but also to provide hands-on assistance to ensure the lessons stick. 

Another opportunity for improving water sector cyber defenses is incorporating cybersecurity programs like CRI’s into continuing education credits for workers at water utilities, which are required by many state governments. Koff notes that CRI worked with the state of New York to make its cyber readiness training a part of mandated continuing education programs. “It’s a great example of public, private, and nonprofit partnership,” Koff says, “which is a win for the greater public.” 

Securing water infrastructure doesn’t require reinvention. It requires making sure that every utility has the support to put the basics in place. Simple steps done well can make the difference between vulnerability and resilience for the communities that depend on these systems. 

CRI’s pilot program is now a permanent offering for critical infrastructure providers, with special provisions for water utilities. Learn more about how water utilities can get involved. 

Explore more

Stylized head shots of Nemanja “Neno” Malisevic and Kaja Ciglic, Senior Directors of Digital Diplomacy at Microsoft.

Cyberspace and the future of global diplomacy

An illustration of people approaching three kiosks labeled developers, access brokers, and negotiators

Five things you need to know about ransomware

City skyline with digital overlay, representing cybersecurity planning and cross-sector coordination

Strengthening cyber capacity in Kenya: A new toolkit with lessons for the region