Developing a Cybersecurity Plan for Water and Wastewater SCADA Systems
Water and wastewater utilities rely on supervisory control and data acquisition (SCADA) systems to monitor treatment processes, regulate pumping, manage chemical dosing, and maintain service continuity. These environments combine industrial control systems, operational technology (OT), information technology (IT), remote access, and field devices. A cyber incident can therefore affect public health, regulatory compliance, worker safety, and the availability of essential services.
A practical security plan must account for how a facility actually operates. Protecting a programmable logic controller (PLC) requires a different approach from securing an office laptop, cloud application, or billing database. The strongest programs connect cybersecurity controls with process safety, preventive maintenance, emergency response, and the daily responsibilities of operators and engineers.
For professionals across the Los Angeles Basin, peer learning is especially valuable. Technical events, facility tours, and workshops offered through LABS of CWEA can help agencies compare practices, discuss emerging threats, and build a shared understanding of resilient water infrastructure.
Define The Operational Environment
Start by documenting every system that supports treatment, collection, conveyance, and administrative operations. Include SCADA servers, human-machine interfaces (HMIs), engineering workstations, PLCs, remote terminal units, intelligent electronic devices, sensors, radios, cellular gateways, network switches, historians, backup systems, and vendor connections. The inventory should identify each asset’s owner, location, function, operating system or firmware, communication path, and replacement priority.
Network diagrams should show trust boundaries rather than simply drawing a line between “IT” and “OT.” Identify connections between corporate networks, control networks, safety systems, laboratory systems, cloud platforms, remote sites, and third-party maintenance services. Record which protocols are used, where data flows, and whether connections are continuously available or enabled only when needed.
This baseline supports risk-based decisions. A legacy PLC that cannot receive modern security patches may require compensating controls, such as network isolation and strict access restrictions. An unsupported SCADA server may need a replacement project, while a low-impact monitoring device may be managed through enhanced logging and physical controls.
Assess Threats And Consequences
A water utility should evaluate threats according to plausible pathways and operational consequences. Common scenarios include ransomware entering through an office network, stolen credentials being used for remote access, malicious changes to chemical dosing, manipulation of tank levels, denial-of-service attacks against communications, and unauthorized modification of PLC logic. Accidental actions, weak vendor practices, and removable media can create risks alongside deliberate attacks.
Risk analysis should consider more than data loss. Ask how an event could affect disinfectant residuals, effluent quality, worker exposure, flooding, pump availability, environmental permits, public communication, and continuity of service. Rank assets by safety and process impact, then assess the likelihood and detectability of each scenario. This produces a prioritized security roadmap instead of an unfocused list of technical vulnerabilities.
Useful references include the NIST Cybersecurity Framework, NIST guidance for industrial control systems, the AWWA cybersecurity guidance, and relevant federal and state requirements. These frameworks should inform local procedures rather than replace them. A small agency may begin with a focused assessment of high-consequence assets and expand its scope over time.
Build Segmented And Resilient Architecture
A secure SCADA architecture separates systems by function and limits unnecessary communication. Typical zones include business IT, a demilitarized zone for shared services, the SCADA supervisory layer, control networks, remote facilities, and safety-related equipment. Firewalls should enforce documented rules between zones, while one-way communication or tightly controlled data brokers may be appropriate for selected monitoring functions.
Remote access deserves particular attention. Replace shared accounts and permanently exposed services with individually assigned identities, multifactor authentication where technically feasible, time-limited approvals, and session logging. Vendor access should be disabled by default and activated for a defined maintenance window. Remote desktop tools, modems, cellular routers, and virtual private networks should be inventoried and reviewed regularly.
| Security Area | Practical Control | Evidence Of Maturity |
|---|---|---|
| Asset management | Maintain an approved inventory of OT devices and software | Named owner, location, function, and lifecycle status |
| Network security | Segment IT, SCADA, control, and remote-site traffic | Current diagrams and reviewed firewall rules |
| Identity and access | Use unique accounts, least privilege, and multifactor authentication | Access register and periodic reviews |
| Vulnerability management | Test patches and apply them through change control | Documented test results and maintenance records |
| Monitoring | Collect logs from critical servers, firewalls, and remote access tools | Alert thresholds, retention rules, and response records |
| Recovery | Maintain offline backups and tested restoration procedures | Successful recovery exercises with measured times |
Segmentation is most effective when paired with dependable operations. Devices should be hardened using approved configurations, unused services should be disabled, and engineering changes should require authorization. Because aggressive changes can disrupt treatment processes, every modification needs testing, rollback instructions, and coordination with control-room personnel.
Manage Identity, Changes, And Vendors
Access should be based on job responsibilities and limited to the systems required for each role. Operators may need control access but not administrative privileges; contractors may need temporary access to a specific workstation; engineers may require elevated permissions only during an approved change. Review accounts at least quarterly and remove access promptly when employees transfer roles or leave the organization.
Maintain a formal change-management process for PLC programs, HMI screens, alarm settings, firmware, firewall rules, and network configurations. Store approved versions in a protected repository and preserve the ability to compare current logic with a known-good baseline. A second-person review is valuable for changes that could affect chemical feed, pressure, flow, disinfection, or safety interlocks.
Third-party risk should be addressed in contracts and operating procedures. Vendors should disclose remote-access methods, security responsibilities, supported software versions, incident-notification timelines, and backup expectations. Before granting access, verify the technician’s identity, define the work scope, and record the session. The LABS of CWEA news page can also help professionals track relevant training, events, and water-sector developments that support ongoing awareness.
Detect Events And Respond Safely
Detection begins with useful telemetry. Collect authentication events, firewall activity, remote-access sessions, changes to PLC logic, engineering workstation alerts, antivirus status, and unusual communication between zones. Centralized logging is helpful, but alerts must be reviewed by someone who understands both cybersecurity and process operations. An unfamiliar command may be a serious intrusion or a legitimate maintenance action, depending on context.
Create incident playbooks for ransomware, unauthorized control changes, loss of communications, compromised credentials, malware on an engineering workstation, and suspected manipulation of process values. Each playbook should identify who can isolate equipment, who contacts management and legal counsel, how operators maintain safe process conditions, and when regulators, law enforcement, vendors, or public information staff are notified.
Exercises should include technical and operational participants. A tabletop scenario can test decision-making, while a controlled recovery drill can verify that backups, spare hardware, configuration files, and manual operating procedures are usable. Do not make an emergency response dependent on a network that may be unavailable. Maintain printed or offline contact lists, critical diagrams, valve and pump information, and safe shutdown or manual-control procedures.
Sustain A Culture Of Readiness
Cybersecurity becomes durable when it is integrated into standard utility management rather than assigned to a single specialist. Provide role-based training for operators, maintenance crews, engineers, managers, and contractors. Topics should include phishing, removable media, password practices, remote support, suspicious alarms, incident reporting, and the operational effects of disconnecting a device.
Measure progress with meaningful indicators: percentage of critical assets inventoried, time to disable departed-user accounts, completion of backup tests, number of overdue patches, remote sessions reviewed, and time required to detect and contain an event. These measures show whether the program is improving resilience, rather than simply counting policies or training completions.
Leadership continuity also matters. Institutional knowledge can be lost when experienced personnel retire or change roles, so procedures, diagrams, lessons learned, and decision authorities should be documented. The organization’s past presidents reflect the value of professional leadership and continuity—qualities that water agencies can apply to long-term OT security planning.
Priorities For The First Year
- Inventory and classify all SCADA, PLC, HMI, communications, and remote-access assets.
- Segment critical control networks and remove unnecessary internet exposure.
- Require unique accounts, least privilege, strong authentication, and documented vendor access.
- Establish tested backups for PLC logic, SCADA servers, configurations, and essential documentation.
- Conduct an incident exercise involving operators, IT staff, leadership, vendors, and public-information personnel.
A cybersecurity plan should be treated as a living operating program. Review it after major system changes, near misses, exercises, vendor transitions, and new regulatory guidance. Agencies that combine sound engineering, disciplined access control, reliable recovery, and practical workforce training will be better positioned to keep water and wastewater services safe and available.
LABS of CWEA members can turn these principles into facility-specific action through technical presentations, workshops, peer exchanges, and professional development opportunities. Use the next training or networking event to compare assessments, strengthen response procedures, and move your utility’s SCADA security program from documentation to dependable daily practice.