Recent cyberattacks targeting the U.S. water and wastewater systems (WWS) sector have underscored the urgent need for enhanced cybersecurity measures within critical infrastructure. The National Institute of Standards and Technology (NIST) has responded to these challenges by publishing guidelines aimed at securing remote access to operational technology (OT) environments, a crucial step in safeguarding public health and national infrastructure. The guidelines, outlined in NIST Special Publication 1800-45, provide a framework for utilities to implement secure remote access solutions, addressing vulnerabilities that have been exploited in recent attacks.
Understanding the Threat Landscape
In late July 2026, a surge in cyberattacks against WWS utilities was reported, with threat actors specifically targeting OT devices rather than traditional information technology (IT) systems. Alerts from the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Environmental Protection Agency (EPA) indicated that attackers were infiltrating internet-facing components, particularly programmable logic controllers (PLCs), to disrupt operations. This shift in focus highlights the critical vulnerabilities present in OT environments, which are increasingly interconnected and exposed to external threats.
Challenges in Securing Water and Wastewater Systems
The U.S. WWS sector comprises nearly 50,000 community water systems and over 16,000 wastewater treatment facilities, varying significantly in size and complexity. While larger utilities may have the resources to implement robust cybersecurity measures, smaller systems often struggle with limited budgets and expertise. This disparity necessitates adaptable security approaches that can be effectively implemented across the sector.
The digital transformation of WWS utilities has introduced efficiencies but also increased cybersecurity risks. Many systems are now remotely monitored and controlled, creating potential entry points for cyberattacks. The connectivity that enhances operational capabilities also exposes these systems to unauthorized access, particularly when security measures are inadequate.
NIST’s Guidelines for Secure Remote Access
The NIST guidelines emphasize the importance of a layered security approach to remote access in OT environments. Key recommendations include:
- Implementing multifactor authentication (MFA) to validate user identities.
- Utilizing encryption for data and network traffic to protect sensitive information.
- Establishing network segmentation to isolate OT systems from broader enterprise networks.
- Employing specialized servers to manage access and monitor network traffic.
These measures are designed to mitigate risks associated with remote access, ensuring that utilities can maintain operational resilience even in the face of cyber threats.
Practical Applications and Future Directions
The NCCoE has collaborated with various stakeholders in the WWS sector to develop reference architectures that demonstrate how these security controls can be implemented effectively. For instance, one approach involves configuring firewalls and remote access servers to protect OT resources, while another utilizes cloud-based solutions for smaller utilities lacking extensive IT infrastructure. Additionally, automated system-to-system communication can be secured through hardware encryption, ensuring that data exchanged between OT systems remains protected.
Looking ahead, NIST is launching a new project focused on OT asset management and visibility, recognizing that effective cybersecurity begins with a comprehensive understanding of the assets within an organization. By improving asset visibility, utilities can better manage their security posture and respond to emerging threats.
As the WWS sector continues to evolve, the implementation of NIST’s guidelines will be crucial in enhancing cybersecurity resilience. By prioritizing secure remote access and adopting a holistic approach to risk management, utilities can better protect their critical infrastructure from the growing threat of cyberattacks.
For further insights into securing operational technology environments, refer to the NIST Cybersecurity Insights blog.


