18706_Authority_Oct

16 The Authority | October 2025 unauthorized connections are established for maintenance or operational convenience. These ad hoc interactions can inadvertently create pathways for unauthorized access, increasing the risk of compromise. • Limited cyber expertise: operators and engineers are experts in water treatment, not necessarily in network security. Without dedicated cybersecurity staff, many utilities struggle to assess risk, implement controls, or respond to incidents. The language that is spoken by IT professionals typically clashes with the perspective of the operators that work in these environments every day. • Operational priorities: the “if it isn’t broken, don’t fix it” mindset persists. When systems appear to function normally, cybersecurity investments can be deprioritized—until an attack exposes the gaps. Although these gaps are identifiable through low-cost means, they can be overlooked when focused on the current functionality. Emerging technology: opportunity and risk Despite these challenges, the water sector is undergoing a digital transformation where many utilities are adopting: • Smart sensors for real-time monitoring of flow, pressure and water quality • Cloud-based SCADA systems for remote access, scalability and data analytics • AI and machine learning (ML) for predictive maintenance, flow optimization and anomaly detection These technologies offer tremendous benefits. AI, for instance, can analyze motor currents and bearing temperatures to predict equipment failure before it happens, and additional aid in capital improvement planning for realistic equipment lifespans. Cloud platforms enable centralized control across distributed assets and smart sensors provide granular visibility into system performance. But with innovation comes risk. Each new connection, device or data stream expands the attack surface. Cloud systems require robust identity management and encryption. Smart sensors must be authenticated and monitored. AI models depend on secure, high-quality data—and that data must be protected from tampering or exfiltration. Security must be embedded from the start. Retrofitting cybersecurity into digital infrastructure is costly and complex. Utilities must adopt a “secure by design” approach, ensuring that every new technology is evaluated not just for functionality, but for resilience with a consequences-driven viewpoint. Operational technology: the front line of defense Protecting OT systems and networks requires a different mindset than securing IT. OT environments prioritize uptime and safety. Downtime can mean service disruption or even contamination. Security controls must be tailored to these realities. Key strategies include: • Network segmentation: separating OT from IT networks limits the spread of malware and unauthorized access. Critical systems should be isolated with firewalls and access controls. • Patch management: while patching OT systems can be disruptive, unpatched vulnerabilities are a common attack vector. Utilities must develop structured processes for testing and applying updates. • Access control: role-based access, multi-factor authentication and regular audits help ensure that only authorized personnel can interact with sensitive systems. Managing passwords can also alleviate the dependence on shared passwords for critical components. • Monitoring and detection: continuous monitoring of OT networks can identify anomalies—such as unexpected changes in setpoints or unauthorized logins—that may be an indication of an attack or at least a situation that needs attention. • Incident response planning: utilities must be prepared to respond quickly and effectively to cyber incidents. This includes maintaining backup systems, enabling manual override capabilities and establishing clear communication Continued on page 46. b oards and executIves must understand that cyber rIsK Is operatIonal rIsK .

RkJQdWJsaXNoZXIy MjY5OTU3