© ROOT-NATION.com - Use of content is permitted with a backlink.
In late July, a series of cyberattacks targeted water and wastewater utilities in the United States, prompting the FBI, EPA, and CISA to issue a joint advisory. The advisory describes the activity, identifies the methods used, and provides recommendations for the sector. Experts note that the attacks targeted operational and administrative systems on which the safe supply of water depends.
Read also: AERONAUT – everything that flies above the ground: aviation, UAVs and drones, rockets, and space
The recommendations consist of a list of measures to mitigate risks. The most useful thing a utility company can do is to map these recommendations onto the timeline of an actual incident to understand which measures should be taken immediately as part of preparedness, and which capabilities should already be available when the incident begins.

The recommendations for the first six hours involve detecting, containing, and eliminating unauthorized access by verifying remote access paths, resetting credentials, and isolating compromised segments. The timeline adds another consideration: each of these actions is coordinated by people, and during the first few hours, they are working at night and on weekends. The companies that acted most quickly during the July attacks were those that were able to assemble a response team within minutes via secure channels and confirm who had joined. The speed of notification and the reliability of communication are the foundation upon which the implementation of the recommended actions rests.
Read also: GPT-5.6 “escaped the sandbox” and hacked Hugging Face: OpenAI reveals details
Over the course of 1–3 days, as containment efforts continue, the recommendations shift toward strengthening defenses: segmenting IT and OT networks, removing unnecessary internet access to control systems, and verifying backups. During this period, a practical constraint for most small enterprises is the need to carry out all of this while continuing to ensure water supply, inform regulators, coordinate with neighboring systems, and communicate with the public. Yet such operators often have a staff of fewer than ten people. A dedicated, secure coordination channel between management and operational units prevents technical and institutional operations from conflicting with one another.

The guidance also includes mitigation measures. Some recommendations are designed for the longer term – from the first week onward – such as advice on data security, monitoring, and incident response planning.
Two exercises will quickly justify the cost. The first is a drill on contacts and notifications: how long does it take to contact each response team member and confirm receipt of the message, and can this process withstand the loss of corporate email and telephone communications? The second is a drill on operating via a secure channel: if major networks are compromised tomorrow, through which channel will leadership discuss containment, and will that channel be encrypted, authenticated, and independent of the compromised infrastructure?
Read also: Space Hacking by NASA: How 1970s Technology Is Saving Voyager 1 From Shutting Down
Most organizations that conduct such drills identify the same three gaps: alerts depend on a manual call tree, the backup coordination channel is a regular messaging app on a personal device, and no one can say for certain which devices in the response chain are controllable and have up-to-date software. In fact, all these issues can be resolved within a quarter.

The July attacks and joint alerts confirm that this critical infrastructure is a target of attacks; this targeting has been documented in federal alerts, and the operators responsible for its protection are among the most resource-constrained across all sectors. But the solution lies not in implementing all the recommendations from the alerts at once, but in taking a step-by-step approach. First, coordination must be secured, as every other mitigation measure depends on it.
Read also: Global Cyber Heist: Worldwide Losses from Hackers Have Reached $1.24 Trillion




