Protect treatment operations and the evidence behind decisions

Water & Wastewater Cybersecurity Assessment

Water and wastewater operations depend on control systems, business networks, communications and outside support. GDF examines those connections within an agreed scope, documents supported findings and helps the owner decide what to correct, validate and preserve.

Water treatment and electrical utility infrastructure.

Start with the system, operator and purpose

A drinking-water system, municipal wastewater plant, industrial treatment facility and regulated utility may have different owners, operating responsibilities and obligations. Establish the entity, facilities, systems and authorized work before selecting a regulatory or technical assessment scope.

Identify treatment and distribution dependencies alongside relevant identity systems, engineering workstations, historians, remote telemetry, vendor connections and business services. Population served, service connections and plant design flow answer different questions; one measure should not be substituted for another.

  • Drinking water: treatment, storage, pumping, distribution and the services supporting their operation.
  • Publicly owned treatment works: collection, pumping, treatment and discharge-related control dependencies.
  • Industrial water and wastewater: process connections, site responsibility and supporting treatment systems.
  • Regulated utilities: entity-specific obligations and evidence needs, separated from general OT risk review.

Connect access, architecture and operational consequences

Review available architecture, asset and configuration records with the people responsible for engineering, operations and IT. Examine where business services connect to the control environment and whether the intended network boundaries are supported by configuration and authorized validation.

Findings should identify the observed condition, supporting evidence, affected operational dependency and remaining uncertainty. A device inventory or automated scan alone does not explain the risk to a treatment process.

  • Asset and dependency records, including systems outside the plant that support operations.
  • IT/OT boundaries, permitted communications and engineering access.
  • Identity, account lifecycle, logging and relevant configuration history.
  • Prioritized corrective actions, responsible owners and evidence needed for verification.

Make vendor access accountable

Remote support can be essential to operations. Establish which vendor accounts, gateways and support tools exist, who authorizes their use and how access is restricted, recorded and removed. Shared credentials, persistent sessions and undocumented connections require a clear evidence-based review.

Compare intended access with available configuration and session records. Define the authorized question before any connection test, including the systems a vendor may reach and the circumstances in which access must stop.

Plan the method around treatment operations

Begin with interviews, existing records, configuration review and approved passive evidence. Operations and engineering identify sensitive equipment, maintenance windows, stop-work contacts and recovery arrangements. Active techniques require specific approval of the target, method, timing and operating conditions.

A laboratory or representative system may be the appropriate place to validate a concern. Exclude unsuitable techniques and document untested areas. Safeguards reduce risk, but no assessment can promise that production disruption is impossible.

Check what restoration would actually require

A backup record does not, by itself, demonstrate that a system can be restored. Review the configurations, software versions, licenses, communications, vendor support and people needed to recover a selected function. Agree on a representative recovery review or exercise only where operating conditions permit it.

Consider the evidence needed during an incident: relevant access and change records, synchronized time sources, isolation decisions and preservation responsibilities. Missing or short-lived records should be identified while the owner can still improve readiness.

Keep technical work and regulatory responsibilities clear

Cybersecurity can form part of a broader risk and resilience assessment and emergency-response planning effort. For an AWIA-related engagement, define the cybersecurity workstream and how it will be used alongside the other required assessment and planning components.

A cybersecurity review is not automatically a complete AWIA assessment or an entire state compliance program. The owner and its responsible advisers establish applicability, required submissions and certifications. GDF provides the technical work and evidence agreed in the engagement.

Receive findings with an accountable next step

The agreed deliverables record the systems and boundaries examined, methods used, supporting evidence, findings and limitations. Management receives a clear summary; restricted technical detail supports the people responsible for corrective work.

A follow-up scope can validate selected corrections or maintain a defined evidence and readiness calendar. Engineering implementation, independent audit, continuous monitoring and incident-response labor are separately agreed work.

  • Scope, responsibility map and assessment limitations.
  • Relevant asset, dependency, access and recovery records.
  • Evidence-supported findings and operational implications.
  • Corrective-action register with ownership, priorities and validation criteria.
  • Management and technical readouts suited to the agreed audience.

Scope your water assessment

Start with the facility type, general location, your role, the decision to be supported and any relevant planning date. Identify the operations, engineering and IT contacts who can authorize the work.

Keep security plans, credentials, network diagrams and incident evidence out of the inquiry form. Controlled information exchange is arranged separately. For an active incident, call to discuss the situation and response availability.

New York requirements depend on the water system

New York community drinking-water and wastewater programs have different coverage and dates. Confirm the responsible entity, system and applicable exclusions before defining a compliance-related scope.

DOH Appendix 5-E generally covers community drinking-water systems serving more than 3,300 people. January 1, 2027 is the general compliance milestone, with exclusions and earlier training and reporting provisions. Some personnel and monitoring requirements use a population tier greater than 50,000.

DEC identifies March 11, 2027 for New York publicly owned treatment works emergency plans and cybersecurity controls, and March 28, 2027 for initial annual certifications. Program requirements apply to all New York POTWs; the 10-MGD tier concerns network monitoring and logging, not whether the entire program applies.

A technical workstream is not automatically the complete required assessment, plan or certification. A commercial operator contract does not automatically transfer municipal certification authority. The owner and responsible advisers confirm obligations and signatory authority.

Sources checked October 6, 2026. New York DOH Appendix 5-E (opens in a new tab); New York DEC wastewater cybersecurity guidance (opens in a new tab).

For covered community drinking-water systems, cybersecurity is one component of the broader AWIA risk, resilience and emergency-planning obligations. EPA AWIA requirements (opens in a new tab).

Frequently asked

Common questions

Can you assess drinking water and wastewater in the same engagement?

An engagement can include both when the scope identifies each system, responsible entity and authorized boundary. Their operating dependencies and regulatory requirements should be recorded separately.

Is this assessment a penetration test?

The assessment reviews the agreed environment, access, dependencies, recovery and technical evidence. Penetration testing is a separate technique that requires a specifically authorized target and method. It is not automatically suitable for every production control system.

Can you build on an existing assessment?

Yes. Review the existing work for coverage, currency and limitations, then define the unresolved questions and evidence needed. New work can focus on a vendor connection, selected correction, recovery dependency or other agreed gap.

Does the cybersecurity assessment complete our AWIA requirements?

The agreed cybersecurity workstream can support a broader risk and resilience assessment and emergency-response planning. It should not be treated as all required assessment components, planning work or certification obligations. Confirm the full scope with the owner and responsible advisers.

Do we need to provide sensitive records with the first inquiry?

No. Start with general facility and scope information. Do not upload security plans, credentials, architecture or incident evidence through the marketing form. An approved controlled exchange can be arranged after the handling requirements are established.

Talk with an examiner

Scope your water assessment

Tell us whether you operate drinking-water, wastewater or another treatment system. Include your role, general location and the decision or timing the assessment must support. Share only broad facility details here.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.