Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityInfrastructure:Electric,Gas & WaterGovernment: Federal, State and Local

High Water Mark: CISA Shares Foundations for Effective Cybersecurity and Risk Management

By Mike Bimonte
Water faucet and cup
LuAnn Hunt via Unsplash
November 28, 2025

Over the past few years, there has been a steady flow of cyberattacks targeting the water and wastewater industry. The threat of nation-state attacks has never been higher. According to Armis’ recent report, Warfare Without Borders: AI’s Role in the New Age of Cyberwarfare, 87% of IT leaders are concerned about the impact of cyberwarfare on their organizations.

The notorious Chinese-linked Volt Typhoon has been targeting critical infrastructure, including Littleton Electric, Light, and Water Departments, for months. In 2023, Iranian hackers compromised a water treatment plant in Aliquippa, Pennsylvania. In 2024, American Water, the largest water utility in America, was targeted by a ransomware attack that caused a real-world service outage. 

According to CISA’s Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators, threat actors exploit vulnerabilities in unpatched systems and weak authentication controls to gain access to operational technology (OT) systems. Insufficient network segmentation and exposed remote access points enable lateral movement between systems.

But the root cause of these risks is a lack of visibility into the assets themselves and their behavior.

According to CISA, developing and maintaining an asset inventory and an OT taxonomy of critical systems enables organizations to prioritize their protection. In doing so, organizations can build the foundation of an effective continuous threat exposure management (CTEM) program.

Too Many Leaks, Not Enough Fingers

In the story Han Brinker, a little Dutch boy becomes “The Hero of Haarlem” after plugging a leak in a floodwall with his finger overnight. Cybersecurity professionals are no strangers to this sort of selfless sacrifice, frequently burning the midnight oil to prevent threats that never sleep. But the reality for many organizations is that there are too many leaks and not enough fingers.

Cybersecurity teams contend with hundreds, if not thousands, of alerts every day, but many of them are false positives. There were 40,000 vulnerabilities disclosed in 2024 alone, but not all vulnerabilities are created equally. The point is that there is both a lot of “signal” to process and a lot of “noise,” making it less useful.

And that only covers the assets that organizations can control. There are plenty of devices that go undiscovered and unmanaged, such as rogue or shadow IoT, in addition to mission-critical legacy devices that are unmanageable because they are incompatible with modern solutions and cannot be upgraded.

However, just as water and wastewater treatment plants can assess water quality using a variety of worthwhile metrics, such as when certain illnesses are on the rise, their security teams can find value in this stream of data; they just need the right facilities to process it.

Waste Not, Want Not

CISA recently published guidance to help OT owners and operators identify and protect mission-critical assets.

An asset inventory is a catalog of enterprise systems, such as hardware and software. An OT taxonomy categorizes and organizes critical assets and their relationships, enabling organizations to prioritize risk remediation and incident response. 

According to CISA, the benefits of an OT taxonomy include improved organization and management, enhanced communication, better decision-making, cost-saving efficiencies, and data analytics and insights.

Developing either an asset inventory or an OT taxonomy begins by identifying assets and collecting their attributes, such as IP address, supported communication protocols, and asset criticality.

An OT taxonomy classifies these assets by criticality or function-based groups within the organization, including control systems, monitoring tools, and management functions. 

Within the water and wastewater industry, pumps, aeration systems, emergency shutdown systems, SCADA systems, filtering systems, treatment reactors, chemical dosing systems, and spill containment systems are all examples of high-criticality assets.

Be Like Water

In the immortal words of Bruce Lee, “Be water, my friend.” What Lee meant was to remain adaptable. Water flows, water crashes, water takes the form of whatever vessel it fills. An effective cybersecurity practice is the same way.

Remaining adaptable begins with an asset inventory and OT taxonomy, allowing resources to flow where they are needed most. Comprehensive visibility is required to reflect what lies below the surface.

Likewise, cybersecurity can take on the shape of its environment by integrating security across IT, OT, cloud, and virtualized environments, and by using contextualization to prioritize protecting mission-critical assets. Organizations can map threats to frameworks, such as MITRE ATT&CK, to gain even greater insights and awareness.

These frameworks help shape an organization's cybersecurity program. In addition to CISA’s recent guidance, the EPA also published cybersecurity guidance in October 2025 after finding major gaps in the water sector, which also calls for improved visibility.

While gaining visibility into these risks and threats is an essential element of CTEM, it is just the foundation. Attack path validation simulates how real-world attacks flow so that organizations can identify vulnerable and exposed assets. Implementing network segmentation is an effective strategy to prevent lateral movement, just like one-way valves keep water flowing in the right direction.

Organizations should also implement continuous monitoring solutions to discover when new devices connect to the network and new vulnerabilities expose devices, as well as behavioral analytics to detect suspicious behavior indicative of an attack. AI-enabled solutions are particularly effective at detecting behavioral anomalies and can provide additional automation benefits to enhance operational efficiency.

Ultimately, in cybersecurity, as in nature, resilience flows from flexibility. Establishing a CTEM program is the foundation of this resilience. From local governments to the nation at large, this requires a whole-of-state and whole-of-nation approach across the public sector.

KEYWORDS: critical infrastructure cybersecurity Cybersecurity Infrastructure Security Agency water utilties security

Share This Story

Mike bimonte headshot

Mike Bimonte is Armis’ Chief Technology Officer of State, Local and Education. Image courtesy of Bimonte 

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Cables plugged in

Chinese Supercomputer Allegedly Hacked, 10 Petabytes of Data Stolen

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Abstract shape

What Are Security Experts Saying About Claude Mythos and Project Glasswing?

Padlock with computer keys

Breach of FBI Surveillance System Considered a “Major Incident,” Security Experts Weigh In

Executive Protection

Beyond the Bodyguard: Why Executive Protection Requires a New Playbook

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

May 7, 2026

Beyond Cameras: Revolutionizing Perimeter Security with LiDAR, AI and Digital Twins

In this webinar, we will explore how LiDAR‑based detection, AI‑powered analytics and digital twins are transforming the future of perimeter protection with 3D detection, real-time situational awareness and unified operational views.

May 12, 2026

Managing Large Scale Events in 2026: Security, Travel and Threat Intelligence

As the Americas prepare to host the world’s biggest football tournament in 2026, security, resilience, and travel risk leaders face a fast-moving threat environment that extends well beyond the stadiums. Learn the risks and readiness considerations that matter most.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing