Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityInfrastructure:Electric,Gas & WaterGovernment: Federal, State and Local

High Water Mark: CISA Shares Foundations for Effective Cybersecurity and Risk Management

By Mike Bimonte
Water faucet and cup
LuAnn Hunt via Unsplash
November 28, 2025

Over the past few years, there has been a steady flow of cyberattacks targeting the water and wastewater industry. The threat of nation-state attacks has never been higher. According to Armis’ recent report, Warfare Without Borders: AI’s Role in the New Age of Cyberwarfare, 87% of IT leaders are concerned about the impact of cyberwarfare on their organizations.

The notorious Chinese-linked Volt Typhoon has been targeting critical infrastructure, including Littleton Electric, Light, and Water Departments, for months. In 2023, Iranian hackers compromised a water treatment plant in Aliquippa, Pennsylvania. In 2024, American Water, the largest water utility in America, was targeted by a ransomware attack that caused a real-world service outage. 

According to CISA’s Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators, threat actors exploit vulnerabilities in unpatched systems and weak authentication controls to gain access to operational technology (OT) systems. Insufficient network segmentation and exposed remote access points enable lateral movement between systems.

But the root cause of these risks is a lack of visibility into the assets themselves and their behavior.

According to CISA, developing and maintaining an asset inventory and an OT taxonomy of critical systems enables organizations to prioritize their protection. In doing so, organizations can build the foundation of an effective continuous threat exposure management (CTEM) program.

Too Many Leaks, Not Enough Fingers

In the story Han Brinker, a little Dutch boy becomes “The Hero of Haarlem” after plugging a leak in a floodwall with his finger overnight. Cybersecurity professionals are no strangers to this sort of selfless sacrifice, frequently burning the midnight oil to prevent threats that never sleep. But the reality for many organizations is that there are too many leaks and not enough fingers.

Cybersecurity teams contend with hundreds, if not thousands, of alerts every day, but many of them are false positives. There were 40,000 vulnerabilities disclosed in 2024 alone, but not all vulnerabilities are created equally. The point is that there is both a lot of “signal” to process and a lot of “noise,” making it less useful.

And that only covers the assets that organizations can control. There are plenty of devices that go undiscovered and unmanaged, such as rogue or shadow IoT, in addition to mission-critical legacy devices that are unmanageable because they are incompatible with modern solutions and cannot be upgraded.

However, just as water and wastewater treatment plants can assess water quality using a variety of worthwhile metrics, such as when certain illnesses are on the rise, their security teams can find value in this stream of data; they just need the right facilities to process it.

Waste Not, Want Not

CISA recently published guidance to help OT owners and operators identify and protect mission-critical assets.

An asset inventory is a catalog of enterprise systems, such as hardware and software. An OT taxonomy categorizes and organizes critical assets and their relationships, enabling organizations to prioritize risk remediation and incident response. 

According to CISA, the benefits of an OT taxonomy include improved organization and management, enhanced communication, better decision-making, cost-saving efficiencies, and data analytics and insights.

Developing either an asset inventory or an OT taxonomy begins by identifying assets and collecting their attributes, such as IP address, supported communication protocols, and asset criticality.

An OT taxonomy classifies these assets by criticality or function-based groups within the organization, including control systems, monitoring tools, and management functions. 

Within the water and wastewater industry, pumps, aeration systems, emergency shutdown systems, SCADA systems, filtering systems, treatment reactors, chemical dosing systems, and spill containment systems are all examples of high-criticality assets.

Be Like Water

In the immortal words of Bruce Lee, “Be water, my friend.” What Lee meant was to remain adaptable. Water flows, water crashes, water takes the form of whatever vessel it fills. An effective cybersecurity practice is the same way.

Remaining adaptable begins with an asset inventory and OT taxonomy, allowing resources to flow where they are needed most. Comprehensive visibility is required to reflect what lies below the surface.

Likewise, cybersecurity can take on the shape of its environment by integrating security across IT, OT, cloud, and virtualized environments, and by using contextualization to prioritize protecting mission-critical assets. Organizations can map threats to frameworks, such as MITRE ATT&CK, to gain even greater insights and awareness.

These frameworks help shape an organization's cybersecurity program. In addition to CISA’s recent guidance, the EPA also published cybersecurity guidance in October 2025 after finding major gaps in the water sector, which also calls for improved visibility.

While gaining visibility into these risks and threats is an essential element of CTEM, it is just the foundation. Attack path validation simulates how real-world attacks flow so that organizations can identify vulnerable and exposed assets. Implementing network segmentation is an effective strategy to prevent lateral movement, just like one-way valves keep water flowing in the right direction.

Organizations should also implement continuous monitoring solutions to discover when new devices connect to the network and new vulnerabilities expose devices, as well as behavioral analytics to detect suspicious behavior indicative of an attack. AI-enabled solutions are particularly effective at detecting behavioral anomalies and can provide additional automation benefits to enhance operational efficiency.

Ultimately, in cybersecurity, as in nature, resilience flows from flexibility. Establishing a CTEM program is the foundation of this resilience. From local governments to the nation at large, this requires a whole-of-state and whole-of-nation approach across the public sector.

KEYWORDS: critical infrastructure cybersecurity Cybersecurity Infrastructure Security Agency water utilties security

Share This Story

Mike bimonte headshot

Mike Bimonte is Armis’ Chief Technology Officer of State, Local and Education. Image courtesy of Bimonte 

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

Popular Stories

Tree shaped as dollar sign

The Salary of a Chief Security Officer

Classroom with rows of desks facing a chalkboard

The AI Powered Classroom Network of the Future: Because Hackers Never Take Recess

Jaguar logo

New Update on Jaguar Land Rover Cyberattack: Q3 Wholesales Down 43%

Cloud icon

Google Cloud Service Exploited in New Phishing Campaign

Person holding phone to smart lock

Why it’s Time to Move on From Legacy Access Control Systems

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

February 26, 2026

Zero Incidents vs. Zero Tolerance – Workplace Violence Prevention Best Practices that Work

Workplace violence remains one of the most complex challenges facing healthcare organizations today. For executive security professionals, the stakes have never been higher: protecting staff, patients, and visitors while preserving a culture of compassion, dignity, and service.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing