Wikideas1 via Wikimedia Commons Over the past few months, U.S. water systems have been the target of increased cyberattacks, widely suspected to be from Iranian state actors, with more than 100 attacks reported across seven states.
Fortunately, none of the reported attacks have resulted in water outages or contamination, but their growing number highlights common vulnerabilities in operational technology systems.
Further reading:
- Are civil engineers ready for cyberspace?
- ASCE leads AI vision in civil engineering with ‘AI RACE’ roadmap
- Texas utility launches landmark water reuse project
In a recent ASCE webinar, Beyond Connectivity: Securing Smart Cities Through Cyber Resilience, Bill Bowers, chief information security officer for American Water, said that cyberattacks can no longer be considered simply an information technology issue.
“The consequences don’t just land in IT; they land in the physical world,” he said. “These aren’t just information breaches anymore. … These are cyber events that are having a kinetic impact on buildings, on hospitals, on water systems across the country.”
As a result, today’s civil engineers must consider more than just physical systems in their designs. Designing and maintaining safe and effective water infrastructure also requires thinking about how those physical structures intersect with commonly implemented operational technology systems, including programmable logic controllers and communication systems. Protecting public safety depends on it.
A broader attack surface
Bowers said the risk of infrastructure cyberattacks has expanded over the past few years – and artificial intelligence has played a significant role.
“There was a time when it took a bad guy sitting at a computer to find an exploit and take advantage of it,” he said. “What we’re seeing now is an AI agent that doesn’t need to eat, doesn’t need to sleep, doesn’t need to go to the bathroom – it can just go all day and find these things that are out there.”
He added that greater interdependencies across different pieces of infrastructure, as well as implementation of remote access controls during the pandemic, have contributed to a larger attack surface. Another factor that has increased vulnerabilities, said Andrew Ohrt, P.E., CISSP, an environmental engineer and cybersecurity expert for West Yost, is the reliance on small regional systems integrators, especially in small- and medium-sized water systems.
“These integrators are very good … at improving performance and reliability, but they have not developed the security skills and knowledge to secure these systems,” he said. “We see cybersecurity gaps in every single project we do for systems that have relied on an integrator – there isn’t an understanding of potential attack pathways or how to secure those pathways.”
That’s important because without adequate visibility into your systems, you may not see opportunities for malicious actors to penetrate these vital services.
“If something gets put into your environment and you don’t know about it, it’s very difficult to secure it,” Ohrt said. “There could be vulnerabilities on it that you’re just not aware of.”
A focus on resilience and recovery
In 2023, the National Infrastructure Advisory Council warned that current U.S. water infrastructure was “unsustainable,” thanks to a combination of issues, including lack of funding, climate change, and increasing cyberthreats. It is worth noting this was years before the recent spate of cyberattacks directed at water systems. The question becomes what civil engineers should be doing to help combat malicious cyber actors, even as they must design systems addressing these other challenges.
Bowers said that building strong security controls starts with recognition that cyberattacks are going to happen – and focusing on how to recover from them.
“It’s a transition from ‘How do we prevent the bad guys from getting in?’ to ‘How do we ensure services are going to be available even if the bad guy does get into your environment?’” he said. “One prevalent (strategy) is having the ability to operate plants manually … so that water and wastewater systems continue to operate regardless of what’s happening from the cyber side.”
Ohrt said engineers benefit when they adopt cyber-informed engineering, or an approach that integrates cybersecurity into the conception, design, development, and operation of infrastructure systems.
U.S. Department of Agriculture“It’s the engineers, ultimately, who have licensure and ultimate responsibility of a project,” he said. “Cyber-informed engineering makes it easier to understand cyberthreats on engineering terms and figure out what to do about them.”
He added that the Department of Homeland Security has rolled out a program called CI Fortify, first developed in Australia, that can help engineers and infrastructure stakeholders better reinforce their systems to ensure that they can maintain service delivery even in the event of an attack.
“(The program) asks questions like, ‘Can you carry out your critical functions for three months without technology or communications?’” said Ohrt. “It really helps you to understand the different interdependencies you have with your technologies and software and how far you can go without them.”
Increased resiliency is a ‘journey’
Bowers and Ohrt maintain that civil engineers must understand it’s not a matter of if, but when an attack on infrastructure might occur. Ohrt said fortifying water systems to be more resilient is a “journey” – and one that engineers should be contributing to.
“It’s easy to say, ‘Oh, we just don’t have the money right now’ – and that’s a valid thing because many stakeholders are public agencies that rely on a planning cycle,” he said. “But there are three low-cost things you can do right now. One, put money in the budget for next year. And if you are planning ahead for the next couple years, put money in there too.
“Second, start working to understand all the dependencies in your system and where the vulnerabilities exist. You can do tabletop exercises, working through different scenarios, or you can just go to your operations team and ask them to walk you through a process and ask what happens if you don’t have communications or a PLC there. They are the experts, and they can answer those questions.
“Third, there are excellent resources available through the Cybersecurity and Infrastructure Security Agency. Reach out to your local CISA rep, and take advantage of those services to become more resilient.”
Bowers said engineers have to think about the future as they design key infrastructure like water systems, as the goal is for them to last decades. That may seem daunting, given the ever-evolving cyberthreat landscape. But, for his part, he believes it makes it more imperative that civil engineers consider cybersecurity as a design requirement from the beginning of any structure’s life cycle.
“Thinking about cyber as a driving factor in some of our decisions from the very beginning means we’re not forced to tackle these things at the end,” he said.

Feed Your Brain
Interested in important infrastructure-related topics like the one? Registration is open for ASCE2027: The Infrastructure and Engineering Experience, which will be a first-of-its-kind event bringing together subject-matter experts from all across the infrastructure space, March 1-5, 2027, in Philadelphia. So, yes, we know you’re excited about the Philly cheesesteaks, but ASCE2027 also is the perfect place to satisfy your appetite for learning.
Technical deep dives. Infrastructure expertise. Come feast!
Learn more about ASCE2027: The Infrastructure and Engineering Experience.