Minnesota Water System Attacks Prompt NAWC Call For Stronger Cybersecurity Standards
By Kevin Westerling,
@KevinOnWater

Recent cyberattacks targeting more than 30 Minnesota community water systems have renewed scrutiny of cybersecurity preparedness across the water sector and intensified calls for stronger federal oversight and standards. In response to the incidents, the National Association of Water Companies (NAWC) is urging Congress to advance legislation aimed at improving cybersecurity resilience across drinking water and wastewater systems.
Statement from NAWC President and CEO Robert F. Powelson:
“Critical infrastructure is squarely in the sights of international threat actors seeking to disrupt essential services with the water sector as a prime target.
Cybersecurity preparedness across the nation’s water and wastewater systems varies widely. While more than 90% of National Association of Water Companies (NAWC) members have comprehensive cybersecurity plans in place, many utilities lack even basic protections. The absence of uniform cybersecurity standards leaves too many systems vulnerable as we are seeing play out in real time.
NAWC continues to urge Congress to pass bipartisan legislation to authorize a Water Risk and Resilience Organization to advise the U.S. Environmental Protection Agency on developing, implementing, and enforcing cybersecurity requirements tailored to the evolving and ongoing threats facing drinking water and wastewater systems.
Protecting these systems is essential to public health, economic stability, and national security. As cyber threats grow more sophisticated, Congress and the federal government must act to strengthen cybersecurity across the entire water and wastewater sector and safeguard the communities that depend on it.”
Background
The NAWC statement follows a series of cyber incidents that have heightened concerns about the security of U.S. water infrastructure. On July 28, Minnesota IT Services (MNIT) disclosed that a coordinated cyberattack had targeted operational technology at more than 30 community water systems across the state on July 26 and 27, prompting a statewide cybersecurity response involving federal, state, local, Tribal, and private-sector partners. Two days later, state officials reported that response and recovery efforts were continuing as authorities worked to assess impacts, share threat intelligence, and strengthen defenses across affected utilities.
The incidents have renewed attention on the cybersecurity challenges facing the water sector, particularly among smaller and resource-constrained utilities. Industry experts have warned that many water systems remain vulnerable not only through industrial control systems and operational technology, but also through more common attack vectors such as email-based phishing, domain impersonation, and credential theft. Recent research cited by cybersecurity firm Red Sift found that a significant share of water and wastewater organizations lack fully implemented email authentication and spoofing protections, creating opportunities for attackers to gain access to critical systems through employees, contractors, or trusted third parties.
Against that backdrop, industry groups, utilities, and government agencies have increasingly called for stronger cybersecurity requirements, greater information sharing, and additional resources to help water systems improve resilience against a growing and increasingly sophisticated threat landscape.