site-logo
site-logo
site-logo

Securing Water Treatment Facilities with IEC 62443

Securing Water Treatment Facilities with IEC 62443

Securing Water Treatment Facilities with IEC 62443

Sunrise at the Industrial Waterworks
Shieldworkz logo

Team Shieldworkz

Water treatment is one of the few sectors where a cybersecurity failure can move directly from a screen to a glass of drinking water. That direct line between a compromised control system and public health is what separates operational technology (OT) security in the water sector from almost every other industry. A breach of a retail network exposes data. A breach of a water treatment control system can expose a community. 

Before we begin, don’t forget to check out our previous post on “Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology” here.

For OT security leaders, plant managers, and CISOs responsible for water and wastewater operations, this is not a theoretical risk. It has already happened, more than once, in ways that were publicly documented and investigated by federal agencies. IEC 62443, the internationally recognized standard for industrial automation and control system (IACS) security, has emerged as the most practical framework available to help utilities structure their defenses, close gaps left by decades of legacy engineering, and demonstrate due diligence to regulators, insurers, and the communities they serve. 

This Blog walks through why water treatment facilities have become an attractive target, what IEC 62443 actually requires in practice, how real incidents have shaped the industry's thinking, and what a realistic, phased path toward compliance looks like for a utility that is still early in its OT security journey. 

Why Water Treatment Facilities Have Become a Prime Target 

Water and wastewater utilities sit at an uncomfortable intersection of three conditions that attackers look for: high public impact, historically low cybersecurity investment, and a growing footprint of internet-reachable equipment. 

Unlike a modern data center, most water treatment plants were built around programmable logic controllers (PLCs), human-machine interfaces (HMIs), and SCADA systems that were designed decades ago for reliability and safety, not for resistance against remote intrusion. Many of these devices were never intended to be exposed to the internet at all. Yet as utilities adopted remote monitoring to cut costs and support smaller operations teams, a meaningful share of that equipment ended up reachable from outside the plant network, sometimes protected by nothing more than a default password. 

Add to this a sector characterized by thousands of small and mid-sized municipal operators, many of which run lean IT staffs with no dedicated OT security function, and you get an environment where a single misconfigured remote access tool can become a national news story. 

The geopolitical dimension has also shifted in recent years. Water and wastewater systems have been explicitly identified by international hacktivist and state-linked groups as symbolic targets, not necessarily because of the value of any data they hold, but because of the disruption and fear a successful attack on drinking water can generate. This means water utilities are now contending with a threat landscape shaped as much by geopolitics as by traditional cybercriminal motives such as financial extortion. 

At the same time, insurers underwriting cyber policies for public utilities are asking more detailed questions about control system segmentation, remote access governance, and incident response readiness. A utility that cannot answer those questions with confidence is not only exposed operationally, it is increasingly exposed financially, facing higher premiums or reduced coverage at the exact moment it can least afford either. 

The Business and Public-Safety Impact of an OT Breach 

Direct risk to public health if chemical dosing, disinfection, or filtration processes are manipulated 

Extended service outages that affect hospitals, schools, and emergency services connected to the same water supply 

Regulatory scrutiny and potential enforcement action following an incident 

Reputational damage that erodes public trust in the utility for years 

Financial exposure from incident response, system replacement, and litigation 

Why Regulation Alone Has Not Closed the Gap 

Over the past several years, federal agencies have issued repeated advisories urging water utilities to strengthen cybersecurity, and some states have begun incorporating cybersecurity questions into sanitary surveys and inspections. Yet regulation in the water sector remains fragmented compared to industries such as energy, where mandatory standards have existed for years. This leaves many utilities in a position where they know cybersecurity matters, but have no single, authoritative framework telling them exactly what a defensible program looks like. IEC 62443 fills that gap by giving utilities a globally recognized, engineering-grounded standard they can adopt voluntarily and point to when demonstrating due diligence to boards, insurers, and regulators. 

Understanding IEC 62443: The Backbone of OT Security in Water Systems 

IEC 62443 is a series of standards developed jointly by the International Society of Automation (ISA) and the International Electrotechnical Commission (IEC) to secure industrial automation and control systems throughout their lifecycle. Unlike general IT security frameworks, IEC 62443 was purpose-built for environments where availability and safety take precedence over confidentiality, and where a patch cannot simply be pushed overnight without risking a process shutdown. 

For water treatment operators, the value of IEC 62443 lies in its structure. It does not ask a utility to secure everything equally. Instead, it provides a methodology for identifying what matters most, segmenting the environment accordingly, and applying security controls proportional to risk. 

Zones and Conduits: The Core Concept 

At the heart of IEC 62443 is the idea of dividing an industrial environment into zones, groups of assets that share similar security requirements, and conduits, the communication pathways that connect those zones. A chemical dosing control system, for example, would sit in a different zone than a plant's general business network, with a tightly monitored conduit governing any communication between the two. 

This concept alone addresses one of the most common findings in water sector security assessments: flat networks where a compromised office laptop can reach the same network segment as a PLC controlling disinfection levels. 

Security Levels: Matching Protection to Risk 

IEC 62443 defines target security levels ranging from SL-1, protection against casual or coincidental exposure, to SL-4, protection against sophisticated, well-resourced adversaries. A booster pump station on the edge of a distribution network may only warrant SL-2 protection, while the core treatment control system handling chemical dosing may justify SL-3 or higher. This tiered approach lets utilities allocate limited security budgets where they matter most, rather than spreading resources thin across every asset equally. 

Lifecycle Coverage Across the Standard 

The IEC 62443 series is organized into parts that address different stakeholders across the automation lifecycle: policies and procedures for asset owners, requirements for system integrators, and secure development practices for component manufacturers. This means a utility's cybersecurity program does not stop at internal policy. It extends into how the utility evaluates vendors, writes procurement contracts, and validates that new equipment meets baseline security requirements before it is ever connected to the network. 

How the IEC 62443 Structure Maps to Water Utility Responsibilities 

IEC 62443 Focus Area 

What It Covers 

Water Utility Application 

Security Program Requirements 

Governance, policies, patch management, risk assessment 

Establishing an OT security program with executive sponsorship and defined ownership 

Zones and Conduits 

Network segmentation and communication control 

Separating SCADA, PLC, and HMI networks from business IT and remote access 

Security Levels (SL 1–4) 

Tiered protection based on threat capability 

Applying stronger controls to chemical dosing and disinfection systems than to non-critical monitoring points 

System Integration Requirements 

Secure design of control system architecture 

Evaluating SCADA integrators and system architects against defined security requirements 

Component Requirements 

Secure development for PLCs, HMIs, and controllers 

Building vendor evaluation criteria into procurement for new automation equipment 

Real-World Incidents That Changed How the Industry Thinks 

Two publicly documented incidents did more to shift water sector cybersecurity priorities than any white paper or conference talk. Both are worth understanding in detail because they illustrate exactly the gaps that IEC 62443 is designed to close. 

Oldsmar, Florida: When a Mouse Cursor Became a Public Safety Threat 

In February 2021, an operator at a water treatment plant in Oldsmar, Florida noticed his mouse cursor moving on its own. Someone had remotely accessed the plant's control system and, within minutes, navigated to the software controlling sodium hydroxide, commonly known as lye, a chemical used to manage water acidity. The intruder increased the chemical's target level from 100 parts per million to 11,100 parts per million, more than one hundred times the normal dosage. The operator caught the change immediately and reversed it before any chemical reached the distribution system. 

Investigators later noted that the plant had been using remote access software that allowed full control of plant computers, the kind of access intended for legitimate troubleshooting but left insufficiently restricted. The incident prompted several U.S. states to issue emergency cybersecurity advisories to their water utilities and pushed remote access governance to the top of the sector's priority list. 

Aliquippa, Pennsylvania: A Nation-State Actor Exploiting a Default Password 

In November 2023, the Municipal Water Authority of Aliquippa in Pennsylvania discovered that a booster station regulating water pressure had been taken over by a hacking group linked to Iran's Islamic Revolutionary Guard Corps. The group exploited a programmable logic controller that was directly reachable from the internet and still using its factory-default password. An alarm alerted operators, who switched the station to manual control and disconnected the compromised device. Federal agencies later confirmed that similar devices from the same manufacturer, running the same default credentials, were exposed at facilities across multiple U.S. states and internationally. 

The Aliquippa incident was notable because it was not a targeted attack on a specific utility. It was an opportunistic sweep for exposed devices with weak credentials, a reminder that even utilities that consider themselves too small to be a target can be swept up in much larger, geopolitically motivated campaigns. 

What These Incidents Have in Common 

Factor 

Oldsmar (2021) 

Aliquippa (2023) 

Entry point 

Remote access software with broad, unrestricted control 

Internet-exposed PLC with a default password 

Detection method 

Operator visually noticed cursor movement 

Automated alarm on the control system 

Outcome 

Change reversed before reaching the water supply 

Station switched to manual operation, no service loss 

Root cause category 

Weak remote access governance 

Poor asset visibility and credential hygiene 

IEC 62443 control that would have helped 

Conduit-level access control and session monitoring (SL-2/3) 

Zone segmentation and mandatory credential management (SL-1/2 baseline) 

Neither incident required a highly sophisticated attacker. Both succeeded because of foundational gaps, the exact kind of gaps that a structured IEC 62443 program is designed to identify and close before they are discovered by someone with less benign intentions. 

The Unique Risk Landscape of Water and Wastewater OT Environments 

Before any control framework can be applied effectively, it helps to understand what makes water sector OT environments different from a typical manufacturing plant or corporate data center. 

Legacy Equipment With Long Replacement Cycles 

Control systems in water treatment often remain in service for fifteen to twenty-five years. Replacing a PLC or SCADA system is a capital-intensive decision that competes with pipe replacement, treatment upgrades, and other infrastructure priorities. This means utilities frequently operate equipment that predates modern authentication standards, encrypted communication protocols, or even basic logging capability. 

Remote Access as an Operational Necessity 

Many utilities operate multiple, geographically dispersed sites, wells, booster stations, lift stations, with limited on-site staff. Remote access is not a convenience; it is how a small operations team manages a distributed system. That necessity has to be reconciled with the reality that remote access is also the single most common entry point identified in publicly documented water sector incidents. 

IT/OT Convergence Without a Corresponding Security Model 

As utilities adopt cloud-based reporting, data historians, and integration with billing or asset management systems, the line between the business network and the control network becomes blurrier. Without deliberate segmentation, a phishing email that compromises an office workstation can, in a flat network, become a pathway into the control system itself. 

Workforce and Resourcing Constraints 

Most water utilities are public entities operating under tight budgets, and even where a cybersecurity budget exists, competition for scarce talent means dedicated OT security expertise is rare. Cybersecurity responsibility often falls to operations staff or a small IT team already stretched across many other duties. 

Safety-Critical Process Variables as the Real Attack Surface 

In a typical enterprise network, the worst outcome of an attack is usually data theft or a disrupted transaction. In a water treatment environment, the attack surface includes physical process variables: chemical dosing rates, disinfection contact time, pump pressure, and valve position. A control system compromise does not just risk downtime; it risks a direct change to a physical process that affects water quality. This is precisely why IEC 62443's emphasis on protecting safety and availability, rather than confidentiality alone, resonates so strongly with the water sector's actual risk profile. 

Interdependencies Across a Distributed Physical Footprint 

A single water utility may operate dozens of remote sites: wells, elevated storage tanks, booster and lift stations, spread across a wide geographic area, often with only a handful of engineers responsible for all of them. Each of those remote sites represents a potential entry point, and because they are frequently connected back to a central SCADA system, a compromise at even a minor, seemingly low-value site can become a pathway toward the core treatment process if network segmentation has not been designed with that risk in mind. 

Practical Recommendations and Best Practices 

A realistic IEC 62443 program does not require a utility to rebuild its entire control system overnight. It requires a disciplined, phased approach that starts with visibility and works progressively toward stronger technical controls. 

1. Build an Accurate Asset Inventory Before Anything Else 

It is not possible to secure what has not been identified. Many utilities discover during an initial assessment that they have more internet-reachable devices than anyone realized, often installed years earlier by a contractor for a specific troubleshooting need and never disabled. A complete inventory of PLCs, HMIs, RTUs, network switches, and remote access points is the foundation every subsequent step depends on. 

2. Segment the Network Into Defined Zones 

  • Separate the control network entirely from the corporate business network 

  • Create distinct zones for critical processes such as chemical dosing and disinfection versus lower-risk monitoring points 

  • Use firewalls and data diodes at conduit boundaries rather than relying on a single perimeter firewall 

  • Document every conduit and the specific business reason it exists 

3. Eliminate Default Credentials and Enforce Strong Access Control 

Every documented water sector incident to date has involved either weak credentials, unrestricted remote access, or both. Replacing default passwords, enforcing multi-factor authentication for remote sessions, and applying least-privilege access to control system accounts closes the exact door that opportunistic attackers are actively scanning for. 

4. Govern Remote Access Deliberately 

  • Require time-limited, approved remote access sessions rather than always-on connectivity 

  • Log and review every remote session against the control system 

  • Restrict vendor and integrator access to only the systems relevant to their work 

  • Disable remote access tools immediately after a project or maintenance window concludes 

5. Deploy Continuous Monitoring for OT-Specific Threats 

Traditional IT security tools are frequently blind to the protocols used in industrial control systems. OT-aware monitoring can detect unusual commands sent to a PLC, unexpected changes to setpoints such as chemical dosing levels, and communication patterns that fall outside normal operational baselines, giving operators the kind of early warning that made the difference in both Oldsmar and Aliquippa. 

Just as important as the technology itself is how alerts are routed. A monitoring platform that generates accurate warnings but sends them to an inbox nobody checks provides little real protection. Effective OT monitoring programs define clear escalation paths so that an anomalous setpoint change reaches an on-call operator or engineer within minutes, not after the next shift change. 

6. Extend Security Requirements Into Procurement and Vendor Management 

IEC 62443 explicitly addresses system integrators and component manufacturers for a reason. A utility's security posture is only as strong as the weakest device connected to its network. Building minimum security requirements into procurement contracts, and requiring vendors to demonstrate secure development practices, prevents new vulnerabilities from being introduced during routine equipment upgrades. 

7. Prepare an OT-Specific Incident Response Plan 

A generic IT incident response plan rarely accounts for the operational realities of a treatment plant, where isolating a compromised system might mean switching to manual chemical dosing rather than simply disconnecting a server. Response plans should define clear thresholds for switching to manual operation, notification procedures for state and federal agencies, and coordination steps with equipment vendors. 

A Phased Roadmap Toward IEC 62443 Alignment 

Phase 

Primary Focus 

Typical Outcome 

Phase 1: Assessment 

Asset inventory, network mapping, gap analysis against IEC 62443 requirements 

Clear picture of current exposure and prioritized risk areas 

Phase 2: Foundational Controls 

Credential hygiene, remote access governance, basic segmentation 

Closes the most commonly exploited gaps quickly and cost-effectively 

Phase 3: Zone and Conduit Design 

Formal segmentation aligned to security levels 

Reduces the blast radius of any single compromised device 

Phase 4: Continuous Monitoring 

OT-aware detection and alerting 

Early warning for anomalous commands or setpoint changes 

Phase 5: Governance and Vendor Management 

Policy, procurement standards, workforce training 

Sustainable program that scales with new equipment and threats 

Frequently Asked Questions About IEC 62443 in Water Treatment 

1.Is IEC 62443 mandatory for water utilities? 

In most regions, IEC 62443 is not a legal mandate for water and wastewater utilities in the way certain standards are for the energy sector. However, it is increasingly referenced by regulators, insurers, and federal advisories as the recognized benchmark for industrial control system security, which makes voluntary adoption a strong signal of due diligence and operational maturity. 

2.How long does it take to align with IEC 62443? 

There is no fixed timeline, since it depends heavily on the size of the utility, the age of its control systems, and available resources. Most organizations see meaningful risk reduction within the first few months by focusing on foundational controls, such as credential hygiene and remote access governance, while full zone and conduit segmentation across a large distributed system can take twelve to twenty-four months to mature. 

3.Do small and mid-sized utilities really need to worry about nation-state actors? 

The Aliquippa incident demonstrated that nation-state-linked groups do not always select targets individually. They scan broadly for exposed, poorly secured devices and exploit whatever they find, regardless of the size of the utility behind it. A small utility with weak credential hygiene can be just as exposed as a large metropolitan system. 

4.What is the difference between IT security and OT security in a water treatment context? 

IT security is generally built around protecting data confidentiality, while OT security in a water treatment plant prioritizes safety and availability of the physical process. A patch or restart that is routine in an IT environment can trigger a process disruption in an OT environment, which is why IEC 62443 was designed specifically around industrial automation and control system realities rather than borrowed wholesale from IT frameworks. 

How Shieldworkz Supports Organizations 

Shieldworkz works with water and wastewater utilities, industrial operators, and critical infrastructure organizations to translate the IEC 62443 standard into a program that fits the realities of a working treatment plant, not just a compliance checklist. Our approach is built around practical execution: 

  • Comprehensive OT asset discovery and network mapping to establish full visibility into PLCs, HMIs, SCADA systems, and remote access points 

  • Gap assessments benchmarked directly against IEC 62443 zones, conduits, and target security levels 

  • Network segmentation design that separates critical process control from business IT without disrupting daily operations 

  • Remote access governance frameworks that balance operational necessity with strict session control and monitoring 

  • OT-specific continuous monitoring to detect anomalous commands, unauthorized configuration changes, and early indicators of compromise 

  • Vendor and procurement risk evaluation to ensure new equipment meets baseline security requirements before deployment 

  • Incident response planning tailored to the operational and regulatory realities of water and wastewater systems 

  • Workforce awareness training designed for operations staff, not just IT personnel 

Every engagement is built around the utility's actual operating environment, staffing constraints, and risk tolerance, so that security improvements strengthen resilience without slowing down the mission of delivering safe, reliable water service. 

Conclusion 

Water treatment facilities occupy a category of infrastructure where the consequences of a cybersecurity failure are measured in public health outcomes, not just downtime or data loss. The incidents at Oldsmar and Aliquippa demonstrated that the entry points attackers use are rarely exotic. They are default passwords, unrestricted remote access, and flat networks, exactly the gaps that a structured IEC 62443 program is built to close. 

For OT security leaders, plant managers, and decision-makers across critical infrastructure, the path forward does not require solving everything at once. It requires an honest assessment of current exposure, a prioritized plan that protects the most critical processes first, and a partner who understands both the engineering realities of a treatment plant and the discipline of the IEC 62443 standard. 

The utilities that move deliberately now, before an incident forces the decision, are the ones that will be best positioned to protect both their communities and their operations for the decades ahead. 

Book a Free Consultation with Our Experts 

If your organization is evaluating where to start with IEC 62443, or looking to strengthen an existing OT security program, our team is available for a no-obligation conversation about your specific environment. We will help you understand where your current gaps sit, what a realistic roadmap looks like, and how to prioritize the steps that matter most for your facility. Reach out to Shieldworkz to schedule your free consultation today. 

Additional resources  

Incident Response Plan For Municipal & Wastewater Utilities here
A downloadable report on the Stryker cyber incident here  
Removable media scan solution vendor evaluation and selection checklist here  
IEC 62443-based OT/ICS risk assessment checklist for the food and beverage manufacturing sector here 

Get Weekly

Resources & News

See How Our Industry-Leading OT Security Solutions Address Critical Security Challenges

You may also like

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.