August 8, 2026
August 8, 2026
The article argues that water and wastewater cybersecurity remains too narrowly focused on network intrusions, malware and unauthorized access, while overlooking failures inside the physical control process. Pumps, valves, controllers and operator displays depend on electronically transmitted sensor data, so corrupted, delayed or unavailable measurements can create dangerous conditions even when no network has been compromised. Such incidents may result from calibration errors, equipment defects, sensor drift, environmental conditions, engineering mistakes, counterfeit components or deliberate manipulation. The author contends that these events should be treated as control-system cyber incidents because untrustworthy electronic information can disrupt safe operation regardless of whether the cause is malicious, accidental or technical.
Applied Control Solutions’ incident repository reportedly contains more than 250 water and wastewater events recorded between 1994 and 2026, including loss of control, equipment damage, environmental releases, boil-water notices and injuries. More than 35% involved sensor problems, while roughly 25% involved malicious cyber activity; in many cases, programmable controllers functioned correctly but acted on false measurements. To address this gap, the article proposes common definitions for control-system incidents, joint investigations by engineers and cybersecurity specialists, better training, systematic incident-data collection, sensor-integrity requirements in procurement and a trusted cross-sector information-sharing program. Without these measures, significant operational and public-safety risks will continue to fall outside existing cybersecurity regulations and reporting systems.
Source: Control Global