Cloud CISO Perspectives: Tips on securing the water sector in the AI era
Google Cloud’s August 2026 CISO Perspectives highlights rising cyber threats to U.S. water utilities, urging stronger security measures and AI-augmented defenses to protect critical infrastructure.
Google Cloud’s threat intelligence teams report increased targeting of water utilities’ internet-connected programmable logic controllers in the U.S., with threat actors exploiting vulnerabilities amid geopolitical tensions. While manual overrides and water-quality checks provide safety nets, operators must prioritize digital security fundamentals to prevent disruptions. The report emphasizes that cyber incidents, though historically rare, require urgent attention to safeguard critical infrastructure.
The guidance recommends foundational cybersecurity practices for resource-constrained utilities, including asset inventory, exposure assessments, and strict access controls. Key steps include replacing default credentials, implementing the 3-2-1 backup rule, and using network segmentation and multifactor authentication. Emergency planning should integrate cyber-incident response into existing all-hazards systems, such as FEMA NIMS and the Incident Command System for Industrial Control Systems.
Third-party and vendor access poses significant risks, as many water utilities rely on external system integrators and maintenance contractors. The report advises auditing remote connections and enforcing rigorous access controls, logging requirements, and multifactor authentication for vendors. These recommendations align with guidance from agencies including the EPA, CISA, and the FBI, underscoring the need for unified governance between IT and OT leaders.
The report advocates for modernizing security with AI-augmented approaches to shift from reactive models to proactive, threat-informed strategies. It highlights the Mandiant Operational Technology Theory of 99, which notes that 99% of intrusion dwell time occurs in commercial IT systems before impacting operational technology. By leveraging AI to secure intermediary infrastructure, defenders can neutralize threats and protect critical physical processes, addressing the evolving tactics of malicious actors.