Urban water systems are vital infrastructure that deliver clean drinking water and support fire protection services for millions of people. Yet these complex networks face growing threats-from natural disasters to cyberattacks and even deliberate sabotage. Protecting this critical infrastructure requires a systematic approach: conducting thorough vulnerability assessments and developing robust emergency response plans. Together, these two processes form the foundation of water system security and resilience.
Table of Contents
- Conducting a comprehensive vulnerability assessment
- What makes vulnerability different from risk?
- Identifying critical system components and customers
- Priority customers and services
- Understanding the spectrum of threats
- Low-level threats
- Insider threats
- External and cyber threats
- Coordinating with law enforcement
- Developing and testing an emergency response plan
- Required ERP components
- Coordination requirements
- Testing and maintenance
- Emergency contact protocols
- Building resilience for the future
Conducting a comprehensive vulnerability assessment
A vulnerability assessment is a structured process that identifies weaknesses in a water system’s security, specifically focusing on threats that could compromise its ability to deliver safe drinking water or provide water for firefighting. Under America’s Water Infrastructure Act (AWIA) Section 2013, community water systems serving more than 3,300 people must develop or update risk and resilience assessments (RRAs) and emergency response plans (ERPs) every five years.
A comprehensive vulnerability assessment typically involves six interconnected elements. First, operators must characterize the system and its objectives-documenting all physical components, operational processes, and the system’s core mission of providing safe and reliable drinking water. Second, they must identify and prioritize adverse consequences, examining what could go wrong and ranking these scenarios by severity and likelihood.
Third, the assessment requires determining critical assets. These include pipes, physical barriers, source water intakes, treatment and storage facilities, and electronic control systems. Fourth, it involves assessing the likelihood of malevolent acts from various adversaries. Fifth, evaluating existing countermeasures helps identify gaps in current security measures. Finally, analyzing current risk enables the development of a prioritized risk reduction plan.
What makes vulnerability different from risk?
Vulnerability represents a weakness that can be exploited by an adversary or impacted by a natural hazard. It essentially measures the probability that if a malevolent act or natural hazard occurred, the water system would suffer significant harm. Risk, on the other hand, combines vulnerability with the likelihood of a threat occurring and the magnitude of potential consequences.
The EPA provides several tools to help water systems conduct these assessments, including the Vulnerability Self-Assessment Tool (VSAT) for larger systems serving over 50,000 people and a Small System Risk and Resilience Assessment Checklist for smaller utilities.
Identifying critical system components and customers
A vital step in any vulnerability assessment is identifying which components and customers are most critical to the system’s mission. System operators must catalog services and customers whose disruption would pose immediate threats to public health or community safety.
Priority customers and services
Critical customers typically include hospitals and healthcare facilities, power generation plants, emergency services (fire, police, emergency medical), schools, and food processing operations. These facilities depend heavily on uninterrupted water supply, and their loss of service could cascade into broader public health emergencies.
Beyond customers, operators must identify critical subsystems and singular locations-points in the infrastructure where failure would cause disproportionate damage. These might include main transmission lines, primary treatment facilities, pumping stations, or central control systems. Each asset should be categorized by vulnerability level (High, Medium, or Low) based on its exposure to potential sabotage or destruction.
The EPA’s risk assessment framework requires utilities to evaluate components including source water, water collection and intake systems, pretreatment and treatment facilities, storage systems, distribution networks, and electronic or automated systems. This assessment must also consider the system’s monitoring practices, financial infrastructure, chemical handling procedures, and overall operations and maintenance.
Understanding the spectrum of threats
Water systems face a broad spectrum of threats ranging from minor vandalism to sophisticated terrorist attacks. Understanding this threat landscape is essential for allocating security resources effectively.
Low-level threats
At the lower end of the spectrum, water systems may encounter vandalism, graffiti, or minor property damage. While these incidents rarely affect water quality or service delivery, they may indicate insufficient perimeter security and could signal vulnerability to more serious attacks.
Insider threats
The Cybersecurity and Infrastructure Security Agency (CISA) defines insider threats as situations where someone with authorized access uses that access-intentionally or unintentionally-to harm the organization’s mission, facilities, or systems. In water utilities, this could mean a disgruntled employee sabotaging equipment, manipulating chemical dosing, or compromising control systems.
Insider threats can manifest as violence, sabotage, theft, or cyber attacks. Some are motivated by personal grievances, while others may involve financial pressures or ideological motivations. Utilities should implement access controls, background checks, and monitoring systems to mitigate these risks.
External and cyber threats
At the severe end, water systems face potential terrorist attacks-both physical and cyber. According to a joint advisory from the FBI, CISA, EPA, and NSA, U.S. water and wastewater systems face ongoing cyber threats from both known and unknown actors targeting their information technology and operational technology networks. These attacks threaten the ability of facilities to provide clean, potable water to their communities.
Recent advisories have highlighted how hacktivist groups exploit vulnerable internet-facing control systems, sometimes causing physical damage. Pro-Russia hacktivist groups have targeted water and wastewater systems using minimally secured virtual network computing (VNC) connections to infiltrate operational technology control devices. While these attacks have been less sophisticated than advanced persistent threats, they demonstrate the real and growing cyber risk to water infrastructure.
Coordinating with law enforcement
Water utilities should maintain relationships with local and federal law enforcement agencies to stay informed about potential threats. Law enforcement can provide intelligence about likely threat types in the region and assist in developing appropriate security responses.
Developing and testing an emergency response plan
An Emergency Response Plan (ERP) describes the utility’s strategies, resources, and procedures to prepare for and respond to incidents-natural or man-made-that threaten life, property, or the environment. According to EPA guidance, incidents can range from small main breaks or localized flooding to large-scale hurricanes, earthquakes, or system contamination.
Required ERP components
Under AWIA, emergency response plans must include several key elements. First, they must outline strategies and resources to improve system resilience, addressing both physical security and cybersecurity. Second, they must detail plans, procedures, and equipment to be used during malevolent acts or natural hazards that threaten safe drinking water delivery.
Third, ERPs must specify actions that can lessen the impact of incidents on public health and water supply. This includes developing alternative source water options, relocating water intakes where necessary, and constructing flood protection barriers. Fourth, plans must include detection strategies that help identify threats before they cause widespread damage.
Coordination requirements
Water systems must coordinate with Local Emergency Planning Committees (LEPCs) established under the Emergency Planning and Community Right-To-Know Act when developing or revising ERPs. This coordination ensures that water utility emergency procedures align with broader community emergency response frameworks.
Testing and maintenance
An untested plan is little better than no plan at all. Emergency preparedness involves conducting training and exercises, reviewing and updating policies and procedures, and practicing coordination with all partners and stakeholders. Utilities should participate in tabletop exercises that simulate various emergency scenarios, allowing staff to practice their roles and identify gaps in the plan.
The EPA offers Tabletop Exercise Packages covering various scenarios including cybersecurity incidents, ransomware attacks, and industrial control system compromises. These exercises help utilities assess their preparedness and refine their response procedures.
Emergency contact protocols
Every ERP should include a comprehensive emergency contact list distributed to all relevant personnel. This list should identify key internal staff, external partners (law enforcement, fire services, public health agencies), mutual aid partners, and regulatory authorities. The list must be kept current and readily accessible to staff during emergencies.
Plans should be reviewed at regular intervals-at minimum every five years as required by law-and updated whenever significant changes occur to the system, staffing, or threat environment.
Building resilience for the future
Vulnerability assessments and emergency response plans are not one-time activities but ongoing processes. As threats evolve and infrastructure ages, utilities must continuously reassess their risks and update their response capabilities. The certification requirements under AWIA ensure this happens at least every five years, but best practices suggest more frequent reviews.
Ultimately, the goal is not just to respond effectively when incidents occur, but to build systems resilient enough to maintain operations or recover quickly. This requires investment in physical security, cybersecurity, staff training, and community partnerships.
What do you think? How well do you believe your local water utility is prepared for emergencies? What role should community members play in supporting water system security and resilience?
References
- https://www.epa.gov/waterresilience/awia-section-2013
- https://www.epa.gov/system/files/documents/2024-07/drinking-water-rra-checklist-508-compliant.pdf
- https://www.epa.gov/waterresilience/vulnerability-self-assessment-tool-conduct-drinking-water-or-wastewater-utility
- https://dnr.wisconsin.gov/topic/DrinkingWater/awiaResilience.html
- https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-287a
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
- https://www.epa.gov/system/files/documents/2024-10/community-water-system-emergency-response-plan-template-and-instructions.pdf
- https://www.waterboards.ca.gov/drinking_water/certlic/drinkingwater/water_resiliency/prepare.html
- https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience
Leave a Reply