
By Hagai Galili
The wave of cyberattacks that became public in late July 2026 targeting municipal water systems across 12 states has exposed both a financial and operational risk for water utility leadership. Attackers compromised internet-facing digital controllers (the automated switches that manage physical equipment) modifying settings and locking operators out of central monitoring displays.
Beyond immediate operational friction lies a defined balance sheet exposure.
Despite ongoing capital investments in standard enterprise cybersecurity tools, water utilities remain exposed to the “Blind Operator” scenario. When a cyber incident forces a digital network shutdown, decision-makers face immediate financial trade-offs, weighing skyrocketing emergency overtime, manual field dispatch costs, and public health mandates against the severe regulatory penalties of unverified water distribution.
Utility decision makers must evaluate cybersecurity through the lens of capital preservation. When an intrusion occurs, the loss of remote monitoring leaves operators unable to independently verify the physical state of high-service pumps, chemical dosing systems and pressure valves.
AWWA urges Congress to expand cybersecurity measures
Yet, under U.S. Environmental Protection Agency (EPA) oversight and Safe Drinking Water Act mandates, utilities cannot simply halt treatment or drop system pressure without incurring administrative penalties, public notice expenditures and potential credit rating scrutiny. This is the Blind Operator scenario: a condition where operators are legally and fiscally obligated to maintain continuous service but lack verified physical data to confirm whether core capital assets are operating safely.
Regulatory Mandates and Balance-Sheet Exposure Under Fire
Because municipal water and wastewater systems are essential public assets, the sector operates under rigorous regulatory requirements. Under EPA guidelines and state environmental enforcement frameworks, utilities face direct financial sanctions, consent decrees, and public notification costs if operations interrupt drinking water delivery or water quality standards without an approved operational justification. A suspected network intrusion alone does not constitute valid grounds to halt distribution or reduce system pressure.
Compounding this pressure, emergency incident response playbooks mandate immediately severing all digital links between corporate systems and plant assets to stop malware from spreading. While effective for digital containment, this mandatory shutdown instantly blinds operators, forcing leadership into an impossible choice between operating critical infrastructure without data or triggering costly, penalized service shutdowns
In practice, this creates a clear financial conflict. Utility leadership must disconnect digital networks to meet cyber containment standards while keeping physical treatment assets running. Faced with this choice, management is effectively forced to maintain pumping and treatment operations, accepting the unhedged operational risk of running critical equipment without remote visibility rather than incurring the guaranteed financial penalties and liabilities of an unexcused service shutdown.
Addressing the Blind Spot in Network-Centric Defenses
To drive efficiency and lower operating costs, utilities expanded their reliance on enterprise cybersecurity solutions across converged operational networks. While essential for enterprise protection, standard IT platforms inspect digital data traffic rather than underlying physical mechanics.
When a cyber event forces network quarantine, traditional IT monitoring leaves operators with an incomplete operational picture. As a result, digital control displays struggle to differentiate between three distinct scenarios with vastly different financial profiles:
- Physical Impact: Mechanical settings are altered, requiring emergency repairs and manual overrides.
- Visibility Impact: Communication lines go dark while physical field machinery continues operating normally.
- False Positives: Minor network glitches prompt unnecessary emergency callouts or precautionary asset shutdowns.
Cyber, physical security fact sheets offer tips for utilities
Physical Signal Monitoring: A Capital-Efficient Defense
To evaluate the return on investment for physical cybersecurity, it helps to distinguish between two fundamental layers of utility infrastructure: the software layer (operating screens, corporate networks, and digital controllers) and the physical machinery layer (pumps, drives, valves, and the raw electrical signals that power them).
While traditional security platforms concentrate expenditure on monitoring software traffic across computer networks, Process Oriented OT Cybersecurity places its defense directly at the physical machinery layer. By measuring raw electrical process signals directly from the equipment, this approach captures performance data independently of software controllers, computer networks, or operating screens.
To deliver operational visibility while preserving capital efficiency, a physical signal monitoring architecture fulfills these key criteria:
Hardware Isolation: Monitoring equipment operates via passive signal collection and has no outbound connection back into plant controls. Because it cannot send commands, the monitoring layer itself cannot be remotely hacked or used to disrupt physical operations.
Direct Physical Measurement: Operating data is derived directly from physical electrical currents. While software logic, computer controllers, and screen displays can be manipulated or severed, electrical signals continuously reflect true mechanical output.
Physics-Based Anomaly Detection: Analysis relies on physical engineering baselines rather than software code. The system detects operational stress the moment equipment strays from standard physical parameters.
Dynamic Actionable Playbooks: Upon potential threat detection, the architecture delivers real-time, prioritized recommendations directly to operators. Rather than forcing a binary choice between operating blind or executing a full plant shutdown, these tailored response protocols guide personnel through targeted physical verification and isolated containment steps.
Strategic Incident Response and Asset Protection
When computer networks fail or a security alert forces a network shutdown, utility executives face an immediate decision: continue operating without remote screens or initiate a precautionary plant shutdown. Precautionary shutdowns frequently incur severe expenses, including manual field operations, emergency water hauling, boil-water notices, and regulatory review.
Integrating physical process data into incident response workflows replaces operational assumptions with verified facts. Decision-makers can immediately verify whether an alert represents actual physical equipment manipulation or a harmless network-level disruption. If raw electrical signals confirm that high-service pumps and dosing systems are operating safely within baseline ranges, leadership can maintain service continuity with confidence while IT teams isolate and clean network threats in isolation.

Preserving Fiscal Stability in Utility Operations
Recent cyber incidents demonstrated that software firewalls alone do not fully eliminate operational risk. When enterprise network quarantines occur, operating without physical visibility exposes utilities to asset damage and regulatory liability.
By establishing an independent physical baseline directly at the equipment layer, water utility executives gain a practical, capital-efficient framework to resolve operational uncertainty, comply with EPA mandates, and safeguard both municipal infrastructure and fiscal reserves.

Hagai Galili is chief operating officer at SIGA, an OT cybersecurity company. He holds a B.Sc. in Mechanical Engineering and brings a deep expertise in scaling operations, industrial systems integration and cross-functional leadership. At SIGA, Galili shapes strategic vision, drives global product deployments and aligns technology with business outcomes to build resilient organizations and foster market partnerships.








Leave a Reply