Skip to main content

A National Decision with Global Weight: Federal Water Cyber Protection Sets a Standard for Coordinated Resilience

STATUS: Developing SEVERITY: 6/10 AUDIENCE: Government, Water and Wastewater, Critical Infrastructure Security Leads   

Aug 27, 2026

·

Blog

·

Secure Communications

A planned federal program to bring private-sector cyber support to resource-constrained water providers is more than a domestic capacity fix — it is a national decision that reinforces a standard the rest of the world is converging toward: critical infrastructure resilience depends on coordinated conformity to a shared operating model, not isolated technical fixes. Governments that treat this as the direction of travel, rather than a one-off program, will be the ones best positioned when the next sector is tested. 

The next design test is operational: can assistance help utilities detect and contain threats while preserving trusted coordination when systems are isolated, degraded, or under investigation? The answer will matter well beyond the water sector, and well beyond the United States. 

What Happened and Why It Is Different 

Nextgov/FCW reported that the White House is preparing a water-sector cyber protection program led by the Office of the National Cyber Director. The planned effort would enlist private companies to help states with limited cyber resources strengthen defenses for water and wastewater infrastructure — a model that mirrors, and validates, the public-private conformity frameworks now emerging across allied governments.1 

The program may begin in Texas as a testbed and later extend services to other requesting states. At the time of reporting, the participating companies, program scale, and final launch details had not been made public. A staged rollout of this kind is itself instructive: it signals that national authorities intend to prove the operating model before scaling it, a discipline worth adopting anywhere similar programs are contemplated. 

The initiative follows a wave of intrusions against water systems. More than 30 community water systems in Minnesota were targeted, with roughly 12 states reporting similar activity.1 State officials said systems continued operating safely and identified no known public-health effects — a reassuring outcome, but one that should not be read as reducing the urgency of the underlying gap. 

The operational context is unambiguous. National cyber authorities have warned that threat actors are targeting internet-exposed programmable logic controllers, changing passwords and IP addresses, locking out operators, and contributing to boil water notices and sustained manual operations. Authorities are urging owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the internet without delay.2,3 

What the Program Could Change  

Current Constraint 
Opportunity Through Aligned Action 
Operational Requirement 
Risk if Standards Are Overlooked 
Small and rural utilities worldwide often operate with limited cyber resources. 
A coordinated, standards-based support model makes specialized capability accessible at scale. 
Integrators and local operators must be included, since they understand how field systems are deployed and maintained. 
A technically sound service can still miss undocumented field connections or local operating realities. 
Detection and remediation expertise is difficult for individual utilities to sustain alone. 
A shared, government-anchored model aggregates expertise and establishes repeatable, conforming support. 
Support must define how detection, containment, recovery, and communications work together as one system. 
Improved visibility alone does not ensure the response team can coordinate through disruption. 

Why This Matters

Old Assumption 
Current Reality 
Resilience Response 
Cyber assistance is mainly a technology-delivery problem. 
National programs of this kind operate across federal, state, private-sector, integrator, and utility boundaries — success depends on everyone conforming to the same operating model. 
Design governance, trusted communications, and accountability into the model from the start, and hold every participant to it. 
Removing exposure is the end state. 
Authoritative guidance also anticipates manual operations and recovery after isolation. 
Pair hardening with tested continuity procedures and communications that remain trusted during containment. 
A successful pilot proves the service can scale. 
A pilot proves value only when it works for utilities with limited staff, mixed deployments, and third-party dependencies. 
Measure readiness by response execution: who is reached, what is confirmed, how decisions are recorded, and how operations continue. 
IMMEDIATE 
Treat the reported program as a positive, authoritative signal for the direction the sector should move in, but do not delay current exposure reduction work. Remove unnecessary direct internet access to PLCs and route required remote access through secure gateways or VPNs, consistent with national guidance. 2,3
IMMEDIATE 
Map every party required in the first hours of an incident, including operators, state officials, federal responders, technology providers, and system integrators. Define how each party is reached if normal enterprise channels are unavailable or untrusted. 
SHORT-TERM 
 Exercise a joint scenario in which a utility isolates affected systems and moves to manual operations. Test notification, secure voice and messaging, personnel accountability, decision logging, and regulator updates as one workflow. 
SHORT-TERM 
Require participating vendors to state what connectivity, identity, cloud, carrier, and directory dependencies their services retain during isolation. Match continuity claims to the deployment model that makes them true. 
ONGOING
Use outcomes, not enrollment, to measure program value. Track whether utilities can identify exposure, contain activity, maintain safe operations, coordinate across organizations, and restore from known-good configurations. 

BlackBerry Secure Communications Position

The proposed federal program deserves to be read as what it is: a welcome, authoritative move from guidance toward operational capacity, and a national decision that reinforces just how significant coordinated critical-infrastructure defense has become on the global stage. Its strongest form will connect cyber defense to continuity — helping utilities reduce exposure, isolate affected systems, coordinate across organizational boundaries, and keep essential services running. 

Detection starts the response. Trusted coordination carries it. Governments and operators everywhere should see this program not as an isolated domestic measure, but as further confirmation that alignment with a shared, conforming operating model is now a strategic imperative for critical infrastructure resilience. 

Citations:

1. White House to soon launch water provider cyber protection program (David DiMolfetta, Nextgov/FCW, August 26, 2026). 

2. CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs (Cybersecurity and Infrastructure Security Agency, July 30, 2026). 

3. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions (Federal Bureau of Investigation and Environmental Protection Agency, July 30, 2026). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now