Skip to main content

A 90-Day Communications Continuity Plan for Water Utilities

When a water utility isolates its operational technology during a cyberattack, isolation alone does not create resilience. A practical 90-day plan builds three things in sequence: reliable alerting to replace the manual call tree, an out-of-band coordination channel independent of the isolated network, and managed devices for the small group carrying the response.

Sep 3, 2026

·

Blog

·

Secure Communications

When a water utility cuts off its operational technology during a cyber incident, the goal is continuity. Pumps still need to run. Operators still need to coordinate shifts. Regulators still need updates. Communities still need safe water.

Recent guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and international partners makes the technical requirement clear. Critical infrastructure operators should be prepared to isolate vital operational technology and enable systems from other networks during a disruption or crisis. Attacks against water and wastewater systems have shown why. Attackers targeting internet-facing programmable logic controllers caused loss of monitoring, loss of control, boil-water notices, and sustained manual operations in some cases.

Watch the On-Demand Webinar: What CI Fortify Doesn't Say About Communications

Isolation alone does not make an organization resilient. A utility that can disconnect its network but cannot reach staff, coordinate shifts, confirm acknowledgments, brief public agencies, or document its response has traded one failure mode for another. The communication plan has to be treated as part of the isolation plan, not as an afterthought.

A new CISA advisory gives new recommendations about how to maintain communications while systems are down. Every country running water systems, power grids, transportation networks, and manufacturing on OT infrastructure faces the same trade-off: isolate a compromised system and communications infrastructure built on the same network goes down with it. Operators outside the U.S. should read this advisory as less of a compliance document and more as an early indication of where their own regulators are likely headed.

For this 90-day plan, each 30-day phase closes a specific gap and the sequence matters. You cannot coordinate a response until you can reach your people, and you cannot trust a coordination channel that runs through the same infrastructure you just cut off.

Days 1 to 30: Replace the Manual Call Tree

The first 30 days should focus on reach. Many utilities still depend on manual call trees that work in ordinary conditions but fail under pressure, especially overnight, during severe weather, or when staff are already stretched thin. "The manual call tree fails at two, three a.m. in the morning," says Ramon Pinero, Vice President and General Manager, BlackBerry AtHoc. That is precisely when a water utility can least afford a communications gap.

Start by building an alerting process that can reach employees, contractors, mutual aid partners, and external stakeholders across multiple channels. A single alert should publish to phones, email, and mobile apps at once, so no one depends on a channel that happens to be down.

Reach is only half the requirement. The process must confirm who received the alert, who acknowledged it, and who is available to respond. During an inquiry or after-action review, that record becomes evidence. A utility that can show exactly who was contacted, and when they responded, can account for its actions when regulators and the public ask questions.

Days 31 to 60: Establish an Out-of-Band Coordination Channel

Once alerting is in place, the next priority is coordination. Leadership, operators, incident commanders, and public-sector partners need a trusted way to communicate when enterprise systems, internet connectivity, or carrier networks are degraded or untrusted.

The test is straightforward. "Can our team still coordinate internally and with the state and CISA once the network is cut?” says Pinero. “If the honest answer is we're not sure, then that's the gap to close." Uncertainty is the signal to act before an incident, not during one.

This channel should be available and rehearsed before an incident occurs. It should not depend on the same infrastructure being isolated. The channel should support secure voice, messaging, and status coordination across the people responsible for keeping essential services running. That means end-to-end encryption for the conversation and delivery that holds up when public networks are strained.

Days 61 to 90: Manage the Response-Critical Devices

In the final month, identify the small set of devices that response leaders, operators, and emergency coordinators will use during an isolation event. Bring those devices under management. Validate identity, access, encryption, and update controls.

"A fallback channel on a compromised laptop is just not a fallback," Pinero says. The trusted channel and the trusted device have to travel together, because either one, compromised, undermines the other.

The goal is not to build a large new security program. It is to make sure the handful of people carrying the response are using trusted devices and trusted channels when the rest of the environment is uncertain. For most utilities, that is a manageable number of devices and a realistic 30-day objective.

Test the Plan Before It Is Needed

By day 90, the utility should be able to run a practical drill. Isolate the relevant systems. Notify the response population. Coordinate manual operations. Brief external partners. Then produce a record of who was contacted, through which channel, when they acknowledged, and what actions followed.

That evidence is not paperwork. It is proof that the organization can keep operating when the network is no longer a safe place to coordinate. A drill also surfaces the gaps a plan on paper hides: the contractor whose number changed, the coordination channel no one has opened in six months, the device that never received its last update.

For water utilities, that is the real measure of resilience. Not whether you can disconnect the network, but whether your people can coordinate to keep the water safe once you have.

Getting Started

The 90-day structure works because it closes gaps in the order they matter: reach first, coordination second, device trust third. A utility does not need to solve everything at once. It needs to know that when the network becomes untrusted, the people running the response can still find each other, talk securely, and account for what they did.

For utilities, the priority is not adding more complexity. It is making sure the right people can be reached, can coordinate securely, and can account for their actions when ordinary systems are unavailable or untrusted. BlackBerry supports that goal with secure communications capabilities built for high-consequence environments, including multi-channel alerting, out-of-band coordination, validated identity protection, and certifications such as FIPS, Common Criteria, and FedRAMP Class D (High).

Start with this single question today: if you isolated your operational technology tonight, could your team still coordinate the response by morning? The answer tells you where your 90 days should begin.

Related reading:

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now