Cyber exposure in the U.S. water sector, and the case for a managed defense layer that scales to systems no one is defending.
What the data says
The vulnerabilities affecting American water systems are not only numerous, they are being weaponized faster than any small utility can respond. The gap between a flaw becoming public and that flaw being exploited has narrowed to a matter of days. No volunteer model, and no lone operations manager doubling as the IT person, closes a gap that short across more than 50,000 water systems. A shared, managed defense layer is the only structure that can.
Three findings
01 The exposure base is large and growing. Securin tracks 1,935 vulnerabilities affecting water and wastewater systems, up from the roughly 1,800 reported in early 2026. 242 are weaponized and 43 are confirmed exploited in the wild.
02 The exploitation window has collapsed. The average time from public disclosure to a working exploit is roughly two-thirds (64%) shorter for recent flaws than for those a decade old. Nearly a quarter of weaponized water-sector flaws had exploit code available on or before the day they were disclosed, and the median flaw is exploited within 11 Days.
03 The entry point is the edge, not the plant floor. In documented intrusions, attackers reached water utilities through internet-facing devices, remote-access services, and VPNs. The initial access vectors are the corporate and edge layer that sits in front of the control system, which is exactly the surface a small operator cannot watch alone.
A sector defended by almost no one
There are more than 50,000 community water systems and roughly 100,000 wastewater systems in the United States. The overwhelming majority serve fewer than 10,000 people, run on thin municipal budgets, and have no dedicated security staff. Federal reviews found that most water systems inspected in 2024 failed to meet basic cybersecurity standards, and that few had any cyber professionals on staff at all.
Against that backdrop, the vulnerability base keeps expanding. Securin Core tracks 1,935 vulnerabilities affecting the water and wastewater sector. The concern is not the raw count. It is what share of that count is already dangerous, and how quickly the rest becomes dangerous.
Twelve tracked threat actors target the water sector in Securin Core, nine of them Iran-linked (including CyberAv3ngers and the group tracked as Bauxite) and three Russia-linked. Their activity is not theoretical. In 2023 an Iran-affiliated group defaced internet-exposed programmable logic controllers at U.S. water utilities using default credentials. In April 2026, six federal agencies jointly warned of active Iranian exploitation of internet-connected controllers across water, energy, and government facilities, with real operational disruption. In June 2026, an Iran-nexus group claimed an attack on the largest water utility in the western United States. Days, not months
The single most important trend in the data is not how many vulnerabilities exist. It is how little time defenders now have. Across successive eras of disclosed-and-later-weaponized water-sector flaws, the average distance from public disclosure to a working exploit has fallen sharply. The window a utility has to patch before an exploit exists has all but closed.
Through the edge, into the plant
Documented attacks on water utilities have not begun at the control system. They have begun at the internet-facing edge: an unpatched firewall, an exposed remote-access service, a VPN protected only by a default password. Once inside that corporate and edge layer, an adversary can move toward the operational network that runs pumps, valves, and chemical dosing.
The cases below are illustrative examples, not a complete catalog. There are almost certainly more exploited vulnerabilities in use against the sector than any single view captures. Each of these has been used in real intrusion activity, each is weaponized, and each carries a high Securin Risk Index. What they share is the pattern: the way in is the edge and the remote-access surface.
The Littleton Pattern
The Volt Typhoon intrusion at Littleton Electric Light & Water in Massachusetts began through an unpatched, known vulnerability in a FortiGate firewall and went undetected for over 300 days. A nation-state pre-positioning campaign whose front door was an unpatched edge device is the clearest possible argument for continuous exposure management as a matter of national security, not routine IT hygiene. Ransomware comes in the same door
Nation-state crews are not the only adversaries using the edge. Securin Core links 456 vulnerabilities to ransomware. Grouped by the kind of software they affect, the ones that serve as entry points cluster in remote-access tools, VPNs, internet-facing web applications, and network devices. These are the initial access vectors: the routes an intruder uses to establish a foothold before moving toward anything operational.
Industrial control systems remain a serious target, and a successful reach into the control network is the highest-consequence outcome for any water utility. But it is rarely the way in. The door is the internet-facing and remote-access surface, and that is the surface a small utility with no security staff has no way to watch continuously.
No single provider is the answer
The Water Watch Center's design is a set of regional managed security providers reporting up to a national center housed under the National Rural Water Association. The question is which kind of provider can actually serve a utility that has fewer than five IT staff and serves fewer than 10,000 people. The market sorts into five categories, and no single one is sufficient on its own. The most plausible regional model pairs the field presence and water-domain trust of a control-system integrator with a shared, always-on security operations capability that covers both the edge and the operational network, running on the free tooling and federal support already available. Free and funded layers already exist to build on: federal vulnerability scanning for public water utilities, federal cybersecurity assessments, dedicated grant funding for rural and municipal utilities, and the National Rural Water Association's own cybersecurity center. The Center's job is to operate and integrate that support into a service a small utility can actually use, not to buy new tools.
What a credible defense layer requires
The findings in this brief point to three capabilities any managed defense layer for water has to include. They follow directly from the speed of weaponization, the edge-first entry pattern, and the scale of the sector.
1. Exploitation intelligence that runs ahead of the attacker.
With a median of eleven days from disclosure to exploitation, prioritization cannot wait on slow-moving public catalogs. The Center needs an intelligence source that identifies which flaws are being weaponized early and completely, so regional providers patch the few that matter before an exploit lands rather than chasing thousands that do not.
2. Continuous visibility of the edge and remote-access surface.
Because intrusions begin at internet-facing devices, the Center needs continuous external attack-surface monitoring across enrolled utilities, not a periodic scan. The goal is to see the exposed firewall or remote-access service the way an adversary sees it, and close it first.
3. Automation that scales to the whole sector.
No amount of hiring reaches 150,000 utility environments. Continuous, automated validation that can run cheaply across many small environments is the only way to cover the sector, and the Center is the natural proving ground for such approaches.
For water and wastewater organizations, the challenge is keeping pace with vulnerabilities that can become exploitable faster than traditional security processes can respond. As exploitation accelerates and adversaries continue to target internet-facing infrastructure, security programs need continuous visibility, risk-based prioritization, and validation focused on the exposures that are most likely to matter. Closing that window requires shifting from periodic assessment to continuous exposure management: understanding what attackers can reach, which weaknesses are most likely to be exploited, and where remediation will reduce risk fastest.