What is OT security in the water sector?
OT security in the water sector is the protection of the control systems that drinking water companies, water boards and Rijkswaterstaat use to abstract, treat, distribute, drain and manage water, so that cyberattacks cannot disrupt the supply of safe drinking water, wastewater treatment or water level management. It covers SCADA systems, PLCs and RTUs spread across thousands of sites, from pumping stations and reservoirs to polder pumping stations and sewage treatment works. Because an outage directly affects public health or, in a low-lying country like the Netherlands, flood protection, water counts as critical infrastructure.
π― Why is the water sector so critical?
Drinking water and wastewater both appear in Annex I of NIS2, the list of sectors of high criticality. An attack on the control system can change chemical dosing, drop the pressure in the distribution network or halt a treatment plant, with risks for public health and the environment. In the Netherlands, water management adds a further dimension: pumping stations, weirs and locks keep low-lying land dry.
At the same time the sector is vulnerable. Installations run for twenty years or more, many sites are unmanned and operated remotely, and smaller organisations have little in-house OT security expertise. As early as March 2019 the Netherlands Court of Audit (Algemene Rekenkamer) reported that by early 2018 Rijkswaterstaat, the national water authority, had still not implemented around 40% of the planned security measures for its vital water works. During a test, ethical hackers broke into the control centre of a water structure; Rijkswaterstaatβs security operations centre only spotted them when they plugged a laptop into the network.
π§± Who are the players in the Dutch water sector?
| Organisation | Role | Typical OT |
|---|---|---|
| 10 drinking water companies | Abstracting, treating and supplying drinking water | Pumping stations, treatment plants, reservoirs, distribution network |
| 21 water boards (waterschappen) | Water levels, flood defences, wastewater treatment | Polder pumping stations, weirs, over 300 sewage treatment plants |
| Rijkswaterstaat | National water system and wet infrastructure | Locks, storm surge barriers, bridges |
| Municipalities | Sewerage | Sewage pumping stations |
| Vewin | Association of the drinking water companies | Advocacy, sector agreements |
| Unie van Waterschappen | Umbrella body of the water boards | Policy and coordination |
| Het Waterschapshuis | Shared ICT organisation of the water boards | Hosts CERT-WM, co-author of the CSIR |
Two sector channels handle incident response and information sharing. CERT Watermanagement (CERT-WM) was founded on 1 October 2016 by Het Waterschapshuis and Rijkswaterstaat and supports all 21 water boards. Since the Dutch Cybersecurity Act entered into force on 15 August 2026, CERT-WM has been the legally designated sectoral CSIRT for the water boards. The drinking water companies share threat intelligence in the Water-ISAC, a public-private partnership that includes the NCSC.
π§ What OT runs in the water sector?
A typical drinking water company or water board operates hundreds to thousands of outstations from one or a few control centres:
- Central SCADA β monitors pumping stations, treatment stages and drainage pumps and gathers alarms in a control room that is often staffed around the clock
- Telemetry and RTUs β small unmanned outstations communicate with the centre over 4G, fibre or radio, often using protocols such as Modbus TCP or DNP3
- PLCs β control pumps, valves, aeration and chemical dosing locally
- Analysers and sensors β measure turbidity, pH, chlorine, level and flow
- Remote access β suppliers and on-call engineers log in outside office hours to resolve faults
It is precisely this combination of many dispersed sites, public mobile networks and third-party access that makes the attack surface so large.
π¨ Which incidents are known?
| Incident | Year | What happened | Lesson |
|---|---|---|---|
| Oldsmar (Florida) | 2021 | Sodium hydroxide dosing was raised remotely from 100 to 11,100 ppm; in 2023 the former city manager said it was an employee error and that the FBI had found no evidence of a hack | Contested, but it exposed the risks of unsecured remote desktop access |
| South Staffordshire Water (UK) | 2022 | The Clop ransomware gang breached the IT network and leaked material including SCADA screenshots; supply was not affected | IT breaches can expose OT information |
| Waternet (Amsterdam) | 2021β2022 | Not an attack: the ILT placed the drinking water company under enhanced supervision for insufficient control of its cybersecurity | The supervisor acts on governance, not only after an incident |
| Aliquippa (Pennsylvania) | 2023 | CyberAv3ngers took over a Unitronics PLC at a booster station using its default password | Internet-connected PLCs are an easy target |
| Southern Water (UK) | 2024 | Black Basta ransomware hit the IT estate at a cost of around Β£4.5 million; operations continued | Separating IT from OT limits the impact |
There is no publicly known cyberattack that has disrupted drinking water supply or water management in the Netherlands. Attempts are common, though: in 2021 the Aa en Maas water board reported more than a thousand password-guessing attempts a day, adding that every water board sees the same.
βοΈ Which rules apply to the water sector?
Since 15 August 2026 drinking water companies and wastewater operators, including the water boards, have been covered by the Dutch Cybersecurity Act (Cyberbeveiligingswet). The Cybersecurity Regulation of the Ministry of Infrastructure and Water Management (Cyberbeveiligingsregeling IenW) details the duty of care and the reporting obligation for these sectors, and the Human Environment and Transport Inspectorate (ILT) is the supervisor.
- Drinking water β the Drinking Water Act (Drinkwaterwet) applies alongside the Cybersecurity Act. Every drinking water company draws up a supply plan with scenarios, including cyberattacks, which the ILT reviews
- Incident reporting β you report a significant incident with an early warning within 24 hours and an incident notification within 72 hours; for drinking water an incident is significant when 10,000 or more connections are without drinking water for six hours or longer (see Cybersecurity Act Incident Reporting)
- Water boards β as public bodies they follow the BIO. The former BIWA (Baseline Informatiebeveiliging Waterschappen) was absorbed into the BIO in 2020
- Physical assets β for pumping stations, locks and treatment plants, the CSIR translates the BIO and IEC 62443 into measures per asset class
π οΈ How do you secure water sector OT step by step?
- Map every site β build an asset inventory of each outstation, including modems, SIM cards, PLC firmware and connections. Many organisations discover forgotten 4G routers along the way
- Take OT off the internet β check whether controllers or HMIs are directly reachable; internet exposure was the way in at Aliquippa
- Secure remote access β let suppliers log in only through a jump server with MFA, time-limited accounts and logging
- Segment β separate office IT, central SCADA and the telemetry network through network segmentation into zones, using a private APN for 4G links
- Monitor β deploy network monitoring that understands OT protocols and flags unusual commands to pumps and dosing systems
- Practise manual operation β make sure treatment plants and pumping stations can keep running locally and by hand if SCADA fails, and rehearse this every year
- Organise the reporting chain β agree who engages CERT-WM or the NCSC during an incident and who submits the early warning within 24 hours
β Frequently asked questions
Do Dutch water boards fall under the Cybersecurity Act?
Yes, Dutch water boards fall under the Cybersecurity Act both as wastewater operators and as public bodies. Since 15 August 2026 the duty of care, the reporting obligation and the registration obligation have applied to them. CERT-WM is the legally designated CSIRT for the water boards.
Who supervises cybersecurity at Dutch drinking water companies?
The Human Environment and Transport Inspectorate (ILT) supervises cybersecurity at the ten Dutch drinking water companies. It does so under both the Cybersecurity Act and the Drinking Water Act. In 2021 the ILT placed Waternet under enhanced supervision because of shortcomings in its cybersecurity.
What is CERT-WM?
CERT-WM (CERT Watermanagement) is the computer emergency response team of the Dutch water boards, set up in 2016 by Het Waterschapshuis and Rijkswaterstaat and hosted by Het Waterschapshuis. The team helps water boards detect and handle cyber incidents. Since August 2026 CERT-WM has been the legally designated sectoral CSIRT.
What was the BIWA?
The BIWA (Baseline Informatiebeveiliging Waterschappen) was the information security baseline of the Dutch water boards. In 2020 the BIWA was merged into the BIO, the shared baseline for all tiers of Dutch government. For OT assets, water boards supplement the BIO with the CSIR.
Why are pumping stations vulnerable to cyberattacks?
Pumping stations are often unmanned, spread across a large area and connected to the control centre over 4G or telemetry links. Their controllers run for years without updates and are sometimes directly reachable from the internet. That makes pumping stations an attractive target for hacktivists.
Has Dutch drinking water ever been hacked?
There is no publicly known cyberattack that has disrupted the Dutch drinking water supply. Water boards do face password-guessing attempts every day; Aa en Maas counted more than a thousand a day in 2021. Incidents abroad, such as Aliquippa, show that poorly secured water installations are actively attacked.
π In summary
OT security in the water sector protects the control of drinking water, wastewater and water management, a sector that since 15 August 2026 has been covered by the Dutch Cybersecurity Act and the supervision of the ILT. The biggest risks lie in dispersed outstations, internet-connected controllers and third-party access; asset inventory, segmentation, monitoring and rehearsed manual operation form the foundation.
