
Sector
Water Sector
Drinking water supply and wastewater disposal are critical infrastructure. NIS2, the KRITIS umbrella act, and the revised EU Drinking Water Directive combine cybersecurity, OT security, and physical resilience into a single set of obligations — and for the first time bring many small and medium-sized operators within scope. We consolidate these requirements across all levels into a robust security architecture.
Overview
A Sector in Transition
The water sector in Germany is highly fragmented. Approximately 5,500 water utilities and thousands of wastewater operators share responsibility for supply, organised almost entirely at municipal level through municipal utilities, municipal enterprises, and special-purpose associations. This structural fragmentation has historical roots and makes operational sense from a supply perspective, but it poses a security challenge: many operators employ small teams, have no dedicated IT security staff, and yet run highly networked facilities.
The water sector has undergone significant digitalisation — often precisely because staffing is scarce. Water reservoirs, pumping stations, treatment plants, and wastewater treatment plants are now operated via programmable logic controllers (PLCs) and SCADA control systems, frequently with remote maintenance and remote control technology spanning dispersed, geographically distributed sites. Operational technology (OT) is converging with corporate IT — IT/OT convergence. What was originally conceived as a closed, locally operated system has become a remotely controllable network of sensors, actuators, and control rooms. The boundary between an IT incident and a genuine supply disruption is consequently blurring — and this concerns a commodity whose failure, unlike electricity, cannot be bridged by a backup generator.
The Threat Landscape
The vulnerability of water facility control systems has been evident in Germany for years — not through a single large incident, but through recurring findings of security weaknesses. As early as July 2016, two security researchers identified the human-machine interfaces (HMIs) of several German waterworks that were accessible from the internet without protection and without meaningful authentication. In some cases, the facilities could be operated remotely — including their pumps — rather than merely observed. The Federal Office for Information Security (BSI) notified the operators and the access points were closed.[1] In April 2019 the pattern recurred: during a penetration test, researchers gained full control of a wastewater treatment plant whose process control system was openly accessible on the network and operated with a pre-filled username — the password was equally straightforward to guess.[2] In both cases the targets were live operational facilities, not laboratory environments.
Internationally, theoretical possibility has long since become actual attack. In February 2021, an attacker in Oldsmar, USA, gained remote access to the treatment plant and set the sodium hydroxide dosage to a toxic level — an employee noticed the manipulation on screen and reversed it.[3] In November 2023, the Iranian-attributed group CyberAv3ngers compromised an internet-exposed Unitronics controller in Aliquippa, Pennsylvania, using a default password, and defaced the operator terminal; the facility switched to manual mode and supply remained stable. The case is instructive precisely because the point of entry was trivial — factory default settings, an open port, no second factor. At the time of the attack, approximately 1,800 identical controllers were openly accessible from the internet worldwide, including in Europe.[4] In October 2024, an attack struck American Water, the largest water utility in the United States serving 14 million people; the company took its customer portal and billing systems offline as a precaution, while core operations continued.[5]
In Germany, supply has remained stable to date — attacks have affected administration, communications, and customer services. At the Trinkwasserverband Stader Land, an attack in July 2023 disrupted email and general reachability for several weeks; no data was encrypted and water supply continued uninterrupted.[6] The ransomware attack on the municipal IT service provider Südwestfalen IT in October 2023 affected more than a hundred municipalities through a single point of failure — wastewater fee collection was also suspended for months.[7] The most probable risk today is less the manipulation of water quality than the gradual erosion of operational control, situational awareness, and the capacity to act — compounded by the leverage that a single compromised service provider can exert over many operators simultaneously.
The official figures warrant careful interpretation. For the year 2020, the BSI received 419 critical infrastructure (KRITIS) reports in total — 73 from the energy sector, but only seven from the water sector.[8] This low figure reflects primarily the state of regulation: nationwide, only approximately 47 of some 5,500 water utilities were classified as critical infrastructure at all, as the reporting obligation was triggered only from a threshold of 500,000 residents served.[9] Where no reporting obligation exists, little is reported — the seven notifications therefore represent only a narrow cross-section of the actual situation. Bavaria illustrates the disproportion: only three large utilities are subject to statutory requirements there, while approximately 2,100 others are not. The President of the Bavarian State Office for Information Security summarised the position in May 2025 — well-networked systems, some accessible from the internet, but minimal on-site staff and certainly no IT security specialists.[10] Since 2024, the CyberSec@Wasser situation centre has been closing this gap, producing for the first time a dedicated threat assessment for the sector — operators there are monitoring ongoing attack attempts against IT and OT, thus far without significant success on the part of attackers.[11]
The Regulatory Drivers
The legislature has lowered the threshold radically. The NIS2 Implementation Act, in force since December 2025 and transposed into the BSI Act, no longer links obligations to a population served of 500,000 but instead to company size: drinking water and wastewater operators qualify as important entities from 50 employees or €10 million in turnover. The previous KRITIS threshold no longer acts as a filter — many medium-sized municipal utilities and special-purpose associations that previously considered themselves unregulated now fall under binding requirements for risk management, attack detection, and incident reporting. Significant incidents must be reported within 24 hours, with a detailed follow-up report after 72 hours and a final report within one month. Non-compliance may result in fines of up to €10 million or 2% of annual turnover.[12]
The physical dimension is addressed in parallel. The KRITIS umbrella act, in force since March 2026 and transposing the European CER Directive (EU 2022/2557), makes the physical resilience of critical facilities a standalone obligation for the first time — requiring risk analysis, a resilience plan, and executive liability tied to the demonstrable effectiveness of the measures taken.[13] For the water sector, a third, sector-specific strand is added: the revised EU Drinking Water Directive (EU 2020/2184), transposed nationally through the Drinking Water Ordinance, requires a risk-based approach across the entire supply chain — from the catchment area through treatment to distribution. The risk assessment for drinking water catchment areas was required by November 2025; risk management for supply systems follows by January 2029. Risk-based thinking thereby becomes a permanent obligation rather than a one-off exercise.[14]
Technical standards provide the operational framework. The Sector-Specific Security Standard for Water/Wastewater (B3S WA), maintained by DVGW and DWA and recognised as appropriate by the BSI, specifies through the guidance document DVGW W 1060 / DWA-M 1060 how an information security management system (ISMS) is to be implemented in the sector. It applies explicitly to facilities below the KRITIS threshold as well.[15] The underlying logic is decisive: what is protected is the supply function itself, not merely the individual system — resilience over pure prevention, meaning the ability to act and recover even when an attack succeeds. Executive liability makes the comprehensive, documented demonstration of risk analysis, resilience planning, and effectiveness monitoring a direct responsibility of senior management.
Where the Critical Risks Lie
The most challenging risks rarely reside within a single domain. They emerge at the interfaces — where conventional IT, operational technology, physical security, and external service providers converge and are in practice often managed in separate accountability silos. In the water sector, a structural factor compounds this: geographically dispersed, frequently unmanned remote sites — water reservoirs, pumping stations, and pressure boosting stations — connected via remote control technology. Each such connection is a potential entry point, and physical access to an outlying station generally implies full access to the control systems. Cyber and physical security cannot be separated here.
OT environments cannot be secured using the methods of conventional IT security. In IT, confidentiality is the primary priority; in OT the order is reversed — availability and integrity come first. Patch cycles are long, many controllers run for decades, and a direct path from an office client to plant control systems must not exist at all. This is precisely where the sector's most common real-world vulnerability lies: controllers with factory-default passwords, unsecured remote maintenance access, and internet-accessible human-machine interfaces (HMIs) — the 2016 and 2019 findings and the Aliquippa case all follow the same pattern. Defence in depth addresses this: layered, mutually independent protective measures following the onion-layer principle, consistent network segmentation between IT and OT, zone and conduit models in accordance with IEC 62443, and the Zero Trust principle — no automatic trust, for either users or connections. Standards such as ISO/IEC 27001 and IEC 62443 provide the technical framework; they specify what regulation requires, but do not substitute for the architecture that holds IT, OT, and physical security together.
Sources
[1] Openly accessible HMIs at German waterworks, manipulable pumps (July 2016) — DER SPIEGEL · Golem.de
[2] Wastewater treatment plant penetration test, full control takeover (April 2019) — datensicherheit.de / PSW Group
[3] Oldsmar, Florida (February 2021): sodium hydroxide dosage manipulated, ~15,000 served — BBC
[4] Aliquippa, Pennsylvania (November 2023): CyberAv3ngers, Unitronics PLC with default password, ~1,800 exposed PLCs worldwide — Forescout · CSO Online
[5] American Water (October 2024): largest US water utility, 14 million people served, customer portal/billing taken offline — CNBC
[6] Trinkwasserverband Stader Land (July 2023): weeks-long disruption, no data encryption, supply uninterrupted — Tageblatt · Kreiszeitung Wochenblatt
[7] Südwestfalen IT (October 2023): >100 municipalities affected, wastewater fee collection disrupted, damage ~€1.5 million — Borncity
[8] BSI reports 2020: 419 critical infrastructure (KRITIS) reports in total, 73 energy, 7 water — Kompetenzzentrum Wasser Berlin
[9] ~47 of ~5,500 water utilities classified as critical infrastructure (KRITIS) (threshold: 500,000 residents served) — MDR (AG KRITIS / Manuel Atug)
[10] Bavaria (May 2025): only 3 large utilities subject to statutory requirements, ~2,100 others unregulated — BR24
[11] CyberSec@Wasser situation centre: first sector-level threat assessment since 2024, ongoing attack attempts against IT/OT — ZFK · kdw-nrw.de
[12] NIS2 Implementation Act: important entity from 50 employees / €10 million; reporting deadlines 24h/72h/1 month; fines up to €10 million / 2% — DVGW IT-Sicherheit · nisd2.eu
[13] KRITIS umbrella act (in force March 2026), CER Directive (EU) 2022/2557, executive liability — BSI-KritisV § 3 Sektor Wasser
[14] EU Drinking Water Directive (EU) 2020/2184, Drinking Water Ordinance; risk assessment by Nov. 2025, supply systems by Jan. 2029 — Rödl & Partner
[15] B3S WA / DVGW W 1060 / DWA-M 1060, BSI suitability determination, applies also below the KRITIS threshold — DWA

