Welcome to the second Cloud CISO Perspectives for August 2026. Today, Chris Sistrunk and Stephanie Kiel detail the critical issues facing the water sector, and actionable steps that OT operators can take to secure their infrastructure.
As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.
By Chris Sistrunk, Practice Leader, OT, Mandiant Consulting, and Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud
Google Cloud’s threat intelligence teams have observed that threat actors are becoming bolder when targeting critical infrastructure amid geopolitical conflicts. Recently, we’ve seen increased targeting of water utilities' internet-connected programmable logic controllers in the U.S.
Historically, cyber incidents haven’t usually disrupted operations, in part because water utility operators have long had manual override capabilities and established water-quality checks that kick in before water reaches consumers. Pumps and pipes fail routinely for reasons that have nothing to do with cyber threats.
However, they do require our urgent attention and a commitment to stronger security hygiene. Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.
We recommend a threat-informed, risk-managed response. The current state of water sector security is indicative that additional action should be strongly considered in light of the unique operational resilience that keeps these systems safe.
Actions water and wastewater utilities should consider
For resource-constrained utilities, the most effective defense is to focus on cybersecurity fundamentals. By prioritizing these fundamental practices, you can significantly harden your systems and transform your organization into a far more challenging and resilient target, causing even well-resourced threat actors to look elsewhere. Inventory assets and assess exposure: Identify if your control systems are insecurely exposed to the internet, which often allows for the successful exploitation of vulnerabilities.
Basic security hygiene: Replace default credentials with strong passwords, and rigorously harden exposed access points, including firewalls.
Backups: Make sure that critical systems, including control systems, are safeguarded following the proven 3-2-1 backup rule (keep three copies of your data on two types of storage, with at least one copy stored off-site). Ensure critical spare equipment is on-hand to minimize downtime from cyberattacks.
Segmentation: Use network segmentation and multifactor authentication to ensure that remote access, when necessary, is strictly controlled. You should use read-only access where full control isn't required.
Emergency planning: Integrate cyber-incident planning into your existing all-hazards incident command system, including FEMA NIMS and Incident Command System for Industrial Control Systems, the same response structures you already use for physical pipe breaks, boil water alerts, and natural disasters.
Secure third-party and vendor access: As many water utilities do not manage their own IT or OT and rely on third-party system integrators, you should audit the remote connections used by the system integrators and maintenance contractors. You should ensure third-party vendors are held to rigorous access controls (such as MFA standards) and logging requirements.
These recommendations echo guidance from the American Water Works Association, the National Rural Water Association, the Water-ISAC, the Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI.
Recommendations for IT and OT leaders: Bridging the governance gap
IT and OT leaders must work together to build a unified governance framework and should focus on making cyber-physical systems more resilient over the long term, a collective effort that spans government agencies, private sector organizations, and individuals. The goal is to build a future where these systems are secure, adaptable, and capable of recovering quickly from disruptions.
Although PLCs almost always sit outside standard software development practices, a robust approach to the software your organization uses can significantly enhance your overall security posture, such as those outlined in NIST’s Secure Software Development Framework (SSDF). They’re also good examples of leading indicators that can help you gauge your resilience, and to help you get started we’ve published a guide to evaluate leading indicators.
Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.
As technology evolves, it is critical to modernize security, transitioning from a reactive, manual model to an AI-augmented approach that keeps human expertise central to decision-making. This approach offers an unique opportunity to be a force multiplier for lean security teams.
To stay ahead of today’s threats, organizations must move beyond simple compliance checklists and adopt a more agile, threat-informed strategy that makes compliance a natural outcome of good security, rather than the primary goal.
The Mandiant Operational Technology (OT) Theory of 99 has become more relevant in the AI era. Although the funnel of opportunity has been significantly compressed, in intrusions that go deep enough to impact OT:
99% of compromised systems will be computer workstations and servers
99% of malware will be designed for computer workstations and servers
99% of forensics will be performed on computer workstations and servers
99% of detection opportunities will be for activity connected to computer workstations and servers
99% of intrusion dwell time happens in commercial, off-the-shelf computer equipment before any Purdue level 0-1 devices are impacted
As a result, there is often a significant overlap across tactics, techniques, and procedures used by threat actors who target IT and OT networks. However, the Theory of 99 underscores a significant defender's advantage in the AI era. By using advanced AI capabilities to secure the 99% of intermediary infrastructure, organizations can proactively neutralize threats and ensure robust protection for the critical 1% of physical operational processes.
AI for cyber defense
As we have shared before, AI capabilities offer the opportunity to shift the balance in network security in the favor of defenders. The defender’s advantage becomes even more important as malicious actors increasingly use AI capabilities across the attack lifecycle.
In the current threat environment, automating defenses can serve as a force multiplier for human security teams, enhancing decision-making and productivity to ensure critical exposures are addressed before they can be exploited. With careful planning, critical infrastructure providers can protect their physical assets while building a more resilient, threat-informed defense.
To effectively realize AI advantages for defense, you should integrate AI tools into systems in a structured, intentional way. It’s crucial that operators understand the unique vulnerabilities that AI introduces to physical processes, evaluate specific business uses that can benefit from security automation, and establish clear frameworks to continuously test and monitor. As part of our approach, we’ve developed the Secure AI Framework to help you achieve secure integration and deployment of AI capabilities, regardless of sector.
Most importantly, human oversight must remain central — meaning that AI should support decision-making, and safety practices need to be embedded directly into incident response plans.
What’s next for water security
Protecting water systems from malicious cyber threats is not just a technical challenge; it is a fundamental public safety imperative. Given that access to clean, reliable water is an essential service, we anticipate that federal, state, and local governments will increasingly shift from policy debate to decisive action to ensure the continuity of this critical public infrastructure in the face of cyber threats.
For example, the Office of the National Cyber Director in partnership with the State of Texas has just launched a pilot program to help protect water infrastructure providers from cyberattacks, and U.S. senators have already introduced a new bill in response to recent events. Google is committed to helping you protect your cloud and hybrid cloud OT environments. To learn more about Google guidance on securing critical infrastructure, please visit our CISO Insights Hub.
Here are the latest updates, products, services, and resources from our security teams so far this month:
Please visit the Google Cloud blog for more security stories published this month.
Please visit the Google Cloud blog for more threat intelligence stories published this month.
To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.