Water utilities operate within a high-risk threat environment. According to ColorTokens, public water systems are being targeted by state actors, with particular focus on programmable logic controllers (PLCs) and human-machine interfaces (HMIs)—the devices that control treatment, pressure, and distribution.
This matters because water infrastructure sits at the intersection of criticality and vulnerability. Unlike IT networks, operational technology (OT) systems were designed for reliability and uptime, not security. A compromised PLC or HMI doesn't just expose data; it can alter chemical dosing, pressure regulation, or flow control in ways that cascade downstream to thousands of consumers. The attack surface is expanding as utilities connect legacy systems to networks for remote monitoring.
ColorTokens identifies three core defensive layers: asset visibility (knowing what devices exist on your OT network and their configurations), Zero Trust controls (treating every connection as untrusted until verified), and microsegmentation (isolating critical OT assets from lateral movement).
What separates this from theoretical threat modeling is the specificity: state actors are already moving against these targets. This signals a shift from opportunistic attacks on water systems to coordinated, sophisticated threats. Water utilities lack the security staffing and budget of power grids or financial institutions, making them attractive targets relative to resistance.
The immediate pressure is on utilities to audit their OT networks now—not after a breach. Asset discovery is step one: do you know every PLC, HMI, and supervisory control system on your network? If you can't answer that, you can't defend it. Microsegmentation requires network redesign, but it's the difference between one compromised device and a cascading failure across the system.

