ics-ottrade-pressNewsThe Broadside2 min read

NIST issues remote-access guide for water system OT

The guidance is the first federal document to treat water utilities' operational realities (unmanned sites, vendor remote support, 15-to-20-year equipment lifecycles) as the design constraint, not an afterthought.


TL;DR

NIST published a guide laying out three reference architectures for securing remote access to operational technology at water and wastewater systems. The publication addresses unauthorized access to unmanned control sites (the threat vector NIST engineer CheeYee Tang identified as the water sector's top survey-ranked concern) and aims to serve smaller utilities that lack in-house cybersecurity expertise. One architecture uses a cloud-based model to lower the cost and skill barrier for budget-constrained operators. NIST says the approaches apply to other critical-infrastructure OT environments facing the same vendor-support and equipment-longevity constraints.

The guide doesn't arrive in a vacuum. CISA, the NSA, the FBI, the EPA, and the DOE have been urging critical-infrastructure operators since at least 2020 to remove OT connections from the public internet and secure whatever remote-access paths remain. What NIST adds is implementation detail: three reference architectures that an engineering team can evaluate against its own plant topology, rather than another set of principles to interpret.

Tang, speaking on the Federal Drive, was blunt about why remote access leads the priority queue. Unmanned pump stations and treatment sites house control equipment capable of disrupting normal operations or causing system failure. When a vendor or operator dials in for maintenance, that same channel is what an intruder would use. "They could disrupt and stop the water," Tang said. "They could potentially change the content of the water system."

The architectures aren't one-size. The "classic" model covers utilities that already have on-premise infrastructure and the staff to run it. The cloud-based model is aimed at the other end of the spectrum, small operators who don't have a security engineer on payroll and need a managed entry point that doesn't require building a VPN concentrator from scratch. That design choice reflects the NIST team's survey finding: many water systems lack the resources and expertise larger utilities take for granted.

Practical gap

The guide doesn't mandate a specific remote-access architecture. It demonstrates options. What it doesn't do is tell a utility with 15-year-old PLCs and a maintenance contract with the original vendor how to retrofit those devices without breaking the support arrangement. Nor does it set a compliance expectation that state regulators or EPA auditors can enforce. That gap matters because water-sector cybersecurity regulation in the U.S. remains fragmented (some states require EPA sanitary survey reviews to include cyber, some don't) and a NIST guide carries no compliance weight unless an authority incorporates it.

CISA's May 2025 fact sheet on OT mitigations, co-signed by the EPA and DOE, urged operators to "remove OT connections to the public internet" and "secure remote access to OT networks" as a primary mitigation. NIST's guide operationalizes the second of those two instructions. It also implicitly concedes the first won't happen for much of the sector. Water utilities, particularly small ones, aren't going to stop letting contractors and vendors connect remotely to diagnose SCADA faults, the operational cost of truck-rolling a technician to every wellhead is prohibitive. The guide accepts that reality and tries to make the connection architecture defensible.

For a municipal IT director or a state CISO advising water authorities, the guide provides a reference to cite when asking for budget. For an assessor evaluating a utility's cybersecurity posture under a state sanitary survey, it supplies three architectures to benchmark against, even if the benchmark isn't regulatory yet.


Published ·Deep Fathom