NIS2 · Sector deep-dive
NIS2 for Drinking Water and Wastewater
Drinking water and waste water are two separate Annex I sectors of high criticality. Large in-scope utilities are therefore normally essential entities, supervised proactively rather than only after an incident. Most European water operators are municipally owned, run lean IT teams and depend on decades-old control systems — a combination the directive addresses head-on.
Why water utilities are a distinct problem
Water treatment and distribution is controlled by SCADA and PLC systems that were designed for reliability and safety, not for adversaries. Pumping stations, reservoirs and dosing equipment are geographically dispersed and reached over telemetry links — historically radio and leased lines, increasingly cellular and IP. Every one of those remote sites is a physical and logical entry point, and most utilities have more of them than they have security staff.
The publicly documented attacks on water operators in Europe and North America have largely not been sophisticated. They have exploited internet-exposed HMIs, default or reused credentials on remote access tools, and vendor maintenance connections. That is encouraging in one sense — the controls that would have stopped them are basic — and uncomfortable in another, because those basics are exactly what a small utility struggles to fund.
Consequences also differ from other sectors. A treatment plant that loses supervisory control can often keep flowing on manual operation for a while, so outright supply loss is rarer than feared; the sharper risks are loss of monitoring, incorrect dosing, and wastewater discharge events with environmental and public-health consequences.
Where water utilities typically have the biggest gaps
- Internet-reachable control systems. HMIs and remote-access gateways exposed for out-of-hours convenience, often discoverable through public scanning services.
- No inventory of remote sites and telemetry. Pumping stations added over decades, with no single list of what is connected, how, and by whom it is maintained.
- Integrator-held credentials. The automation contractor who built the plant often retains standing access and shared engineering passwords across multiple utilities.
- Continuity plans that stop at manual operation. Running the plant manually is written down; restoring the control system, and knowing that the backups of the PLC logic are current and readable, usually is not.
- Unclear reporting responsibility. In a municipal structure it is often ambiguous whether the utility, the municipality or the IT shared-service centre files the 24-hour early warning.
What this means for the Article 21 measures
- Basic cyber hygiene and training — Article 21(2)(g). Remove internet exposure, replace shared engineering accounts, and require MFA for all remote access. This is the highest-value work in the sector.
- Business continuity and backup — Article 21(2)(c). Offline, tested backups of PLC programs, SCADA configurations and historian data, with a documented restoration order and a rehearsed manual-operation procedure.
- Supply chain security — Article 21(2)(d). Contract with automation integrators for named individual accounts, time-boxed access, logging, and notification of vulnerabilities in the systems they supply.
The full measure list is on the Article 21 requirements page. Utilities identified under the CER Directive should build one evidence base serving both regimes.
Documentation
The NIS2 Starter Kit gives a small utility team the risk assessment, asset register, continuity plan and incident procedure without a consulting engagement.
