It looks like you are coming from United States, but the current site you have selected to visit is Slovenia. Do you want to change site?

Yes, please! No, keep me on the current site

Utilities don't have to choose between modernization and cybersecurity

By Rocio Echeverria, Senior Vice President and General Manager, Smart Water Division

September 17, 2026 Rocio Echeverria
Cybersecurity Municipal Drinking Water Municipal Wastewater

Utilities can modernize safely by choosing digital systems built with security from the start, using layered protections, encrypted data and controlled access that make connected infrastructure more secure, not less.

Rocio Echeverria is Senior Vice President and General Manager of Measurement and Control Solutions, Water, at Xylem, where she leads the business responsible for Xylem Vue and Sensus smart metering water solutions deployed across utilities. She has spent her career at the intersection of water technology and critical infrastructure protection, working alongside utilities as they navigate the dual pressures of modernization and security.

Recent cyber incidents affecting U.S. water utilities have put a question in front of every utility leader: can we keep modernizing without exposing our systems to attack? The same digital tools that help utilities do more with less, including real-time monitoring, remote operations and smart metering, can also create new cybersecurity considerations when foundational protections are not in place. According to Fortinet's 2024 Cybersecurity in Water Management Facilities Report1, one-third of water utilities reported experiencing at least one cyberattack in the previous 12 months, up from 22% in 2021.

We sat down with Rocio Echeverria to talk about what secure modernization looks like in practice, and why retreating from digital transformation is the wrong answer.

The recent incidents affecting several U.S. utilities got national attention. What actually caused them?

Rocio: The recent incidents were caused by the absence of basic cybersecurity architecture. Industrial control devices were connected directly to the public internet without network segmentation, firewalls, secure remote access controls or multi-factor authentication. These were not sophisticated breaches that defeated strong defenses. They were exposures: systems sitting open and reachable because the foundational security controls were never put in place. The problem is not connectivity itself. The problem is unmanaged, insecure connectivity.

So the answer isn’t to disconnect or slow down digital transformation?

Rocio: No. The answer is the opposite. Well-designed digital systems provide improved visibility, stronger controls, centralized management and more effective security capabilities than many legacy environments. Legacy systems were designed before today’s threat landscape existed and often cannot support modern encryption, authentication or monitoring. Retreating from digitalization means staying on systems that are harder to defend, not easier. The focus should be on secure connectivity, not eliminating connectivity.

What does secure-by-design look like in practice? How does Xylem approach this?

Rocio: Our approach is defense-in-depth, using multiple layers of security rather than relying on any single control. Across our digital water portfolio, we incorporate enterprise-grade network security, encrypted communications, secure user authentication, role-based access controls, continuous monitoring and independent security testing. But technology alone isn’t enough. Effective cybersecurity also requires clear governance processes so that risk is reduced through multiple layers of protection while maintaining the operational visibility and connectivity utilities need to run their systems effectively.

At Xylem, we've incorporated these principles because we believe cybersecurity should be built into modernization efforts from the beginning, not added later. Modern digital systems can strengthen both operational performance and resilience, helping utilities identify issues sooner, make more informed decisions, improve asset performance and respond faster when disruptions occur.

Many utilities, especially smaller ones, have limited cybersecurity resources. How do they move forward?

Rocio: This is the real challenge. Two-thirds of utility executives say cybersecurity is a top priority, but one-quarter of small systems have limited ability to implement cybersecurity controls2. That gap is structural, and it cannot be closed by regulation alone or by voluntary guidance alone. It requires sustained investment, technical assistance, workforce development and information sharing across the sector. AWWA and other industry leaders have called for expanded federal support, and the EPA has stepped up by proactively identifying vulnerabilities at 277 water systems and eliminating 350 vulnerabilities in 2025 alone3. Utilities also need technology partners who build security in from the start, so that adopting modern systems does not mean taking on new risk.

What should utility leaders look for when evaluating technology providers?

Rocio: Utilities should ask whether security is built into the solution from the outset or added later. Key questions include:

  • How is access controlled?
  • Is multi-factor authentication supported?
  • How is data protected?
  • How are vulnerabilities monitored and addressed?
  • What testing and validation processes are in place?
  • How is the solution maintained throughout its lifecycle?

Cybersecurity should be part of procurement decisions, not an afterthought.

Where this is heading

The sector is moving from treating cybersecurity as a compliance overlay to embedding it as a procurement and infrastructure planning requirement. Utilities are increasingly evaluating authentication, encryption, secure remote access, vulnerability management and lifecycle support alongside cost, performance and reliability. The shift reflects a broader understanding that cybersecurity is not simply a technology issue. It's a resilience issue.

Frequently asked questions

Start with the fundamentals: change default passwords immediately, reduce exposure to the public-facing internet, patch known exploited vulnerabilities, run cybersecurity awareness training, conduct regular assessments and develop an incident response plan. By building a strong cybersecurity foundation, utilities can modernize with greater confidence while improving the resilience, reliability and security of their operations.

Many water systems were designed before today’s threat landscape existed, and their operational technology often cannot support modern security protocols. According to EPA reporting, 70% of U.S. water systems do not fully comply with Safe Drinking Water Act requirements3, with vulnerabilities like unchanged default passwords and shared login IDs. One-quarter of small systems report limited ability to implement cybersecurity controls.

Utilities should ask whether cybersecurity is built into a solution from the outset or added later. Key questions include: Does the solution support multi-factor authentication? How is data protected in transit and at rest? How are vulnerabilities identified, monitored and addressed? What independent testing or security validation is performed? How is access controlled, and what lifecycle support is provided to keep systems secure over time? Cybersecurity should be evaluated alongside cost, performance and reliability as part of every technology and infrastructure investment decision.

Secure-by-design means building security controls such as authentication, encryption, network segmentation, secure remote access and vulnerability management into systems from the outset rather than adding them after deployment. Cybersecurity should be considered a core infrastructure requirement, not an afterthought. The most resilient utilities evaluate security, performance, reliability and lifecycle support together when making technology investment decisions.

Adding connectivity can increase the attack surface, but it does not necessarily increase risk. Risk depends on how that connectivity is designed, secured and managed. Many of the recent incidents affecting water utilities were not caused by connectivity itself. They were caused by weak controls such as exposed systems, default passwords and inadequate access management. A well-designed connected system supports stronger authentication, encryption, centralized management, continuous monitoring and other security controls that legacy environments often cannot provide. The goal is not to avoid connectivity. It's to ensure connectivity is implemented securely and supports operational resilience. 

The moment to invest is now

The recent incidents were a reminder, not a verdict. They showed what happens when modernization outpaces security, and they pointed clearly to the fix. Secure-by-design modernization is available now, and the utilities that adopt it will deliver reliable service with confidence, even as threats evolve.

The lesson from recent incidents is not that utilities should slow modernization. It's that modernization and resilience must advance together. As infrastructure becomes more connected, the organizations that succeed will be those that treat cybersecurity as a foundational requirement from the beginning rather than a safeguard added later.

1Fortinet, 2024 Cybersecurity in Water Management Facilities Report.
2American Water Works Association, 2026 State of the Water Industry Report.
3U.S. EPA Water Sector Cybersecurity Program reporting.