
What municipal utility directors need to know about cybersecurity in 2026: AWIA, NERC CIP, and TSA rules, common vulnerabilities, and vendor requirements.
Cybersecurity for municipal utilities is the mix of technical controls, operational procedures, and regulatory compliance that protects water, electric, and gas systems from ransomware and unauthorized access, covering both the software that manages billing and customer accounts and the operational technology that controls physical infrastructure. For a director, it is a governance responsibility: the binding federal requirement for water systems is AWIA Section 2013 risk and resilience assessments, and your utility software is both a compliance tool and, if unmaintained, a security liability.
For years, water-sector cybersecurity was largely voluntary. It is tightening, but not in the way many summaries suggest, so it is worth getting the facts right. This guide covers what actually applies in 2026, why small utilities are targets, the vulnerabilities regulators keep finding, and what to require from the software that sits at the center of your risk. It is written for directors of water, electric, and gas utilities. The platform that handles billing, meter data, and customer records, your utility billing software, is precisely the system whose security posture becomes your exposure.
Is your utility running aging on-premise software that a thin IT team cannot keep patched?
The assumption that a small municipal utility is too obscure to attract attackers is operationally dangerous. Ransomware groups do not select by notoriety; they select by vulnerability, and small, under-resourced systems running aging on-premise software with limited IT staff fit that profile. The defining US case is the 2021 Oldsmar, Florida water treatment incident, where an attacker reached control systems through remote-access software and tried to raise sodium hydroxide to dangerous levels for a community of 15,000. The pattern CISA and Water ISAC document is not sophisticated: entry through legacy remote-access software, default credentials never changed after installation, or unpatched systems an overstretched team has not updated. Moving off that aging footprint is itself a security measure, as covered in migrating legacy utility systems to the cloud.
Do you know which framework actually binds your utility, and which are voluntary?
Getting this right matters, because a widely repeated claim is out of date. The EPA proposed requiring cybersecurity assessments within water-system sanitary surveys in 2023, then withdrew that memo in October 2023 after litigation. It is not a current mandate. The binding federal requirement for water systems is AWIA Section 2013. Obligations differ by service type:
For water utilities, the current AWIA cycle is active: community water systems serving 3,300 or more must assess cybersecurity risk in their risk and resilience assessment and certify to the EPA on schedule. Whether you also face NERC CIP depends on your Bulk Electric System classification, which you should confirm with your regional reliability coordinator. Because software is central to that reporting, treat compliance and platform together, as in water utility regulatory compliance.
CISA and Water ISAC consistently find the same weaknesses in small and mid-sized municipal systems:
Registering with your sector information-sharing center, WaterISAC for water or E-ISAC for electric, gives small utilities the real-time threat intelligence they usually lack.
Can your board see documented evidence of your security posture today, or only after an incident?
A director does not need to become a security expert, but must ensure the right questions are asked and the evidence is documented. A practical sequence for 2026:
For the wider software-selection view, use the municipal utility software buying guide.
Would your current vendor pass an independent security audit, and can they prove it?
Your utility software processes customer PII, financial data, and consumption records, and sits between your IT and OT environments, so its security posture is directly your exposure. Require these in any RFP or renewal:
Cloud-native architecture matters most here: it removes the on-premise attack surface by design, with no local server to breach and no on-premise database to encrypt. That is a core reason utilities move, covered in why utilities move billing to the cloud. Insist these commitments are contractual, not sales-brochure claims.
AWIA Section 2013 requires community water systems serving 3,300 or more people to complete a risk and resilience assessment covering cybersecurity threats and to develop an emergency response plan, recertified to the EPA every five years. The 2025-2026 certification cycle is active. Separately, the EPA's 2023 proposal to require cybersecurity review within sanitary surveys was withdrawn after litigation, so it is not a current mandate, though the EPA and states still encourage voluntary review.
NERC CIP is a mandatory set of cybersecurity standards for Bulk Electric System operators in North America, enforced by FERC with penalties up to $1 million per violation per day. Whether it applies to a municipal electric utility depends on Bulk Electric System classification, which a director should confirm with their regional reliability coordinator. Regardless, CISA's Cybersecurity Performance Goals apply as a voluntary baseline.
At minimum, SOC 2 Type II, the independent audit that verifies controls operate over a sustained period; require the full report. Also require cloud-native architecture to eliminate on-premise attack surfaces, OAuth 2.0-compliant API integrations with audit logging, documented incident response SLAs, encryption in transit and at rest, and role-based access with a complete audit trail. These should be contractual commitments, not brochure claims.
They typically encrypt billing and customer information systems, making them inaccessible until a ransom is paid or systems are rebuilt from backup. Where OT and IT networks are not segmented, attacks can reach operational control systems. The most common entry points documented by CISA and Water ISAC are unchanged default credentials, unpatched remote-access software, and unsegmented IT and OT networks.
For a municipal utility director, cybersecurity is not an IT task to delegate and forget, it is a governance posture you must be able to document, to a regulator, a council, or an insurer. Get the compliance facts right, close the credential and patching gaps regulators keep finding, and hold your software vendor to a real security standard. See how a cloud-native utility billing software platform removes the on-premise attack surface and provides the SOC 2, encryption, and audit-trail evidence your compliance posture depends on.