In late July, federal agencies warned water and wastewater utilities about a significant increase in attacks targeting internet-exposed operational technology. By early August, public reporting described similar incidents in at least seven states. The reported activity did not begin as a communications story. It began where these incidents always do: in control rooms, with operators trying to understand whether they still had visibility and control over the systems that keep water moving.

But the question from a customer is not whether a programmable logic controller is exposed to the internet. It is simpler, and more urgent: Is my water safe? Is service affected? What does this mean for my household?

That is why a cyber incident at a utility is never only a cybersecurity incident. It is a public-information emergency. Technical containment may be the first operational priority, but the information vacuum begins at the same time. If a utility has not decided who speaks, how often it updates, and how it will explain uncertainty in plain language, someone else will define the story before the facts are settled.

The public-facing risk is real — even when the technical facts are still moving

The federal alert is clear about the possible operational effects. CISA reported that attackers had changed passwords and IP addresses on exposed controllers, locking operators out and disconnecting equipment. The agency said the activity had resulted in boil-water notices and sustained manual operations. The FBI and EPA described reported impacts including loss of pressure and flooding; they also emphasized that the effect of a compromise depends on what the affected equipment controls and whether the utility can move safely to manual operation.

Those are technical facts with immediate communications consequences. A pressure issue, a shift to manual operations, or a precautionary notice creates a fast-moving set of questions for customers, employees, elected officials, regulators, and local media. It does not matter that an investigation is incomplete. People will reasonably want to know what they should do now.

Utilities should not speculate about attribution, the scope of a breach, or possible worst-case outcomes. They should communicate the decisions they have made, the practical guidance customers need, and the time of the next update. Credibility is built by distinguishing what is known from what is still being verified — not by waiting for every technical question to be resolved.

Four communications decisions that cannot wait for the incident review

1. Put public health and service guidance first. A first statement should lead with the facts people can act on: whether drinking-water quality is affected, whether service is uninterrupted, whether a boil-water or other precautionary notice is in effect, and where customers can get verified updates. Technical detail belongs behind that guidance, not in front of it.

2. Establish a single source of truth and an update rhythm. An incident page, a customer alert channel, and a media point of contact should all convey the same core information. Even if the only new information is that the investigation continues, a stated update time gives the public a reason to return to the utility rather than rely on a screenshot, a rumor, or a third-party account.

3. Brief the people who will be asked first. Call-center staff, field crews, board members, elected officials, mutual-aid partners, and community leaders need a concise, approved set of facts before they are left to answer questions on their own. The goal is not to give everyone a script. It is to make sure no one inadvertently contradicts a public-health instruction or fills an information gap with an assumption.

4. Practice the handoff between technical and communications teams. Cybersecurity and operations teams need room to investigate and restore service. Communications teams need a dependable route to verified facts, a decision-maker who can clear messages, and a way to flag the questions the public is asking. That handoff should be part of the incident plan, not invented in the first hour of an event.

Preparedness means more than a holding statement

A prepared utility does not write a generic cyber statement and call the job complete. It has an incident-specific communications annex that identifies the first questions customers will ask, the approval path for public-health guidance, the spokesperson and backups, customer-service protocols, notification channels, and how updates will be coordinated with local government, regulators, and law enforcement.

The utility should also rehearse the scenario. Federal guidance recommends that water systems routinely test their ability to operate safely on manual controls, maintain known-clean backups, and report incidents with operational detail. The communications equivalent is testing whether the organization can turn those operational facts into a clear public update in minutes — while the facts are incomplete, the stakes are high, and misinformation is already circulating.

For a utility, the objective is not to make a cyber incident disappear. It is to protect public health, restore operations, and preserve the trust that makes every difficult operational decision easier to carry out. Those goals require a technical response and a communications response that begin together.

Sigler has helped water providers communicate through contamination response, pipeline failures, boil-water advisories, operational disruptions, and other moments when communities need direct, useful information. Learn more about our crisis communications practice and our work with water utilities and infrastructure projects.

Sources
CISA alert, July 30, 2026 · FBI/EPA public service announcement, July 30, 2026 · EPA Incident Action Checklists for Water Utilities · NPR reporting, August 12, 2026.