Cyber Security
Explore top cybersecurity practices for the Water and Wastewater Systems sector with CISA's latest toolkit and expert-led webinars. Learn how to enhance cyber resilience.
October is Cybersecurity Awareness Month, and this year's national theme, Securing the Next 250, reminds us of a vital truth: cybersecurity is not just a technical challenge, it is a shared responsibility that touches every corner of our organizations.
Every employee, regardless of their role, can make a difference in building our collective resilience. While automated network defenses catch a lot, your daily attention is your organization's primary operational defense. Whether you are managing administrative workflows, processing vendor invoices, or overseeing critical system infrastructure, everyday cyber hygiene directly protects your organization’s core mission, your public trust, and the local services that Delawareans rely on daily.
To support your team and help strengthen our shared defenses, as your Cybersecurity State Coordinator for Delaware, I am hosting a practical, non-technical webinar: Key Ways to Stay Secure Online: Securing the Next 250. This session is designed to explore real-world, actionable strategies to keep your operations resilient in the modern era.
We are offering four identical weekly sessions throughout the month of October. All sessions will be conducted via Microsoft Teams. You and your staff only need to register for one of the following dates:
- Session 1: Tuesday, October 6, from 12:00 PM to 12:45 PM [Register here]
- Session 2: Wednesday, October 14, from 10:00 AM to 10:45 AM [Register here]
- Session 3: Friday, October 23, from 10:00 AM to 10:45 AM [Register here]
- Session 4: Monday, October 26, from 11:00 AM to 11:45 AM [Register here]
Beyond attending the webinar, we encourage you to use this month to strengthen your team's defenses by practicing recommended cybersecurity behaviors in your daily work, such as using strong passwords, reporting suspicious activity, and following secure data handling procedures, and sharing these best practices across your own professional networks.
We encourage you to share this invitation with your leadership teams, operations staff, and colleagues. Securing our digital infrastructure requires consistent execution across the entire roster, and we look forward to working together to protect the systems and services that keep our state running. Thank you very much.
NRWA and the Water Information Sharing & Analysis Center (WaterISAC) have launched a pilot program providing 12 months of complimentary WaterISAC membership for eligible NRWA member utilities serving fewer than 10,000 people. Utilities may apply now through December 31, 2026. This offer is for new WaterISAC membership applicants only (current WaterISAC members are not eligible).
Small and rural utilities face many of the same cyber, physical security, and operational risks as larger systems, often with fewer dedicated resources. WaterISAC membership helps close that gap by delivering timely, water-sector-specific information and a trusted community for information sharing.
Benefits of membership include:
- Timely cyber and physical security alerts
- Weekly Security & Resilience Updates
- Threat analysis and incident reporting
- Webinars and expert briefings
- Water sector intelligence products
- A peer community focused on water sector security and resilience
Utilities enrolling through this pilot also receive access to WaterISAC’s H2OSecCon session, “Responding to a Cyberattack on a Small Water Utility,” which shares real-world lessons and actionable recommendations tailored to small systems.
To learn more and apply, please use one of the links below:
Press Release: https://www.waterisac.org/tlpclear-nrwa-and-waterisac-expand-complimentary-security-resources-to-small-water-utilities
___________________________________________________________________________________________________________________________________
Today, CISA and federal partners released the fact sheet CISA and Partners Urge Hardening Automatic Tank Gauge Systems in response to malicious cyber activity targeting U.S. automatic tank gauge (ATG) systems, which are widely used across critical infrastructure sectors.
● Remove ATG systems from public internet exposure
● Enforce strong, unique passwords and multifactor authentication
● Apply vendor patches and update software
● Monitor for unauthorized access and suspicious activity
For more information, review the full fact sheet. Report suspicious activity to CISA’s Operations Center (report@cisa.gov or 888-282-0870) and the FBI’s IC3 (www.ic3.gov).
Please share your thoughts with us through this anonymous survey. We appreciate your feedback.