Google Cloud Outlines Cybersecurity Priorities for Water Utilities in the AI Era
Google Cloud outlines cybersecurity priorities for water utilities, emphasizing asset visibility, security hygiene, segmentation, vendor controls, incident planning and responsible use of AI for cyber defense.
Xcademia Team
Xcademia Research Team

Google Cloud Outlines Cybersecurity Priorities for Water Utilities in the AI Era
Water infrastructure is becoming an increasingly important cybersecurity concern as operational technology systems become more connected to digital networks.
In its September 1, 2026, Cloud CISO Perspectives post, Google Cloud examines cybersecurity challenges facing water and wastewater utilities and outlines practical steps organizations can take to strengthen resilience.
The article, written by Chris Sistrunk of Mandiant Consulting and Stephanie Kiel of Google Cloud, focuses on operational technology (OT), internet-connected programmable logic controllers (PLCs), third-party access and the growing role of artificial intelligence in cyber defense.
Google Cloud says its threat intelligence teams have observed threat actors becoming bolder when targeting critical infrastructure amid geopolitical conflicts. The company also says it has recently observed increased targeting of internet-connected PLCs at U.S. water utilities.
At the same time, the article notes that water systems have existing operational safeguards. These include manual override capabilities and established water-quality checks that can provide additional protection before water reaches consumers.
The recommended response is therefore not based solely on advanced security technology. Google Cloud emphasizes cybersecurity fundamentals, stronger coordination between IT and OT teams, operational resilience and carefully governed use of AI.
Water Utilities Face a Distinct Cybersecurity Challenge
Water and wastewater systems combine digital technology with physical processes.
Operational technology can monitor and control equipment involved in water-related operations. This creates a security environment where cyber risks can intersect with physical infrastructure.
Google Cloud notes that cyber incidents have not historically tended to disrupt water operations, partly because operators have manual override capabilities and established water-quality checks.
Operational failures can also occur for reasons unrelated to cyberattacks.
These safeguards remain important, but Google Cloud says they should not replace fundamental cybersecurity controls. Instead, utilities should adopt a threat-informed, risk-managed approach that builds on existing operational resilience while strengthening digital security.

Six Security Actions Water Utilities Should Consider
For resource-constrained water and wastewater utilities, Google Cloud recommends concentrating on cybersecurity fundamentals.
The company identifies six areas where utilities can strengthen their defenses.
1. Inventory Assets and Assess Exposure
Utilities should identify their control systems and determine whether any are insecurely exposed to the internet.
Internet exposure can create opportunities for attackers to exploit vulnerabilities, making asset visibility an important starting point for security teams.
Understanding what systems are connected, how they are exposed and what access paths exist can help organizations identify areas requiring attention.
2. Strengthen Basic Security Hygiene
Google Cloud recommends replacing default credentials with strong passwords and hardening exposed access points, including firewalls.
These are foundational security measures, but they remain particularly important for organizations operating with limited security resources.
The guidance reinforces the idea that utilities do not necessarily need to begin with sophisticated security technology. Establishing and maintaining basic protections remains an important part of defensive strategy.
3. Protect Critical Systems With Backups
Google Cloud recommends following the 3-2-1 backup rule for critical systems.
This means maintaining:
Three copies of data
Two types of storage
At least one copy stored off-site
The company also recommends keeping critical spare equipment available to help minimize downtime following cyberattacks.
For OT environments, recovery can involve more than restoring files or applications. Physical equipment and operational processes may also need to be considered when preparing for disruption.
4. Segment Networks and Control Remote Access
Network segmentation can help separate different parts of an environment and limit unnecessary connectivity.
Google Cloud recommends using multifactor authentication for remote access and suggests using read-only access when full control is not required.
These measures can help utilities better control who and what can access operational environments.
5. Integrate Cybersecurity Into Emergency Planning
Cyber incidents should be incorporated into existing all-hazards incident command structures.
Google Cloud specifically points to structures such as the Federal Emergency Management Agency's National Incident Management System (FEMA NIMS) and the Incident Command System for Industrial Control Systems.
The broader recommendation is to integrate cyber incidents into emergency-management processes already used for situations such as physical pipe failures, boil-water alerts and natural disasters.
6. Secure Third-Party and Vendor Access
Many water utilities rely on third-party system integrators and maintenance contractors for aspects of their IT and OT environments.
That creates additional access paths that need to be managed.
Google Cloud recommends auditing remote connections used by system integrators and maintenance contractors.
The company also says third-party vendors should be subject to rigorous access controls and logging requirements, including multifactor authentication standards.
These recommendations echo guidance from organizations including the American Water Works Association, National Rural Water Association, Water-ISAC, Environmental Protection Agency, Cybersecurity and Infrastructure Security Agency and FBI.
Bridging the IT and OT Governance Gap
Google Cloud says IT and OT leaders need to work together on a unified governance framework.
The company frames this as a long-term effort to make cyber-physical systems more resilient, adaptable and capable of recovering from disruptions.
OT environments have operational requirements that can differ from conventional enterprise IT environments.
At the same time, increasing connectivity means the two areas cannot always be treated as completely separate security domains.
This makes coordination between IT, OT and security teams increasingly important.
Google Cloud also recommends moving beyond simple compliance checklists toward a more agile, threat-informed strategy.
The objective is to make strong security and resilience the foundation, with compliance becoming a natural outcome rather than the sole measure of security effectiveness.
Why Software Security Still Matters in OT
PLCs generally sit outside conventional software development practices.
However, Google Cloud argues that applying stronger software-security practices to the software an organization uses can strengthen its overall security posture.
The article points to the NIST Secure Software Development Framework (SSDF) as an example.
Google Cloud also discusses leading indicators that organizations can use to evaluate resilience.
The broader message is that OT security does not exist independently of software security. Modern operational environments can depend on interconnected software, systems and services, creating areas of overlap between traditional IT security and OT security.
The Mandiant OT Theory of 99
A central concept discussed in the article is the Mandiant Operational Technology Theory of 99.
According to Google Cloud, the theory highlights the significant role conventional IT infrastructure can play in intrusions that eventually reach OT environments.
The article identifies several observations:
99% of compromised systems will be computer workstations and servers.
99% of malware will be designed for computer workstations and servers.
99% of forensics will be performed on computer workstations and servers.
99% of detection opportunities will involve activity connected to computer workstations and servers.
99% of intrusion dwell time happens in commercial, off-the-shelf computer equipment before Purdue Level 0-1 devices are impacted.
The theory highlights a potential defender advantage.
Rather than focusing only on the final OT layer, security teams can concentrate significant defensive attention on the IT and intermediary infrastructure that may be involved before an intrusion reaches physical operational processes.
Google Cloud says there is often significant overlap between the tactics, techniques and procedures used against IT and OT environments.
The source does not provide independent measurements showing how effective this approach is across water utilities.

AI as a Force Multiplier for Cyber Defense
Google Cloud also examines how AI could change cybersecurity operations in critical infrastructure.
The company says AI capabilities can potentially shift the balance in network security toward defenders, particularly as malicious actors increasingly use AI capabilities across the attack lifecycle.
For security teams with limited resources, automation could serve as a force multiplier by supporting decision-making and productivity.
However, Google Cloud stresses that AI integration needs to be structured and intentional.
Organizations should consider:
Vulnerabilities AI can introduce to physical processes
Business uses where security automation could provide value
Continuous testing
Continuous monitoring
Human oversight
Integration with incident response plans
Google Cloud points to its Secure AI Framework as an approach for helping organizations securely integrate and deploy AI capabilities.
Why Human Oversight Still Matters
The article does not present AI as a replacement for security professionals.
Instead, Google Cloud says human oversight must remain central.
AI should support decision-making, while safety practices should be embedded directly into incident response plans.
This distinction is particularly important for water infrastructure because cybersecurity decisions can intersect with physical operational processes.
The source does not provide specific information about autonomous AI control of water infrastructure.
Instead, its focus is on using AI capabilities to support defenders while retaining human expertise in decision-making.
For critical infrastructure operators, the implication is that AI-assisted security should operate within defined governance, safety and response processes.
Google's Secure AI Framework
Google Cloud says it has developed its Secure AI Framework to help organizations securely integrate and deploy AI capabilities across sectors.
The article emphasizes several considerations for organizations introducing AI into security environments:
AI-related vulnerabilities
Security automation opportunities
Continuous testing
Continuous monitoring
Human oversight
Incident response
Physical-process safety
The goal is to gain potential defensive benefits from AI without introducing unmanaged risks into operational environments.
From Compliance Checklists to Threat-Informed Security
Google Cloud argues that organizations should move beyond simple compliance checklists.
Compliance remains relevant, but the company recommends a more agile, threat-informed strategy focused on actual security and resilience.
For water utilities, that means understanding:
Which assets are exposed
Which access paths exist
Where third parties connect
How networks are segmented
How critical systems can be restored
How cyber incidents fit into emergency response
Where AI can safely support defenders
The broader message is that resilience depends on how security controls work together rather than on individual compliance requirements.

What Comes Next for Water Security?
Google Cloud describes water security as both a cybersecurity issue and a public safety concern.
Because reliable access to clean water is an essential service, the company anticipates that federal, state and local governments will increasingly move from policy debate toward action aimed at protecting critical water infrastructure.
The article points to a pilot program launched by the Office of the National Cyber Director in partnership with the State of Texas to help protect water infrastructure providers from cyberattacks.
It also notes that U.S. senators have introduced new legislation in response to recent events.
The supplied source does not provide additional details about the specific provisions of the legislation or the full scope and outcomes of the pilot program.
Additional details were not disclosed in the announcement.
What This Means for Water Utilities
The announcement highlights a broader industry shift toward treating cybersecurity as part of operational resilience rather than as a separate IT responsibility.
For water utilities, the recommended starting point is relatively fundamental: understand exposed assets, strengthen authentication, segment networks, maintain reliable backups and control third-party access.
AI adds another layer to this discussion.
Google Cloud sees AI as an opportunity to augment security teams, particularly where organizations have limited resources. At the same time, the company emphasizes structured governance, testing, monitoring and human oversight.
For critical infrastructure organizations, this could mean that AI security programs need to account for both digital and physical consequences, particularly when AI-enabled capabilities are introduced into environments connected to operational technology.
The practical impact will depend on each organization's infrastructure, resources, risk profile and operational requirements.
What Organizations Should Do Next
For water and wastewater utilities, the source points toward a practical sequence.
First, understand the environment.
Identify connected assets, exposed control systems, remote connections and third-party dependencies.
Second, strengthen the fundamentals.
Remove default credentials, improve authentication, segment networks and protect critical systems with reliable backups.
Third, prepare for recovery.
Incident response should address both cybersecurity and operational consequences.
Fourth, strengthen IT and OT coordination.
Security decisions need to account for both digital risks and the physical processes supported by operational technology.
Finally, introduce AI deliberately.
AI can potentially improve security analysis, automation and decision support, but organizations should establish appropriate governance, testing, monitoring and human oversight before relying on AI-assisted security capabilities.
Conclusion
Google Cloud's September 2026 guidance places cybersecurity fundamentals at the center of protecting water infrastructure in the AI era.
The recommendations range from asset inventory and stronger authentication to network segmentation, backups, emergency planning and tighter vendor controls.
At the same time, Google Cloud argues that AI can provide additional defensive capabilities by helping security teams analyze threats, support decision-making and automate aspects of security operations.
The article's emphasis, however, is not on replacing human security expertise with AI.
Instead, it presents AI as a supporting capability that should operate within structured security, safety and governance frameworks.
For water utilities, the broader lesson is that stronger cyber resilience starts with understanding the systems already in place, protecting their access paths and preparing to respond when defenses are tested.
AI can add another layer of support, but the fundamentals remain essential.
Source: Google Cloud Blog
About the Author