Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud The latest on security from Google Cloud's Office of the CISO, twice a month. Welcome to the second Cloud CISO Perspectives for August 2026. Today, Chris Sistrunk and Stephanie Kiel detail the critical issues facing the water sector, and actionable steps that OT operators can take to secure their infrastructure. Our curated insights hub for boards of directors highlights resources on cybersecurity, risk governance, and security transformation, including the latest blogs and research from Google Cloud.
By Chris Sistrunk, Practice Leader, OT, Mandiant Consulting, and Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud Google Cloud’s threat intelligence teams have observed that threat actors are becoming bolder when targeting critical infrastructure amid geopolitical conflicts. Recently, we’ve seen increased targeting of water utilities' internet-connected programmable logic controllers in the U.
Historically, cyber incidents haven’t usually disrupted operations, in part because water utility operators have long had manual override capabilities and established water-quality checks that kick in before water reaches consumers. Pumps and pipes fail routinely for reasons that have nothing to do with cyber threats. However, they do require our urgent attention and a commitment to stronger security hygiene. Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.
We recommend a threat-informed, risk-managed response. The current state of water sector security is indicative that additional action should be strongly considered in light of the unique operational resilience that keeps these systems safe. For resource-constrained utilities, the most effective defense is to focus on cybersecurity fundamentals . By prioritizing these fundamental practices, you can significantly harden your systems and transform your organization into a far more challenging and resilient target, causing even well-resourced threat actors to look elsewhere.
