Cybersecurity starts with engineering, not IT
October 7, 2026
AWWA Articles
Cybersecurity starts with engineering, not IT
Andrew Ohrt is co-author of “Resilience Through Cyber-Informed Engineering: An Engineering and Operations Approach to Cybersecurity,” and this Cybersecurity Awareness Month, he shares a bit more about how utilities can proactively design for protection against cyberattacks.
What is cyber-informed engineering?
Cyber-Informed Engineering (CIE) is an approach that applies engineering methods and controls to ensure the safety, reliability, and performance of operational systems against cyber-enabled compromise. It treats cyber risk as an engineering problem by identifying unacceptable consequences, then incorporating engineered controls and system design features to limit the harm an adversary can cause, even with full digital access. CIE extends the thinking from other hazards engineers already plan for — such as floods, earthquakes, and equipment failure — to cyber risk. Idaho National Laboratory developed the framework with support from the U.S. Department of Energy, and it became the basis of the National CIE Strategy released in 2022. CIE is organized around a set of principles that start with consequence-focused design: identify the worst outcomes first, then engineer the system so those outcomes are difficult or impossible to achieve.

What is the most common cybersecurity advice you give to utilities?
Providing blanket advice is increasingly tough to do because so many utilities have done great work on shoring up their cybersecurity already. My most common advice now is to look past the network and ask what happens at the plant when the controls stop working or cannot be trusted. Many utilities have strong IT-led security programs, but the people who keep the water flowing during an incident are operators and maintenance staff. I ask whether those staff know how to run the system without automation, whether the procedures for doing so are written down and current, and whether anyone has practiced them recently.
The second piece of advice is: Involve your engineers. Every capital project is a chance to design out a consequence, whether that means adding a local control option, specifying a hardwired safety function, or simplifying a system that has more connectivity than it needs. Utilities that treat cybersecurity only as an IT responsibility miss the engineering controls that do the most to protect the public.
What would A Day without SCADA® look like? How can utilities and engineers prepare for a scenario like this in advance?
A Day without SCADA® is an exercise that simulates a utility losing the ability to see or control its system remotely. That could come from a cyberattack, a ransomware incident that forces the utility to disconnect, a failed software update, a long power or telecommunications outage, or a decision to shut SCADA down because no one can trust what it is showing. That last case is the most challenging to address. Losing the screens is a problem. Losing confidence in the screens, without knowing what has been changed, is worse.
Utilities can prepare in several ways. The first is to identify which facilities and processes are most critical and confirm that each can be operated without automation, then write down exactly how. Second, keep those procedures current and stored somewhere that does not depend on the network, including paper copies at each site. Third, practice, practice, practice: Exercise the scenario. A tabletop exercise will surface gaps in decision-making and communications, and a functional exercise where crews actually run a station by hand will surface the gaps nobody thought to write down.
Even before a utility gets to the point of doing an exercise, engineers can design facilities so that operation without automation is possible and safe: local control panels, analog backup instrumentation, hardwired interlocks that protect equipment and people regardless of what the control system says, and process designs that fail to a safe state. Applying cyber-informed engineering principles during design is the best way to make sure that A Day without SCADA® is a hard day for the utility rather than a public health emergency.
Any final advice for utility leaders?
The targeting of our sector by adversaries is now undeniable and unambiguous. To the utility staff responsible for managing this risk: If you haven’t yet, get started with cybersecurity improvements. You are already responsible for everything critical to your operations: financial performance, treatment performance, and customer service. You have the same responsibility for cybersecurity now. You may be thinking that improvements cost money you don’t have right now, or that you don’t know where to start because you don’t have a plan. There is plenty of guidance, and there are plenty of people in both the public and private sectors who can help. AWWA even offers a planning template at https://www.awwa.org/resource/cybersecurity-guidance/. Make the call. Use it. Get started.
Advertisement