Utility Security, Cybersecurity & Readiness
ARWA helps members protect facilities, people, and systems: physical security, cybersecurity, emergency planning, and customer-account fraud prevention. Contact your Circuit Rider or the ARWA office at arwa@alruralwater.com / (334) 396-5511 if you need assistance.
On this page: AWIA risk & resilience · Cybersecurity · Physical security checklist · Identity theft (Red Flags) · Alabama resources · Facility signs
AWIA risk and resilience (RRA & ERP)
Community water systems serving more than 3,300 people must complete Risk and Resilience Assessments and Emergency Response Plans and re-certify to EPA on a five-year cycle (AWIA Section 2013 / SDWA Section 1433). Those plans must address physical security and cybersecurity.
AWIA assistance, deadlines & free Circuit Rider help
Cybersecurity
Water and wastewater systems are critical infrastructure. Cyber incidents targeting industrial control systems (SCADA/OT), billing, email, and remote access are an ongoing national concern. ARWA encourages every system (large and small) to treat cybersecurity as part of everyday operations and emergency planning, not only as an IT project.
National partnerships (NRWA & WaterISAC)
Through the National Rural Water Association (NRWA), state associations and members have expanded access to water-sector cyber and physical security information. In 2024, NRWA and WaterISAC announced a formal collaboration so more rural and underserved systems can receive WaterISAC threat awareness products and education. Eligible systems can learn more and sign up via NRWA/WaterISAC channels.
- NRWA National Rural Water Cybersecurity Center (cyber advisories and rural-focused resources)
- WaterISAC (Water Information Sharing and Analysis Center: alerts, best practices, webcasts)
- WaterISAC + NRWA collaboration announcement
- WaterISAC Cybersecurity Fundamentals (no-cost fundamentals for water and wastewater utilities)
- WaterISAC membership / NRWA signup path (confirm current eligibility and benefits with WaterISAC/NRWA)
Federal no-cost tools
- CISA Water and Wastewater Cybersecurity toolkit
- CISA free cyber vulnerability scanning for water utilities
- EPA cybersecurity resources for the water sector
- CISA Water and Wastewater Sector overview
Practical starting points for small systems
- Inventory internet-facing systems (email, VPN, remote SCADA access, cloud billing)
- Unique passwords and multi-factor authentication where available
- Limit remote access; know who has vendor/contractor accounts
- Separate or carefully control OT/SCADA access from office IT when possible
- Keep backups offline or immutable; test restore
- Train staff on phishing and social engineering
- Know who to call: IT support, Circuit Rider, ADEM, county EMA, law enforcement, WaterISAC/CISA reporting paths
- Build cyber into your ERP and tabletop exercises (see AWIA page)
ARWA can help you navigate these resources and connect you with technical assistance. We do not replace your IT vendor or your legal/compliance obligations.
Physical security checklist
Use this as a practical facility checklist. Pair it with your AWIA Risk and Resilience Assessment and ERP so physical and cyber measures work together. (This content was previously the separate Basic Utility Readiness Guide.)
Site and operations
- Employee awareness, cameras, and employee identification
- Locks on gates, doors, buildings, electrical panels, and control panels
- Vehicles locked; keys never left in equipment
- Gates secured; security fencing where needed
- Adequate lighting and law enforcement awareness / routine checks
- Clear signage (Do Not Enter, Employees Only, Restricted Area, monitoring notices)
- Working security systems and alarms (prefer real monitoring over “dummy” cameras alone)
- Know surrounding terrain and report suspicious activity
- Auxiliary power; limited key control for sensitive areas
- Know when to stop production; keep emergency action plans current
- Review emergency plans with employees and local officials
Emergency contacts to keep current
- Local and county law enforcement
- Fire, hazmat, hospitals, rescue
- ADEM
- County Emergency Management Agency and county health department
- CDC (public health guidance as needed)
- Electricity supplier
- News media contacts for public notification
- Consecutive water systems / wholesale partners
Know when and how to issue boil-water or do-not-drink notices under your ERP and ADEM procedures.
Chemicals
- Secure storage for chlorine, acids, bases, fuels, and oxidizers
- Purchase/delivery schedules; inventory control; minimum practical inventories
- Secure chemicals on utility vehicles; keep SCBA inspected
Source and distribution
- Hydrant security coordination with fire and law enforcement
- Extra attention to hydrants and assets in limited public view
- Pump stations and structures: fence, lock, light
- SCADA/telemetry: limited access to sensitive information and remote pathways
- Tanks: locks, ladder control, access elimination where practical
- Meter vaults/pits locked; alarms; increased raw-water monitoring when warranted
Identity theft prevention (FTC Red Flags Rule)
The FTC Red Flags Rule is still in effect. It requires certain financial institutions and creditors that offer or maintain covered accounts to have a written Identity Theft Prevention Program designed to detect, prevent, and mitigate identity theft when accounts are opened or used. Residential utility accounts are a classic example of a covered account in the rule’s definitions (personal/family/household accounts with multiple payments).
Official guidance: FTC Red Flags Rule overview · Fighting Identity Theft with the Red Flags Rule (how-to)
Does this apply to my utility?
Coverage is based on activities, not on being “a water system” alone. The Red Flag Program Clarification Act of 2010 narrowed who counts as a “creditor” for Red Flags purposes. In broad terms, a creditor for this rule is one that regularly and in the ordinary course of business does one or more of the following:
- Obtains or uses consumer reports in connection with credit transactions
- Furnishes information to consumer reporting agencies in connection with credit transactions
- Advances funds to or on behalf of a person (with limited exceptions)
Many utilities that only bill after service, never pull credit reports, and never report to credit bureaus may fall outside the narrowed creditor definition. Systems that pull credit for deposits or service decisions, report to CRAs, or finance customer balances are more likely still covered if they maintain covered accounts. This is not legal advice. Confirm with your attorney or board counsel based on how you open accounts, bill, collect, and use credit information.
Even when the Rule may not strictly apply, a simple written program is still good practice: account fraud, fake new-service applications, and account takeover remain real risks and often overlap with cybersecurity (phishing, compromised email, social engineering).
What a program must do
If you maintain a Red Flags program, it should be written and include reasonable policies to:
- Identify relevant red flags for your covered accounts
- Detect those red flags in day-to-day operations
- Respond appropriately when red flags are detected
- Update the program periodically as risks and practices change
Typical administration steps (scale to your risk):
- Periodic determination of whether you offer or maintain covered accounts
- Risk assessment for new and existing accounts
- Procedures for staff who open, change, or collect on accounts
- Oversight of third-party billers or customer-service vendors
- Staff training
- Board or senior-management approval, with periodic (often annual) review
- Documentation of material incidents and responses
The Rule focuses on identity theft in connection with covered accounts (false accounts and account misuse). Broader customer-data protection (access control, encryption, breach response) is still important and ties to cyber hygiene, even when it is outside the Red Flags Rule itself.
ARWA Word template (July 2026 model)
ARWA offers a downloadable Identity Theft Prevention Program model (Microsoft Word) that systems can adapt. The July 2026 rewrite replaces the old 2008–2009 “compliance deadline” model. It includes 2010 Clarification Act scope notes, modern account channels (portal, phone, ACH), account-takeover / cyber-related red flags, an incident log, training and annual review sections, and an optional PII/cyber hygiene appendix.
Treat it as a starting template, not a substitute for current FTC guidance or legal review. Fill in every placeholder, check only the red flags that match how you open and manage accounts, and have counsel review before board adoption.
Download: Identity Theft Prevention Program model (Word, July 2026)
Same download URL as before (file replaced on files storage). Customize before board adoption. Questions: ARWA office (334) 396-5511 or arwa@alruralwater.com.
Alabama & federal preparedness resources
- readyalabama.gov – Alabama emergency preparedness
- Alabama Emergency Management Agency (AEMA) – state EMA; links to local county EMA information
- ready.gov – national preparedness guidance
- National Terrorism Advisory System (NTAS)
- ADEM – state environmental regulator
AEMA (Clanton): 5898 County Road 41, PO Drawer 2160, Clanton, AL 35046 · (205) 280-2200 · Confirm current contact details on the agency website.
Facility security signs for sale
With heightened security measures at utility facilities, you may want facility warning signs.
8" x 12" plastic
OR
24" x 36" aluminum

Last reviewed: July 12, 2026. Merged former Basic Utility Readiness Guide into this hub; added cybersecurity partnership links (NRWA / WaterISAC / CISA / EPA). Identity theft / Red Flags section rewritten for current FTC guidance and 2010 Clarification Act scope. Word template replaced with July 2026 model (post-2010 scope, digital red flags, incident log, annual review).
Being prepared and alert to circumstances which could be detrimental to the production and availability of safe drinking water is essential. Please take measures to ensure proper security and cyber controls are in place.
THREAT ADVISORIES
National Terrorism Advisory System (NTAS)
WaterISAC ·
NRWA Cybersecurity Center
Open for Registration
Operator Certification Classes
Click the link below to see available classes. CLICK IT! :)
Learn More
See all open CEH classes
in our new training section at
training.alruralwater.com
Schedule your own
On-site CEH Training
Earn CEHs
Water Loss Protection
The ARWA/NRWA ServLine Program protects your utility against losses from customers’ water leaks, and provides the opportunity for them to add service line repair replacement protection.
Learn more.


