Small Water System Cybersecurity:Who Owns What?
Small teams often share cybersecurity across operators, IT providers, SCADA integrators, and vendors. This guide helps make each responsibility and handoff clear.
Separate the jobs.
The title on the contract matters less than the work each party actually owns.
Utility team
Sets operational decisions, approvals, emergency procedures, and the process context outside providers need.
SCADA integrator
May install, configure, maintain, and troubleshoot control systems. Cybersecurity scope depends on the engagement.
IT provider or MSP
May manage business IT, accounts, endpoints, firewalls, backups, or remote access. OT scope varies.
Equipment vendors
Support the products and services in their scope. Access, monitoring, and security responsibilities vary.
If two parties both think the other owns a job, nobody owns it.
Five jobs need an owner.
The names may change. The jobs don't.
Know what's connected
Keep a current view of important IT, OT, remote sites, and the connections between them.
Know who can get in
Know each remote access path, who uses it, who approves it, and how access gets removed.
Know what you can see
Know which logs, alerts, network data, and system records exist when something needs investigation.
Assign the investigation
Someone needs to determine what's suspicious, what's affected, and what the evidence supports.
Define response
Know who gets called, who can act, what gets preserved, and how recovery is coordinated.
Ask six questions.
You may already have this handled. Get the handoffs clear.
What systems are you responsible for?
What systems and activity can you actually see?
Who manages remote access?
Who investigates a security alert?
What evidence is retained?
Which actions require operator approval?
Where CrunchAtlas fits.
CrunchAtlas works alongside the utility, integrator, IT provider, and existing tools. Consequential actions stay under operator control.
Network Detection and Response
Passive network evidence turns suspicious activity into an investigated case without probing operational systems.
Explore NDR → 02Alert Investigation
Work alerts to a verdict with the affected systems, evidence, and recommended next step attached.
Explore Alert Investigation → 03Host and Network Forensics
Use available host and network evidence to reconstruct what happened and establish scope.
Explore Forensics → 04Incident Reporting
Carry the investigated case into a reviewable report with findings, evidence, scope, and response information.
Explore Incident Reporting →One platform connects the investigation workflow. Continue into the product, water industry page, or response guidance.
Small water system questions, answered.
Does a small water system need its own cybersecurity team?
Not necessarily. The work can be shared across operators, IT, a SCADA integrator, an MSP, a cybersecurity provider, and other specialists. What matters is that each job has a clear owner.
Is our SCADA integrator responsible for cybersecurity?
It depends on the engagement. An integrator may know the control environment deeply while focusing on engineering, integration, maintenance, and operational support. Confirm which cybersecurity responsibilities are actually included.
Does our MSP already handle this?
It may handle part or all of it. Confirm what the MSP can see in OT, which systems it manages, whether remote access is in scope, and who investigates suspicious activity.
Does CrunchAtlas make a water system compliant?
No. CrunchAtlas can support monitoring, investigation, evidence collection, and reporting. Compliance decisions remain with the utility and its appropriate regulatory, legal, and compliance resources.
Sources used on this page
The ownership and preparedness guidance is grounded in EPA water cybersecurity resources. CrunchAtlas product descriptions are separate from EPA guidance.
This page is educational. It doesn't assign legal, regulatory, engineering, or contractual responsibility for a specific utility. Confirm responsibilities against the utility's contracts, architecture, policies, and applicable requirements.
Know who owns the investigation before you need one.
Bring us the environment you already have. We'll show you where CrunchAtlas fits alongside your team and current providers.
Deployment, evidence availability, provider scope, and the utility's operating model affect what CrunchAtlas can see and investigate. The utility and its authorized partners remain responsible for operational, engineering, regulatory, and compliance decisions.