.

cyber resilence - image

Date:
23.06.2026
Author:
Inventia Team

BLOG

Cyber Resilience is a film, and you play the leading role in it

Cybersecurity, particularly in the context of formal compliance with the requirements of the NIS2 Directive and the amendment to the Act on the National Cybersecurity System (UKSC2), has become a buzzword in recent months. Personally, I prefer to use the term ‘cyber resilience’. ‘Security’ suggests a binary state – we are either secure or we are not – which, in the age of today’s threats, is an illusion. ‘Cyber resilience’, on the other hand, is an organisation’s ability to avoid, repel or mitigate the effects of an attack, but above all, it is an organisation’s ability to maintain critical functions and quickly resume operations following an incident. For senior management, this marks a shift from a defensive stance to strategic business continuity management, with cyber resilience embedded in the organisation’s DNA.

Although cyber resilience remains a largely invisible aspect of everyday life for many, in the public utilities sector its effectiveness determines the security of the continuity of utility supplies to households and businesses, and consequently, the stable functioning of the entire national economy. It is worth looking at the energy sector, which underwent a process of profound cybersecurity transformation several years ago. This was driven by sector consolidation and the realisation that paralysing the transmission grid would immediately paralyse the country, and perhaps even the international grid. Today, the water and sanitation sector finds itself in the same position. Rather than reinventing the wheel, we can draw on the experience of the energy sector, knowing that the NIS2 regulations set out almost identical objectives for us. What is already standard operating practice in the energy sector is now becoming our new reality in the water and wastewater sector.

Cyber resilience extends far beyond the boundaries of IT

In the past, threats associated with digitalisation were mainly linked to viruses that destroyed data on the hard drives of office computers. Even just a few years ago, security focused almost exclusively on IT solutions, covering much more but still failing to reach ‘the front line’. Today, in the age of ubiquitous digitalisation and growing awareness, cybersecurity extends far beyond the confines of the traditional IT department. In water and sewerage systems, it directly affects the operational layer (the term ‘OT’ is becoming fashionable these days, but personally I’m not keen on it), i.e. SCADA systems, PLCs and distributed telemetry devices, whilst also taking physical security into account. After all, will even the best IT systems solve the problem of physical and undetected access to water treatment works, drinking water pumping stations, or the illegal tapping of water from hydrants? Is a ransomware attack more damaging than the deliberate contamination of a drinking water intake? Without a doubt, security must be implemented in an appropriate and balanced manner.

Beyond the technical aspects discussed, cybersecurity has been firmly embedded within the legal and regulatory framework. Now that we have finally seen the national implementation of the NIS2 Directive, we have no choice but to genuinely raise the level of resilience in our sector. The next milestone will be the full entry into force of the Cyber Resilience Act (CRA), which will primarily affect manufacturers of products containing digital components, but will also have far-reaching implications for product users, as they will need to pay particular attention, for example, to whether the supplier and their products meet the requirements of this regulation, and what the expected product lifecycle is.

cyber resilence - INV

The Information Security Management System: the epicentre of cyber resilience

We already know that it is a mistake to equate cybersecurity solely with the purchase of IT solutions. True resilience begins much earlier, at the design stage of the Information Security Management System (ISMS). This is a process underpinned by a thorough risk analysis. This analysis should identify what constitutes a real threat to a given organisation and what measures (proportionate to the budget and scale of the threats) should be taken.

If we look at standards such as ISO/IEC 27001 and ISO 22301, we will see that they do not impose specific technological solutions. Instead, they focus on risk analysis, procedures and processes that clearly define roles and courses of action. This is particularly valuable in crisis situations, when there is no time for improvisation.

Under the NIS2 Directive, an organisation covered by it has just 24 hours to make an initial report of an incident from the moment it becomes aware of it, and a further 48 hours to complete the report – a total of 72 hours, which are counted even at weekends and on public holidays. Knowing who is to do what, when, and who to ‘call’ within the first hour of detecting an anomaly is more important than even the most expensive equipment. This is where the role of automation and having a reliable partner or a highly effective in-house SOC (Security Operations Centre) becomes crucial. The aim is to ensure that a lack of familiarity with procedures and the struggle with the inevitable bureaucracy of reporting do not hinder the actual engineering measures needed to secure the infrastructure at a critical moment, and do not expose the company and its management to avoidable sanctions.

The supply chain as one of the pillars of cyber resilience

Now that we know how to manage internal processes, we must also look outwards – that is, take care of our supply chain. In 2026, it is no longer possible to discuss product security without analysing its origin. The supply chain has become one of the key areas of risk assessment. From the perspective of a water and sewerage company, the choice of technology supplier is a decision that determines compliance with NIS2 requirements, as well as the maintenance of compliance and security throughout the project’s lifecycle. Nor should we overlook the extremely important and responsible role played by qualified integrators, as a system comprising many components is only as secure as its weakest link. Only by configuring all component products into a single, coherent system can the cyber resilience of the entire solution be ensured.

The aforementioned CRA Regulation ushers in a new era of responsibility for manufacturers and distributors of ‘products with digital components’. This term encompasses both software such as SCADA or billing systems, as well as devices such as PLCs or telemetry modules, which will no longer be treated as ‘black boxes’. They will require support for security patches throughout the product’s lifecycle, which manufacturers will have to clearly declare prior to purchase. This will effectively eliminate in-house solutions, and preparations for this must be made well in advance.

When selecting a technology partner, a water utility must take into account not only the price of the solution, but also the compliance of the partner and its products with regulations, the supplier’s ‘sustainability policy’ and the ability to maintain supply chain continuity even during these difficult times, as these are two sides of the same coin. The devastating floods of 2024 clearly demonstrated that (not only) the water and sewerage sector needs partners with actual stock levels and local support. Manufacturers and distributors who avoid stocking products and spare parts in the name of cost optimisation become a bottleneck when the going gets tough – a problem that no legal procedure can resolve, and for which the ultimate responsibility lies with the entity operating under NIS2. I believe that cooperation between facilities is an idea worth considering, for example with regard to the use of shared technological solutions, which, in addition to higher availability, should lead to better commercial terms. UKSC2 itself explicitly mentions the possibility of cooperation between local government units at municipal and district level.

The supply chain as one of the pillars of cyber resilience

Technology as an ally and a vector of attack

The ongoing digitalisation of the water and sewerage sector is a double-edged sword. It allows for the optimisation of losses, labour costs and energy consumption, as well as a rapid response to breakdowns, but at the same time opens up new ‘backdoors’ to the infrastructure. Many incidents do not stem from sophisticated hacking activities, but from a failure to observe basic digital hygiene and a lack of so-called ‘low fences’. Today, bots utilising AI technologies scan the network for weak points and exploit every possible vulnerability, so hoping that no one will take notice of a smaller water supply plant is a pipe dream. CERT Polska publishes an annual activity report[1], in which one can find statistics on the incidents that have been detected. Year on year, these figures are rising at an alarming rate, a trend exacerbated by our geographical location and the balance of geopolitical forces. And how many incidents went undetected and were not included in the report? I wouldn’t even attempt to estimate that number.
The question is not ‘if’, but ‘when’ we will become the target of malicious interest. Therefore, I propose that particular emphasis be placed on the following areas in risk analysis, as experience shows there is plenty to address:

  1. What we already have: we need to take stock of our assets, check that they are up to date, and implement the security mechanisms already available, bearing in mind that products do not guarantee security on their own; it is the correct configuration of the entire system that does.
  2. Verify, don’t trust: Zero Trust marks the end of an era in which we trusted every device by default and without reservation, simply because it was connected by cable to a ‘trusted internal network’, or because we trusted someone who had been working with us for 20 years. Identity and access must be verified and managed based on the current security context.
  3. Remote access: Using services such as VNC/RDP or common ‘port forwarding’ without secure VPN tunnels is an open invitation to intruders, especially on the so-called ‘dirty internet’. A proxy server with session authentication should be standard practice.Access for the supplier should only be granted in justified cases, not 24/7 ‘just in case’. There must be no unsecured option for remote connection from the ‘administrator’s’ home, as they may occasionally need to connect at the weekend.
  4. Password and access management: Factory-set passwords, passwords that are the same across multiple solutions or that have remained unchanged for years on devices and in industrial systems, and the lack of SIM card PIN locks, remain among the most common causes of breaches.
  5. Network segmentation: the division between the office (IT) and operational (OT) networks must be rigorous.Network segmentation should prevent unauthorised persons from having direct access to process controllers. Even if one segment is attacked, the other remains relatively secure.
  6. The principle of least privilege: this is a difficult issue in hierarchical structures, but an essential one. Should senior management have administrator rights to SCADA systems ‘just in case’ or ‘for monitoring purposes’? From a risk analysis perspective, this is a massive vulnerability that occurs all too frequently. The account of a CEO or Director is an attractive target for a hacker, because as soon as it is compromised, the attacker gains access to the entire ecosystem. In a cyber-resilient organisation, access should be dictated solely by a genuine operational need, rather than by one’s position in the organisational chart.
  7. Plan “B”: do we know how to respond when computers and systems stop working? Do we practise such scenarios in real life to refine procedures and reinforce best-practice templates? We devote a great deal of attention to digital solutions and their security, but we must not forget that these solutions control the operation of physical equipment. A resilient organisation must be prepared for a crisis-driven return to the ‘analogue’ world.
  8. The human factor: we have reached the weakest link in our cyber shield. People must be trained on a regular basis. Not everyone is a natural ‘security expert’, so we must educate, educate and educate again. And we must put theoretical knowledge into practice, for example by conducting a simulated phishing attack targeting ransomware. Organisational culture is also significant in this regard. People make mistakes and must have a safe space to report them. If someone makes a mistake and is punished after reporting it, they won’t do it again next time. Neither will others. Mistakes made should be a source of learning and an area for organisational improvement, not a basis for disciplinary action. Without this, our incident logs will remain empty, whilst the infrastructure may have been compromised long ago.

The economics of security and why ‘false savings’ should be avoided

All these technical and procedural aspects have a flip side – the financial one. As managers, we must stop viewing security through the prism of CAPEX (purchase) and start viewing it through the lens of TCO (Total Cost of Ownership), i.e. CAPEX + OPEX. The purchase of a device is usually only the beginning of the costs. The true costs only become apparent once the costs not visible in the initial offer are taken into account: for example, when such a solution needs to be adapted to new security requirements; when technical support is lacking; when remote diagnostics are difficult and a team has to be sent out on site; or when there are costs associated with SOC support or regular firmware updates, which are now a legal requirement.

All these aspects must be taken into account, as the lifecycle of solutions in the industrial sector is not limited to the short term.

How can you effectively protect yourself against a cyberattack?

Audits and penetration tests are mere snapshots of reality. Ensuring cybersecurity is more like a feature film. It is not possible to ‘secure’ a system once and for all, but one must continually ‘secure’ it, as threats are constantly evolving. Each of us plays a role in this film, so we should know the script.

Even the best systems and solutions, both technically and procedurally, may not protect us from an attack by a determined attacker. That is why our actions are designed to build defences that fulfil three main objectives:

  • effective deterrence – eliminating standard loopholes and vulnerabilities makes an attack unprofitable for a hacker in terms of time and money, or even prevents a bot from selecting us for further ‘processing’,
  • early detection – SIEM-class systems and SOC services are designed to alert us to anomalies at the reconnaissance stage, before an intruder takes control of the process,
  • mitigation of consequences – should the defences be breached, which cannot be ruled out, network segmentation and robust business continuity plans are intended to ensure the water supply is maintained, even with a partially paralysed infrastructure.

Summary: Cyber resilience as part of the mission

Cyber resilience is no longer a technical add-on to core operational activities; it has become one of its main pillars. NIS2, UKSC2 and the CRA do not force us to implement technologies straight out of science-fiction films. They compel us to address cybersecurity in a conscious, risk-appropriate and continuous manner. Investing in cyber resilience in the water and sewerage sector is now not only a legal requirement, but above all an expression of responsibility. Building secure infrastructure is a long-term process, but one that is essential to ensure that, in a world full of digital threats, water flows uninterrupted from our taps.