WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Cyber Resilience – Is your Utility Incident Response Ready?
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Cyber Resilience – Is your Utility Incident Response Ready?

Author: Chase Snow

Created: Thursday, March 21, 2024 - 17:48

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

As data breaches continue to impact organizations at an ever-increasing rate, the importance of effective cyber incident response is more important than ever. WaterISAC is sharing resources and tools to help utilities prepare for and implement this crucial aspect of organizational security.

Incident response involves having structured processes in place which are designed to identify and manage cybersecurity incidents. The SentinelOne Vigilance Respond team shares eight steps for effective incident response providing key recommendations and best practices to ensure organizations are well-prepared before such an incident occurs. Consider reviewing these eight steps and the guidance included for each to determine where your utility may need to bolster its incident response.

  1. Engage Legal Counsel & Incident Response
  2. Keep Affected Endpoints Online
  3. Disconnect from the Network
  4. Identify & Preserve Evidence
  5. Collect IOCs & Samples
  6. Prepare for Restoration
  7. Develop a Timeline
  8. Identify Endpoints

In addition to the resources shared above, WaterISAC reminds members of the recent federal resources, including Incident Response Guide for the water and wastewater sector and Top Cyber Actions for Securing Water Systems. The latter includes Develop and Exercise Cybersecurity Incident Response and Recovery Plans as the fifth top action and highlights resources for first developing an effective incident response plan, and then exercising it. No matter where your utility sits with its incident response procedures, be sure to examine these resources and implement them as is best for your utility. For more on incident response best practices and to review the eight steps above, visit SentinelOne.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar