As water companies become more connected and more reliant on data and technology, cyber security is becoming increasingly important. Water utilities operate critical national infrastructure, and with greater connectivity comes greater responsibility to protect systems, services and customers from evolving cyber threats. 

In this episode of the CGI ‘Smart, Secure, Sustainable’ Water Podcast Series, Water SME Luke Eeles is joined by CGI Cyber SME Kunle Anjorin to explore why cyber security is not just about protecting IT systems. It is about protecting operational resilience, public trust, environmental performance and the continuity of a critical national service. 

They discuss how cyber risk becomes an operational issue when it affects service delivery, network visibility, telemetry data, operational assets, field teams, suppliers and customer communication. The episode also explores what the water sector can learn from other critical national services, including the need to design for degradation, map dependencies and practise incident management as an operational capability.

Key takeaways from the episode

1.    Cyber security is now central to water sector resilience

Water is no longer only a physical utility. Behind the simple public experience of turning on a tap are connected systems, sensors, control environments, suppliers, cloud platforms and data. As these systems become more connected, cyber security becomes critical to service resilience, customer trust and regulatory confidence. 

2.    Cyber risk becomes operational when it affects service

The episode highlights that cyber risk is not limited to technology disruption. It becomes an operational issue when it affects the ability to deliver essential services. In water, that could include reduced visibility of the network, loss of confidence in telemetry data, disruption to operational assets, supplier access, field team coordination or customer communication.

3.    Water companies need to understand their assets and dependencies

Luke and Kunle discuss the importance of identifying the asset estate, understanding systems in the field and knowing what protocols are in place to mitigate potential cyber events. 

4.    Cyber resilience means keeping essential services running

The podcast explores why cyber security is not only about preventing attacks. As the sector becomes more dependent on data, automation and connected assets, cyber resilience becomes foundational to keeping essential services running when something goes wrong. 

5.    The sector should design for degradation, not just prevention

Drawing lessons from the telecoms sector, Kunle explains that resilience means asking whether a service can continue to run safely if systems are unavailable, degraded or untrusted. This shifts the focus from simply asking whether systems are secure to asking whether operations can continue under pressure. 

Learn more

CGI works with utilities organisations to strengthen resilience, modernise operations and protect the essential services customers and communities rely on. Our work across the water sector helps organisations balance digital transformation with secure, resilient operations. 

Visit our Utilities, Water and Energy Networks pages for more insights.

Get in touch with our Utilities team to discuss how we can help your organisation deliver for PR24 and beyond.

Transcript

Luke
Welcome back to the CGI Smart, Secure, Sustainable Water Podcast Series. I'm Luke Eeles, Lead SME at CGI, and in our last episode we explored the growing role of data, smart metering and digital technologies across the water sector.
One of the themes that came through strongly in that discussion was that as water companies become more connected and more reliant on data & technology, cyber security becomes increasingly important.

Water utilities operate critical national infrastructure, and with great connectivity comes great responsibility to protect systems, services and customers from evolving cyber threats.

So, today we're going to discuss some of the key cyber challenges facing the UK Water sector, including operational and cyber resilience. To help us unpack all of that, I'm joined by our Cyber SME, Kunle Anjorin.
Kunle, thanks for joining me. Before we get started, do you want to give everyone a quick introduction and tell us a little about your role at CGI?

Kunle 
Thank you Luke and it’s definitely good to join you on this podcast. I’m a director in CGI UK’s Cyber practice with a management focus on helping organisations think and take appropriate action about cyber resilience in the context of critical services and digital transformation.
My focus is on how organisations like water companies, that we’re talking about today, can modernise safely — using data, connected systems, automation and, indeed,  emerging technologies such as AI, while still protecting the essential services that their customers and our communities rely on every day.

Luke
That’s absolutely right, thanks Kunle - because the need for the water sector in general to balance modernisation with protecting their services is especially important. Cyber security is not just about protecting IT systems; it’s about protecting operational resilience, public trust, environmental performance and the continuity of a critical national service.
So, I guess the question is why does cyber matter in water now? When people turn on a tap, cyber security probably isn't the first thing they think about. But, from your perspective Kunle, why should cyber security matter to every water company in the UK right now?

Kunle
That’s a very good question, Luke. Cyber security matters in the UK’s water sector because water is now a digital utility as much as it’s a physical one. The public experience is simple, you turn on the tap and expect safe water, but behind that experience are several connected systems, sensors, connected control environments, suppliers, cloud platforms and most importantly, data.
Now, If those systems are disrupted, the consequences are not just technical. They can affect service resilience, they can affect customer trust, it can even be an environmental performance effect and it could have regulatory confidence.
Customers may not think about cyber when they turn on the tap, but water companies absolutely need to.

Luke
Yes, that’s really interesting. Having worked in the sector for a long period of time, I’ve recently seen reports around several cyber-attacks across the US, targeting water infrastructure, where programmable logic computers, better known as PLCs in the industry, have been targeted and in some instances even hacked. So gaining control of PLCs enables an aggressive players to potentially operate critical assets, so when you think of water, think of things like pumps controlling how much water moves around a system or network valves that direct that flow of water from one area to another or customer to customer. So gaining control of these kind of PLCs and equipment enables an aggressors to do so much harm to our water network.. 

Kunle
That’s an interesting point, Luke. What can our UK water sector learn from such an incident, like you’ve described?

Luke 
I think, in the UK, Kunle, for us it’s about adapting, right? So swiftly identify our asset estate, so what assets do we have out there in the field, determining what the systems are [that] we’re using and the protocols we have in place to mitigate such events.

Kunle
Absolutely. Cyber security protects the invisible systems behind a very visible public service. This is not just about preventing attacks. It is about keeping essential services running when something goes wrong. The more the sector depends on data, automation and connected assets, the more cyber resilience becomes foundational.  

So the real message is this:- Cyber security is not separate from the water sector’s mission – no not at all. It is one of the things that protects safe supply, public trust and the ability to modernise. Which means it is an operational issue that must be properly managed.

Luke 
And that operational issue aspect, Kunle, is really interesting isn’t it? So, I suppose what does cyber risk look like when it does become an operational issue, so we’re not just talking about technology?

Kunle 
Cyber risk becomes an operational issue when it moves from affecting systems to affecting service. This is the crucial shift for the water sector and this matters because drinking water supply and distribution is designated as an essential service under the UK’s Network and Information Systems (NIS) Regulations, and water is part of the UK’s Critical National Infrastructure. So cyber resilience in water is not just a technology concern; it is directly linked to the continuity of a service that our society depends on.

In practice, a cyber incident can affect visibility of the network, it can affect confidence in telemetry data, or the control of operational assets – these are systems that are controlled through operational technology (OT), like you were talking about, the PLCs a minute ago. In addition a cyber incident can affect coordination of field teams that the water companies deploy for work or even their supplier access to their critical sites, indeed it can also affect customer communication with the water companies as well as how incidents are responded to.

Luke
That’s really interesting. So these examples show that the impact could be wide ranging and it could become real-world very quickly. If operators cannot trust the data that’s in front of them, or if they lose visibility of critical assets, the issue is no longer just technical. It becomes an operational resilience issue.

Kunle
That’s correct. There are actually useful lessons I think that I see that can be learned from the telecoms sector another critical national service. So the telecoms has had to design for service continuity right from the start.

Luke  
That’s interesting and why is that Kunle, why have they had to do that?

Kunle
Well, they had to do this because connectivity is at the heart of our modern life with examples such as IOT internet-of-things, driverless cars and even just speaking to people all over the world, Ofcom…

Luke 
… you mean Ofcom, the regulatory body within telecoms sector?

Kunle
That’s correct Luke. Ofcom’s resilience guidance for the  telecoms sector focuses on robust architecture, operational models and keeping services available and working well, not just on preventing security incidents.
So, I think the water sector can actually apply this same mindset, and this is what I mean by that. 

Firstly, the water sector needs to design for degradation, this means if a system is unavailable or performance is reduced, can the service still continue to run safely? 

That’s the first question, the second one is about mapping dependencies. Water companies rely on power, rely on telecoms, cloud platforms, their suppliers, their field teams and they rely on operational sites, and those dependencies all need to be understood well before an incident happens. 

The third aspect that I think the water sector can learn from the telecoms sector is actually practising incident management as an operational capability, not just a cyber response. Telecoms reporting highlights incident management as critical to maintaining service continuity during cyber threats and operational disruptions.
So, all of these put together, is why the NIS regulation is such an important lens for the water company. It encourages water companies to think about the resilience of the network and information systems that support the essential services.

So the real question is, not only, ‘are our systems secure?’ The real question is ‘Can we continue to operate safely if systems are degraded, unavailable or untrusted?’ That is what makes cyber part of operational resilience. It is about protecting the ability to keep a critical national service running, even under pressure.

Luke
Thanks, Kunle. That’s really interesting. I think there’s a few really important messages to take away from today’s conversation.

So, for me, as the UK water sector becomes more connected, as we spoke about, cyber security and operational resilience; they increasingly go hand in hand. It’s not simply about protecting the technology alone, it’s about protecting the essential services that technology enables.

We’ve talked about the importance of understanding our assets and dependencies, being able to operate safely when systems are degraded or unavailable, and making sure our people and processes are prepared to respond when incidents occur.

And perhaps the key question for the sector isn’t just, ‘Are we secure?’ but, ‘Can we continue to deliver a safe and reliable service when something goes wrong?’

Kunle, thanks very much for joining me, it’s been a great discussion.

Kunle

Thank you, Luke, I’ve enjoyed this conversation with you today

Luke
And if you’d like to learn more about cyber security at CGI, visit CGI.com/UK/cyber-security