(TNS) — The state is providing grant money to local governments to harden computer systems against hacking following a wave of cyberattacks targeting U.S. public water systems.
Treasurer Deb Goldberg, who oversees the Massachusetts Clean Water Trust, said the state is “working closely” with public water suppliers across the state “to assess risk and mitigate attacks” and is providing at least $2 million in grant funding to help them make upgrades.
Goldberg said the funding allows “smaller and most at-need communities to continue improving critical security infrastructure to safeguard public health for their residents.”
“As cyber threats become more frequent and sophisticated, we must ensure our local water suppliers have the resources they need to protect their systems,” she said in a statement.
Goldberg said outdated software, weak network security, vulnerable access controls and a lack of employee cybersecurity training are all threats to critical water infrastructure.
The program, created in 2024, provides grants for up to $50,000 to eligible Public Water Suppliers with a cybersecurity risk assessment and at-risk operational technology equipment. To be eligible to apply, a water system must meet criteria as a small system or a “disadvantaged” community.
To date, the program has provided $1.3 million in grants to 38 water systems, according to MassDEP. Qualifying water systems are also eligible to get grants to mitigate cyber risks for up to $50,000 from the State Revolving Fund.
The push to plug cybersecurity gaps in the state’s drinking water supplies comes after systems in at least a dozen states have been targeted by attacks, which White House officials have suggested may be linked to Iran-backed hackers.
In Georgia, a cyberattack is believed to be behind a disruption in Clayton County’s water system that caused a drop in water pressure and forced managers to issue a boil-water advisory.
More than 30 community water systems in Minnesota were affected by a cyber attack in late July, federal officials said.
The attacks have not affected drinking water, and utilities have quickly regained control of their systems.
But the incidents have exposed weaknesses in thousands of public water systems, many of which rely on poorly secured, internet-connected industrial computers, officials said.
The vulnerable components are programmable logic controllers, which operate industrial equipment such as water pressure or adding chemicals at water treatment plants. Those systems are often connected to the internet, allowing hackers to gain access to their functions, officials say.
“Massachusetts has some of the oldest infrastructure in the nation, and it was built long before cybersecurity was a consideration,” Bonnie Heiple, commissioner for the state Department of Environmental Protection, said in a statement.
“Water systems, particularly those in small, rural, and underserved communities, face heightened risks due to aging infrastructure and limited funding,” she said.
© 2026 the Gloucester Daily Times (Gloucester, Mass.). Distributed by Tribune Content Agency, LLC.
