Key Takeaways
- Trenton Water Works (TWW) reports no successful cyber intrusions into its water treatment or distribution systems and continues to provide safe drinking water to roughly 217,000 residents.
- The utility aligns its cybersecurity program with the NIST Cybersecurity Framework and CISA performance goals for the Water and Wastewater Systems Sector.
- TWW has fully segmented its operational technology (OT) environment—including SCADA and PLCs—from its corporate IT network to limit lateral movement by threat actors.
- Active participation in information‑sharing centers such as MS‑ISAC supplies timely threat intelligence and helps the utility continually strengthen defenses.
- Federal agencies (EPA, FBI, CISA, NSA) urge water utilities nationwide to harden OT systems, reduce internet exposure, and prepare rapid response capabilities.
- TWW emphasizes that cybersecurity is an ongoing process and commits to continual investment in technology, training, and partnerships to maintain a resilient water supply.
Overview of Trenton Water Works’ Current Cybersecurity Status
Trenton Water Works (TWW) announced that it has not suffered any successful cybersecurity breaches or unauthorized intrusions into its water treatment or distribution systems. The utility continues to deliver safe, reliable drinking water to approximately 217,000 residents across its five‑municipality service area. This statement comes amid a broader wave of cyber threats targeting critical water infrastructure nationwide, with several states reporting incidents and New Jersey officials noting two municipal systems were recently targeted. Although investigators have pointed to Iranian actors as a leading suspect, no definitive attribution has been made public. TWW’s reassurance is intended to calm public concerns while underscoring its ongoing vigilance.
Alignment with National Cybersecurity Standards
TWW operates in full compliance with the New Jersey Board of Public Utilities’ cybersecurity requirements for regulated utilities. In addition, the utility has deliberately aligned its cybersecurity program with the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which is the nationally recognized standard for managing cybersecurity risk. By adopting this framework, TWW ensures that its policies, procedures, and technical controls follow a proven, risk‑based approach that is regularly updated to reflect emerging threats and best practices.
Application of the NIST Framework’s Five Core Functions
The utility’s cybersecurity program is structured around the NIST Cybersecurity Framework’s five core functions: Identify, Protect, Detect, Respond, and Recover. These functions provide a comprehensive methodology for safeguarding both Information Technology (IT) and Operational Technology (OT) environments. Through systematic asset identification, TWW knows exactly what hardware, software, and data constitute its critical infrastructure. Protective measures—such as firewalls, intrusion prevention systems, and strict access controls—are deployed to shield these assets. Continuous monitoring and anomaly detection enable rapid identification of potential incidents, while predefined response and recovery plans ensure the utility can contain threats, restore normal operations, and learn from each event to improve future resilience.
Segmentation of OT and IT Networks
A cornerstone of TWW’s defensive strategy is the complete segmentation of its operational technology environment—including Supervisory Control and Data Acquisition (SCADA) systems and programmable logic controllers (PLCs)—from the corporate information technology network. This air‑gap‑like separation dramatically reduces the risk of unauthorized access or lateral movement between systems, making it far more difficult for an attacker who compromises an office computer to reach the physical processes that control water treatment and distribution. By keeping OT isolated, TWW limits the attack surface and ensures that even if IT defenses are breached, the core water‑production processes remain protected.
Participation in Information‑Sharing and Analysis Centers
To stay ahead of evolving threats, TWW actively participates in state and federal cybersecurity information‑sharing programs, most notably the Multi‑State Information Sharing and Analysis Center (MS‑ISAC). Through these channels, the utility receives timely threat intelligence, indicators of compromise, and advisories about emerging vulnerabilities specific to the water and wastewater sector. This real‑time data allows TWW to adjust its defenses proactively, patch vulnerabilities before they can be exploited, and coordinate with peer utilities and government agencies during broader cyber incidents.
Collaboration with Federal Agencies and Best‑Practice Guidance
Federal agencies—including the U.S. Environmental Protection Agency (EPA), the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA)—continue to encourage water utilities nationwide to bolster cybersecurity protections. Their guidance emphasizes reducing the exposure of critical operational systems to the internet, implementing robust multi‑factor authentication, conducting regular penetration testing, and developing comprehensive incident‑response plans. TWW’s adherence to these recommendations demonstrates its commitment to following federal best practices and maintaining a security posture that meets or exceeds national expectations for critical infrastructure protection.
Leadership Assurance and Ongoing Commitment
Michael Walker, Chief of Communications and Public Outreach for TWW, reiterated that the utility’s customers can remain confident in the safety of their drinking water and the security of the infrastructure that delivers it. He characterized cybersecurity as an ongoing process, not a one‑time project, and pledged continued investment in cutting‑edge technologies, staff training, and collaborative partnerships. This forward‑looking stance ensures that TWW will adapt to new threat vectors, incorporate lessons learned from industry exercises, and maintain a resilient water system capable of withstanding both cyber and physical challenges.
How Residents Can Obtain Further Information
Residents who have questions about Trenton Water Works’ operations, capital improvement projects, drinking water quality, or cybersecurity measures are encouraged to contact the utility’s Community Relations office at (609) 989‑3033. The agency provides a direct line for public inquiries, ensuring transparency and fostering trust between the utility and the communities it serves. By maintaining open communication channels, TWW reinforces its dedication to public safety and informed citizen engagement.

