Water and wastewater utilities are “always-on” lifeline services. When critical water infrastructure is disrupted—by natural hazards, aging assets, human error, insider threat, vandalism, or targeted attack—the impacts cascade into public health risk, economic loss, and decreased community trust. At the same time, over 70% of the systems inspected by EPA since September 2023 are in violation of basic Safe Drinking Water Act (SDWA) Section 1433 requirements including missing specific sections of the Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP). A strategic security plan turns security from ad hoc fixes of these issues into a risk-based program that protects people, supports continuity of service, and prioritizes investments across a utility’s full asset portfolio.
What “Water Critical Infrastructure” Includes—and Why It’s Different
In the water sector, critical infrastructure is a connected portfolio of sites and systems that enable drinking water delivery, wastewater collection/treatment, and—depending on the organization—dams, reservoirs, laboratories, offices, and public recreation properties. The water sector can have a wide range of assets to protect and consider:
- Water assets: intakes, pump stations, treatment plants, storage, and distribution facilities
- Wastewater assets: lift stations, collection systems, and treatment facilities
- High-consequence sites: dams/reservoirs, major chemical systems, and control rooms
- Enabling functions: security technology, communications, and (where applicable) OT/SCADA interfaces
- Public-facing locations: parks and recreation properties that introduce unique safety/security risks
Water systems are also geographically dispersed, must operate continuously, and often have limited on-site staffing after hours. Strategic security planning helps organizations standardize baseline controls, focus on the highest-consequence assets, and coordinate security with operations, safety, engineering, emergency management, and IT/OT.
Why a Strategic Security Plan Matters
A strategic security plan provides a repeatable way to govern security, reduce risk, and demonstrate due diligence. In practice, it helps water organizations:
- Prioritize what matters most: align protection to mission-critical assets and consequences
- Standardize baseline controls: fencing, locks/access control, visitor/vendor management, monitoring, and incident reporting
- Plan investments: translate gaps into a multi-year roadmap tied to budgets and capital projects
- Improve readiness: integrate with emergency management, exercises, and corrective actions
- Strengthen compliance and audit readiness: map requirements to controls and evidence
8 Key Steps to Develop a Strategic Security Plan for Water Critical Infrastructure
The most effective plans start with mission and asset criticality, then use risk to drive priorities, standards, and a funded roadmap.
- Set scope and objectives.
- Inventory and tier assets.
- Map federal and state requirements.
- Conduct all-hazard assessments.
- Evaluate current security controls.
- Conduct and document a risk assessment.
- Define the future state.
- Create the roadmap and sustainment plan.
Key Regulations and Requirements That Shape Physical Security
Security planning must also operationalize compliance. A strategic plan should map applicable requirements to controls, owners, and evidence so readiness is repeatable and so security investments align with audit and reporting expectations including but not limited to:
- America’s Water Infrastructure Act (AWIA) / Safe Drinking Water Act §1433
- State drinking water regulations and sanitary survey expectations
- State wastewater regulations and permit conditions
- Dam and high-consequence asset security expectations
- Chemical safety and risk management requirements
- Supply-chain and procurement restrictions
- UAS/drone and critical facility protection laws
Why Benchmarking Peer Utilities Matters When Setting Security Measures
Regulations establish a floor, but peer benchmarking helps define a practical and defensible target state. Comparing your program to similar water/wastewater organizations (size, treatment complexity, distribution footprint, staffing model, and threat environment) helps leadership understand what “good” looks like, avoid over- or under-building controls, and justify investments with examples that resonate with boards, ratepayers, and regulators. Guidepost conducted a benchmarking study with support from the Water ISAC and leaders in the water sector to help TRA understand how other systems perceive risk, the current security measures implemented, and plans for security enhancements. This process helps to bring valuable insights and ensures that the organization is in alignment with its peers.
A Practical, ESRM-Aligned Security Strategic Plan Real-World Example
Guidepost recently helped Trinity River Authority (TRA) move to a more risk-based, executable security program. Using Enterprise Security Risk Management (ESRM), we worked with TRA to define what matters most, assess risk, and build a plan that fits TRA’s mission, operating realities, and funding constraints while reinforcing compliance and stakeholder confidence.
Guidepost brings a utility-focused approach that connects governance, site conditions, and day-to-day operations to a prioritized roadmap. We helped TRA document its security program, benchmark against peer organizations, collect key stakeholder insights on security expectations, identify relevant regulations for current and future planned operations, and convert findings into clear baseline standards.
TRA’s portfolio continues to evolve, for example, with the addition of Port Liberty, and the strategy is built to evolve with it. Guidepost structured the plan, so new assets can be onboarded quickly and consistently. The result is a plan that grows with TRA’s footprint while keeping expectations consistent across both legacy and newly added facilities.
Strategy Makes Security Sustainable
In the water sector, the goal is to prevent what you can, mitigate consequences, respond effectively when you must, and recover quickly while maintaining public trust. Because critical infrastructure facilities operate under high consequence, regulatory scrutiny, and limited margin for error, many benefit from engaging a qualified third-party security expert, like Guidepost, to bring objective assessment, sector benchmarks, and specialized experience to the table. A tailored strategic security plan provides the governance, prioritization, and roadmap to do that especially for organizations like TRA with diverse, distributed assets. When built using ESRM, the plan stays aligned to mission, owned by stakeholders, and defensible against both risk and regulatory expectations.