Secure Remote Access for Municipal Water and Electric Utilities
Ben Burke, President
Ben Burke, President
Aug 19, 2026
Aug 19, 2026
min read
min read
min read
Article
Article

Key takeaway: America's water and electric utilities face nation-state-grade cyber threats with local-government-sized security budgets. Purpose-built secure remote access can close that gap — one monitored access pathway, deployable by existing utility staff in under a day, with compliance evidence built in and no added headcount.
Introducing the Dispel Community Power & Water Program
Few sectors carry as wide a gap between what's at stake and what's available to defend it as water and power. Most water and wastewater systems are small and rural, often held together by a handful of operators who carry all the institutional knowledge themselves. Rural electric cooperatives face the same reality — serving millions of Americans without the dedicated cybersecurity staff larger investor-owned utilities have. That's the gap the Dispel Community Power & Water Program is built to close.
It brings the same secure remote access model that large utilities rely on to the smaller water and electric utilities that protect our communities. Our offering is deployable by utility staff in under a day, with no security team required and no infrastructure overhaul. Approved applications receive special pricing designed to meet even the smallest security budgets.
The risk this program answers is not hypothetical. In late July 2026, attackers hit more than 30 municipal water systems in Minnesota over a single weekend, according to a joint FBI and EPA advisory. No sophisticated malware was involved — attackers accessed internet-exposed programmable logic controllers, changed their passwords and IP addresses, and locked operators out of their own equipment. CISA's advisory on the incident urged the water sector to remove internet-facing exposure as the top priority. The activity has since spread to utilities in at least 12 states.
Enterprise Security Wasn't Sized for Small Utilities
Most enterprise OT security tools share the same hidden assumption: a dedicated security team, a months-long deployment window, and a budget line that can absorb both. For a water treatment plant or a rural electric co-op, none of those three things exist. The team is stretched across water quality, power delivery, and whatever else needs doing that day — not network defense. The result is that the same systems under attack are often the least protected — not because these utilities don't care, but because no practical path forward has existed. Until now.
What Right-Sized Secure Remote Access Actually Requires
As small teams work to tighten their security, the lesson is the same: make the secure path the fastest path. We talk to teams who get that 2am call: a line goes down, the engineer who can fix it is 400 miles away, and he can't get in, so someone shares the VPN password. It's an easy thing to do, without realizing the VPN was already the weak point: always-on, one login shared across a whole vendor team, no record of who connected or what they touched. Sharing the password isn't a separate mistake, it's the same gap in the tool, just handed to one more person. When the secure path takes longer than the workaround, the workaround wins, and the unmonitored access it leaves behind is exactly what attackers are counting on.
Our goal is to close the security gap, not widen the one between what a small team can staff and what enterprise tools assume they have. Strip away those assumptions, and a small utility's quick start shrinks down to three things:
Ringfence the risk. A single monitored pathway should replace open OT access entirely — one controlled channel through which people get in and machine data gets out, with no changes to the OT network itself.
One standard access layer. Every vendor, contractor, and internal employee should connect through the same pathway, replacing the patchwork of VPNs most utilities have accumulated over time — often one per vendor, each with its own credentials and its own blind spot.
Extend a small team. Self-service vendor onboarding and built-in compliance reporting should give a two- or three-person team the same oversight a much larger security organization would have, without adding headcount.
EPA and WaterISAC point to the same short list every utility can act on this year: get control devices off direct internet exposure, replace shared credentials with individual accounts and MFA, and turn vendor access on only for the work at hand, then off. None of it requires new headcount — it requires an access model built around those defaults, instead of bolted onto a patchwork of legacy VPNs.
What This Looks Like in Practice
One large municipal water utility has run the Dispel Zero Trust Engine for seven years — securing vendor access, enforcing device policy, and keeping IT and OT segmented, with zero dropped sessions through a full firewall failover. Self-service onboarding and MFA reset eliminated roughly 90 percent of the team's recurring support tickets. Session Forensics keeps every login, action, and risk signal visible from authentication through disconnect, so audit-ready evidence doesn't have to be assembled from scratch every cycle.
Every remote session controlled, logged, and monitored. Every vendor connection scoped through just-in-time access windows, so pathways exist only for the duration of an approved session. Every access event tied to a named individual, not a shared credential. A defensible perimeter in place before the next attack arrives.
When the secure path doesn't require adding headcount, security and operations stop competing. The fastest path and the secure path become the same path, which is the only kind of security that holds up at a utility this size.
Apply for the Program
The Dispel Community Power & Water Program was built for utilities operating exactly this way — lean staff, real threats, and budgets that were never sized for enterprise security. Approved applications receive special pricing designed to meet even the smallest security budgets.
Apply today at go.dispel.com/dispel-community-power-water-program.
Frequently Asked Questions
What is secure remote access for water and electric utilities?
Secure remote access is a single monitored pathway that replaces open, internet-exposed connections to operational technology (OT), like PLCs and SCADA systems, with one controlled channel for vendors, contractors, and remote staff. It's how a utility grants and revokes access without exposing control systems to the internet.
Could what happened in Minnesota happen to us?
If your programmable logic controllers or other OT are directly reachable from the internet, yes — that's exactly how those attacks worked: no malware, just internet-exposed control systems reachable with weak or default credentials. Removing that internet-facing exposure is the first thing a secure remote access pathway does, and it's the top priority CISA and the EPA have urged the water sector to act on.
We don't have an IT or security team. Can we still do this?
Yes. Secure remote access built for small utilities requires no dedicated security team to deploy or operate. Self-service vendor onboarding and built-in compliance reporting give a two- or three-person team the same oversight a larger security organization would have, without adding headcount.
How long does setup take, and will it disrupt our operations?
A right-sized secure remote access deployment is installable by utility staff in under a day, with no changes to the OT network itself and no downtime to existing operations.
Do we have to replace our PLCs, SCADA, or existing VPNs?
No. Secure remote access replaces the patchwork of VPNs most utilities accumulate over time, often one per vendor, each with its own credentials and blind spot, with a single monitored access layer. Your PLCs, SCADA, and OT network stay exactly as they are.
What does it cost, and do we qualify?
The Dispel Community Power & Water Program was built for water and electric utilities with lean staff and budgets never sized for enterprise security tools. Approved applications receive special pricing designed to meet even the smallest security budgets. Apply to find out if you qualify.
Ready to Simplify OT Secure Remote Access?
See how Dispel helps industrial teams standardize connectivity and protect critical environments—without added complexity.

Key takeaway: America's water and electric utilities face nation-state-grade cyber threats with local-government-sized security budgets. Purpose-built secure remote access can close that gap — one monitored access pathway, deployable by existing utility staff in under a day, with compliance evidence built in and no added headcount.
Introducing the Dispel Community Power & Water Program
Few sectors carry as wide a gap between what's at stake and what's available to defend it as water and power. Most water and wastewater systems are small and rural, often held together by a handful of operators who carry all the institutional knowledge themselves. Rural electric cooperatives face the same reality — serving millions of Americans without the dedicated cybersecurity staff larger investor-owned utilities have. That's the gap the Dispel Community Power & Water Program is built to close.
It brings the same secure remote access model that large utilities rely on to the smaller water and electric utilities that protect our communities. Our offering is deployable by utility staff in under a day, with no security team required and no infrastructure overhaul. Approved applications receive special pricing designed to meet even the smallest security budgets.
The risk this program answers is not hypothetical. In late July 2026, attackers hit more than 30 municipal water systems in Minnesota over a single weekend, according to a joint FBI and EPA advisory. No sophisticated malware was involved — attackers accessed internet-exposed programmable logic controllers, changed their passwords and IP addresses, and locked operators out of their own equipment. CISA's advisory on the incident urged the water sector to remove internet-facing exposure as the top priority. The activity has since spread to utilities in at least 12 states.
Enterprise Security Wasn't Sized for Small Utilities
Most enterprise OT security tools share the same hidden assumption: a dedicated security team, a months-long deployment window, and a budget line that can absorb both. For a water treatment plant or a rural electric co-op, none of those three things exist. The team is stretched across water quality, power delivery, and whatever else needs doing that day — not network defense. The result is that the same systems under attack are often the least protected — not because these utilities don't care, but because no practical path forward has existed. Until now.
What Right-Sized Secure Remote Access Actually Requires
As small teams work to tighten their security, the lesson is the same: make the secure path the fastest path. We talk to teams who get that 2am call: a line goes down, the engineer who can fix it is 400 miles away, and he can't get in, so someone shares the VPN password. It's an easy thing to do, without realizing the VPN was already the weak point: always-on, one login shared across a whole vendor team, no record of who connected or what they touched. Sharing the password isn't a separate mistake, it's the same gap in the tool, just handed to one more person. When the secure path takes longer than the workaround, the workaround wins, and the unmonitored access it leaves behind is exactly what attackers are counting on.
Our goal is to close the security gap, not widen the one between what a small team can staff and what enterprise tools assume they have. Strip away those assumptions, and a small utility's quick start shrinks down to three things:
Ringfence the risk. A single monitored pathway should replace open OT access entirely — one controlled channel through which people get in and machine data gets out, with no changes to the OT network itself.
One standard access layer. Every vendor, contractor, and internal employee should connect through the same pathway, replacing the patchwork of VPNs most utilities have accumulated over time — often one per vendor, each with its own credentials and its own blind spot.
Extend a small team. Self-service vendor onboarding and built-in compliance reporting should give a two- or three-person team the same oversight a much larger security organization would have, without adding headcount.
EPA and WaterISAC point to the same short list every utility can act on this year: get control devices off direct internet exposure, replace shared credentials with individual accounts and MFA, and turn vendor access on only for the work at hand, then off. None of it requires new headcount — it requires an access model built around those defaults, instead of bolted onto a patchwork of legacy VPNs.
What This Looks Like in Practice
One large municipal water utility has run the Dispel Zero Trust Engine for seven years — securing vendor access, enforcing device policy, and keeping IT and OT segmented, with zero dropped sessions through a full firewall failover. Self-service onboarding and MFA reset eliminated roughly 90 percent of the team's recurring support tickets. Session Forensics keeps every login, action, and risk signal visible from authentication through disconnect, so audit-ready evidence doesn't have to be assembled from scratch every cycle.
Every remote session controlled, logged, and monitored. Every vendor connection scoped through just-in-time access windows, so pathways exist only for the duration of an approved session. Every access event tied to a named individual, not a shared credential. A defensible perimeter in place before the next attack arrives.
When the secure path doesn't require adding headcount, security and operations stop competing. The fastest path and the secure path become the same path, which is the only kind of security that holds up at a utility this size.
Apply for the Program
The Dispel Community Power & Water Program was built for utilities operating exactly this way — lean staff, real threats, and budgets that were never sized for enterprise security. Approved applications receive special pricing designed to meet even the smallest security budgets.
Apply today at go.dispel.com/dispel-community-power-water-program.
Frequently Asked Questions
What is secure remote access for water and electric utilities?
Secure remote access is a single monitored pathway that replaces open, internet-exposed connections to operational technology (OT), like PLCs and SCADA systems, with one controlled channel for vendors, contractors, and remote staff. It's how a utility grants and revokes access without exposing control systems to the internet.
Could what happened in Minnesota happen to us?
If your programmable logic controllers or other OT are directly reachable from the internet, yes — that's exactly how those attacks worked: no malware, just internet-exposed control systems reachable with weak or default credentials. Removing that internet-facing exposure is the first thing a secure remote access pathway does, and it's the top priority CISA and the EPA have urged the water sector to act on.
We don't have an IT or security team. Can we still do this?
Yes. Secure remote access built for small utilities requires no dedicated security team to deploy or operate. Self-service vendor onboarding and built-in compliance reporting give a two- or three-person team the same oversight a larger security organization would have, without adding headcount.
How long does setup take, and will it disrupt our operations?
A right-sized secure remote access deployment is installable by utility staff in under a day, with no changes to the OT network itself and no downtime to existing operations.
Do we have to replace our PLCs, SCADA, or existing VPNs?
No. Secure remote access replaces the patchwork of VPNs most utilities accumulate over time, often one per vendor, each with its own credentials and blind spot, with a single monitored access layer. Your PLCs, SCADA, and OT network stay exactly as they are.
What does it cost, and do we qualify?
The Dispel Community Power & Water Program was built for water and electric utilities with lean staff and budgets never sized for enterprise security tools. Approved applications receive special pricing designed to meet even the smallest security budgets. Apply to find out if you qualify.
Ready to Simplify OT Secure Remote Access?
See how Dispel helps industrial teams standardize connectivity and protect critical environments—without added complexity.
Recent Articles
Recent Articles
Products
Industries
Resources
Products
Industries
Resources
Products
Industries
Resources


