The first successful municipal water treatment plant in the United States was built in 1872 in Poughkeepsie, New York. It was not connected to the public Internet.
The largest municipal water treatment plant in the United States was the Jardine Water Treatment Plant built in the 1960s in Chicago, Illinois. It was not connected to the public Internet. It is still operational and remains the large municipal water treatment plant in the U. S.
There are probably around 150,000 municipal water treatment plants in the U. S. nationwide according to the Environmental Protection Agency.
Cyberattacks on municipal water treatment facilities have been much in the news lately. U. S. officials suspect Iran-backed hackers are responsible. For example, at CBS Nicole Sganga reports that such cyberattacks have been reported in at least 12 states:
Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, sources familiar with the matter told CBS News on Wednesday.
Those states include Michigan, Minnesota, Georgia, New Jersey and South Dakota. In Minnesota specifically, more than 30 community water systems were impacted, CBS News previously learned.
In Georgia, the Clayton County Water Authority, which serves 300,000 customers in the Atlanta area, said cyber activity last month caused a water pressure drop and forced the agency to issue a boil water advisory. Service was restored within hours, however.
Some utilities have lost critical remote-control capabilities, forcing operators to switch to manual mode. In several cases, the hackers gained remote access to pumps, valves and water pressure.
So far, according to officials, the cyberattacks have had no impact on drinking water, which has remained safe.
Connection to the public Internet is not an operational necessity. It is merely one possible engineering choice, not an inherent requirement of modern water treatment.
Direct connections between operational control systems and the public Internet should be prohibited by law. Where remote access is genuinely necessary, it should occur through dedicated, authenticated, cryptographically protected communications over private networks designed so that a compromise of the public Internet cannot directly compromise plant operations. Security should be achieved primarily through system architecture, not through perfect human behavior.






