By Bronwyn Kelly-Seigh, Technical Manager, ENV
Cybersecurity has traditionally been treated as an IT risk. In drinking water, that distinction no longer holds.
“I spend a lot of time looking at threats most people never see. They are quiet, often hidden, yet capable of real-world consequences. Among the most critical are the cyber threats facing Canada’s water and wastewater systems. These systems are the backbone of modern life, yet they’re often out of sight and out of mind. When they function, no one notices. When they fail, everyone does.”
— Rajiv Gupta, Head of the Canadian Centre for Cyber Security
Cybersecurity has been a well-established risk in Ontario Drinking Water Management for some time. With ongoing threats and events increasingly making headlines, it is more important than ever to examine how cybersecurity integrates into our preventive, risk-based, multi-barrier approach to safe drinking water.
We have spent decades improving drinking-water systems by fundamentally reframing how we manage risk, moving away from relying primarily on end-product testing to assess treatment effectiveness and toward a much more holistic approach that considers hazards from source through distribution and implements multiple barriers along the way.
Yet our understanding of those hazards and barriers can still remain relatively siloed:
- Microbiological hazards: water quality / laboratory / public health
- Chemical hazards: water treatment / H&S / environmental
- Physical hazards: operations / H&S
- Digital hazards: IT
That separation makes sense from a technical-expertise perspective. We want the right specialists working within their areas of expertise.
The reality, however, looks much more like a Venn diagram.
The consequences of an IT failure depend significantly on the system affected. In Public Works, an IT failure can become an operational failure, which can very quickly become a water-quality failure.
When a Digital Threat Becomes a Microbiological One
Walkerton was a devastating lesson for Ontarians, but it fundamentally changed how we think about drinking-water risk.
The inquiry forced us to look beyond immediate failures and examine the systems and processes that allowed those failures to reach the public. That thinking helped move Ontario toward the preventive, risk-based approach we use today.
Cybersecurity is now asking us to apply that same systems-thinking to a new category of risk.
When the barriers and controls protecting drinking water are themselves vulnerable to digital attack, a digital threat becomes a water-quality risk that must be assessed accordingly.
A cyber incident does not have to introduce a new contaminant to create a water-quality problem.
Nature already provides the microbiological hazard.
A digital attack may only need to compromise one of the barriers controlling that ever-present risk to affect water quality, public trust and, ultimately, public health.
This also raises another important question: if a cyber incident compromises the systems, controls, monitoring or data we normally rely on, how do we independently establish that the water remains safe?
Cyber resilience cannot stop at preventing an attack, detecting one, and restoring digital systems. Drinking-water risk management also needs to consider how water quality will be assessed when confidence in normal monitoring or control systems has been disrupted.
Biosecurity Offers a Useful Model
Laboratory biosecurity requirements provide a useful model for thinking about cybersecurity.
In the laboratory, we do not approach biosecurity with the assumption that the biosafety or biosecurity officer has it handled, so analysts do not need to understand it.
Quite the opposite.
We conduct regular risk assessments and tailored training. Every new employee receives role-appropriate instruction in the elements of biosecurity they need to recognize and consider.
That includes IT security, of course, but it also includes physical security, emergency management, access control and accountability.
One of the most important principles is that human behaviour is part of the control system.
Every time someone questions something unusual, notices an anomaly or recognizes a concerning trend, they become part of that system of protection.
Everyone with access to sensitive biological materials receives training appropriate to their role and understands their accountability. Biosecurity is not the responsibility of one person or even one department.
Cybersecurity in Public Works needs to embrace a similar cultural shift.
What Does that Mean for Operator Competency?
Cybersecurity is already part of the DWQMS Risk Assessment. The next question is how we develop operator competency accordingly.
The answer is not simply more IT training.
It requires risk-based, interdisciplinary training supported by strong leadership.
Operators cannot compensate for inadequate infrastructure, weak access controls, unsupported legacy systems or poor incident-response planning. Management must provide the resources, policies, technical controls and ongoing training required to manage those risks.
What operators can do, when given the appropriate tools, training and resources, is develop the competency required to recognize abnormal conditions, escalate concerns, respond appropriately and operate manually where required.
We do not ask drinking-water operators to become microbiologists, toxicologists or chemists.
We do give them enough understanding of those hazards to recognize risk, protect themselves and protect the barriers under their control.
Cybersecurity should be treated the same way.
The goal is not to turn every operator into an IT professional.
It is to make cybersecurity part of the same safety culture that already asks every worker to understand how their actions protect themselves, the integrity of the treatment system and every person downstream.
Take it from a Biosafety/Biosecurity Officer: cybersecurity is no longer only about protecting our data.
In drinking water, it is also about protecting the integrity of the systems that protect public health.
Get Started
To learn more about our tailored biosafety training sessions and how aseptic technique starts before the lab to keep samplers safe, feel free to contact us at
Contact Us – SGS North America

