Skip to main content

ARTICLE

Cyber Threats to Public Utilities

Cyberattacks on U.S. utility systems have sent a clear signal: public infrastructure is becoming a repeated, deliberate target.

Public utilities are a growing cyber target 

Cyberattacks on U.S. utility systems have sent a clear signal: public infrastructure is becoming a repeated, deliberate target. For insurance professionals, that has direct implications for how cyber risk in this sector should be evaluated and covered. 

The question is no longer whether utility organizations will face a cyber incident. It is whether they will be prepared and whether they will have the right coverage in place when it happens.

Three incidents that changed the conversation 

Recent attacks on utility infrastructure show how varied and serious these events can be.

In November 2023, hackers took remote control of equipment at a Pennsylvania water authority. Two months later, another group of hackers caused a Texas water tower to overflow, spilling tens of thousands of gallons — the first confirmed case of a cyberattack causing physical damage to a U.S. water system. Then in October 2024, American Water Works, the largest water utility in the country, serving 14 million people across 14 states, was breached by an unknown threat, forcing billing systems offline. 

Three incidents. Three different adversaries. Three different types of loss. That range is exactly why cyber coverage for public utilities requires careful attention.

The coverage gap brokers should know about 

Cyber insurance is an essential protection for businesses and organizations across all sectors. For public utilities, the stakes and the exposures are especially complex, requiring coverage that reflects the realities of critical infrastructure operations.

Key exposures can include public safety liability, physical damage to infrastructure, regulatory obligations, operational disruption, and the broad community impact a cyber event can cause. A standard cyber policy may not fully address these risks, and coverage gaps often do not become obvious until a claim is underway. 

What brokers should be looking for

When reviewing or placing cyber coverage for a public utility client, several areas deserve close attention: 

First-party costs. Incident response, forensic investigation, system restoration, and business interruption are core considerations. For utilities, business interruption may extend beyond lost revenue to include the cost of maintaining essential services manually while systems are restored.

Third-party liability. If a cyber incident disrupts service, affects public safety, or damages infrastructure, the utility may face claims from customers, municipalities, businesses, or other stakeholders that depend on uninterrupted operations. 

Regulatory defense and fines. Utility providers may be subject to cybersecurity requirements, reporting obligations, audits, and potential penalties following an incident. Not all policies address these exposures as standard.

Crisis management costs. When essential public services are affected, communications support is critical. Policyholders should understand whether those costs are affirmatively covered. 

Physical damage coverage. The Texas incident brought this issue into sharp focus. If a cyberattack causes real-world damage to utility infrastructure, will the policy respond? Many standard cyber forms exclude this exposure, so it needs to be addressed explicitly.

Why this is a specialist market 

Public utilities operate at the intersection of cyber risk, public safety, regulation, and critical infrastructure. Standard markets are not always well-positioned to underwrite that combination with confidence.

Specialist carriers understand how utility systems operate, the regulatory frameworks they face, and where material exposures may sit beyond what general market coverage typically contemplates.