28,273
Internet-facing assets discovered
Across 5 scanned organisations
1,472
Supplier connections mapped
Script · cert · ASN · DNS · header
65
Fix Now priorities
Requiring immediate action
7/5
Universal suppliers across all orgs
Microsoft · Cloudflare · Google · +4 more
Why utilities carry unique and systemic cyber exposure
Water utilities, wastewater operators, and energy-from-waste providers occupy a privileged and pressured position in critical national infrastructure. Their operational technology environments — SCADA systems, remote telemetry units, treatment plant control networks — attract the most attention in cybersecurity discourse. But their digital estates are equally consequential: customer portals, billing platforms, operational dashboards, regulatory reporting systems, and supplier integrations all sit on the public internet, reachable to any attacker with a browser and a reconnaissance tool.
The utilities sector also presents a distinctive supply chain profile. GIS mapping platforms such as Esri ArcGIS are embedded across multiple operators for infrastructure asset management. National telecoms provide the backbone for both internet connectivity and operational communications. And the full stack of enterprise technology — Microsoft 365, Azure, Cloudflare CDN, Google Analytics — is present at every organisation, creating an unusually dense concentration of shared dependencies across the sector.
This report draws on simultaneous scans of five utilities organisations across Belgium, the Netherlands, and the United Kingdom — spanning drinking water production, water utility operations, wastewater management, and energy recovery from waste. The findings reveal a sector-wide failure of security header controls, a striking variation in software hygiene between operators, and a certificate estate at one organisation where 46 individual certificates carry an F rating — exposing operational and customer-facing services alike to transport-layer attack.
All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do utilities operators compare?
ThingsRecon scanned five utilities organisations simultaneously. Four carry an overall score of C; one achieves a B — the standout result in this benchmark and a notable contrast to sector peers. The defining pattern across all five organisations is a universal failure of security header controls: every operator in this benchmark scores D for header risk, making this the first sector in this report series where a single risk category fails across the entire field. Org E, the largest asset estate after Org D, carries 29 Fix Now priorities, D-rated software risk, and a Cert C rating driven by 46 F-rated certificates.
Organisation
Assets
Suppliers
Fix Now
Key Indicators
Score
Org ADrinking water · NL
4,630
83
7
Header D · App B · Software C · SSL C
C
Org BWater utility · BE
3,212
71
10
Header D · App C · Software C · SSL C
C
Org CWater utility · UK
2,603
71
3
Header D · App B · Software A · SSL B
B
Org DWastewater · BE
12,435
141
16
Header D · App B · Software C · 8 F-apps
C
Org EWaste & energy recovery · NL
5,393
151
29
Header D · Software D
Cert C (46 F-rated)
C
Sector Total5 organisations
28,273
—
65
Header D: 5/5 orgs · Universal suppliers: 7
—
⚑ Sector-wide pattern — security header failure
For the first time in this sector intelligence series, a single risk category fails at every organisation in the benchmark. All five utilities operators score D for header risk — meaning that critical browser-side protections including Content Security Policy, HTTP Strict Transport Security, X-Frame-Options, and Referrer-Policy are absent or misconfigured across the full sector. This is not an isolated oversight at one operator; it is a structural gap in how the utilities sector approaches web security hygiene, from drinking water to wastewater to energy recovery.
Sector-wide Risk Patterns
Where the sector is consistently exposed
Security headers are the sector's universal failure — but they are not the only area of concern. Software risk, certificate hygiene, and application ratings vary significantly between operators, revealing both a sector baseline and individual outliers in both directions. Org C's B score and Software A rating demonstrate that a small-to-mid-sized utility can operate a well-controlled external estate. Org E's Software D and 46 F-rated certificates demonstrate what under-investment in web hygiene produces at scale.
Header Security
Critical — 5/5
Every utilities organisation in this benchmark scores D for header risk. CSP, HSTS, X-Frame-Options, and Referrer-Policy are missing or mis-set across all five operators. Public-facing portals — from customer billing systems to regulatory reporting dashboards — are left exposed to clickjacking, XSS amplification, and information leakage, with no browser-side policy enforcement in place.
Software Risk
High — 4/5
Software risk is C at three organisations and D at Org E. Only Org C achieves Software A — the sole operator with no detected software vulnerability debt. At Org E, D-rated software compounds its certificate and header failures, creating multiple independent attack vectors on a single estate.
Certificate Risk
High — Org E
Org E carries a Cert C rating driven by 46 F-rated individual certificates on its external estate. Misconfigured, expired, or deprecated certificates on externally reachable services undermine transport-layer security. For a waste-to-energy operator with digital interfaces to grid infrastructure, unprotected certificate hygiene is a concrete attack enabler.
Application Risk
Medium — Orgs B & E
Org D carries 8 F-rated applications within its estate of 12,435 assets — the largest estate scanned. Org E's application estate scores C. Org A and Org C achieve App B. The same infrastructure category produces both the cleanest application profile and some of the most concentrated risk.
SSL Services
Medium — Orgs A & B
SSL service risk is C at both Org A (drinking water, NL) and Org B (water utility, BE). Deprecated TLS configurations on externally reachable services create interception risk on connections from regulators, partners, and operational management platforms. The remaining three operators achieve SSL B or better.
Sector verdict: Security header failure is the utilities sector's most pervasive and consistent external exposure — present at 5/5 operators without exception. It functions as the sector's baseline risk, on top of which software vulnerabilities and certificate gaps at individual operators layer additional attack surface. The single bright spot is Org C, whose B score and Software A rating show what disciplined web hygiene looks like in this sector — and what is achievable for its peers.
Three Pillars of Risk
The structural vulnerabilities defining this sector
01
Universal Header Misconfiguration
Header security failing at all five operators is not coincidence — it reflects a sector-wide gap in web security policy governance. The sector's reliance on shared technology platforms (Cloudflare, Microsoft) means header remediation at scale is achievable — but requires deliberate action, not default settings.
02
Certificate & Software Debt at Scale
Org E's 46 F-rated certificates and D-rated software risk represent the outer edge of accumulated web hygiene debt in this sector. At a waste-to-energy operator touching grid infrastructure and municipal contracts, the external web estate is the interface through which operational and commercial relationships are managed.
03
Seven-Supplier Concentration Risk
Seven technology suppliers — Microsoft, Cloudflare, Google, Amazon, Meta, GitHub, and jQuery — are present in every utilities organisation scanned. A security event affecting any of these platforms propagates instantly across the full benchmark. Meta's presence across all five operators is particularly notable for a sector handling sensitive infrastructure data.
NIS2 Directive — Annex I Essential Entities & UK NIS Regulations 2018
Water supply and wastewater operators qualify as essential entities under NIS2 Annex I — the stricter of the two NIS2 classifications, carrying higher supervisory obligations and more stringent enforcement powers than the Annex II "important entity" category. Org A (drinking water, NL), Org B (water utility, BE), and Org D (wastewater, BE) are directly subject to essential entity obligations. In the UK, Org C falls under the UK NIS Regulations 2018. Security header failures, software vulnerability debt, and unaddressed certificate risk each represent concrete gaps against NIS2 Annex I requirements for risk management, supply chain security, and demonstrable control of network and information systems.
Supply Chain Intelligence
The technology layer connecting utilities operators
1,472 supplier connections were mapped across the five organisations. Seven suppliers — Microsoft, Cloudflare, Google, Amazon, Meta Platforms, GitHub, and jQuery — appear in every organisation's external estate, forming the densest universal supplier footprint observed across any sector in this series. Microsoft leads in digital proximity, reaching 72% at both Org A and Org D — meaning these operators' external identities are substantially defined by Microsoft infrastructure.
Total supplier connections1,472
Across 5 utilities organisations · script, cert, ASN, DNS, header
Unique connected suppliers~250+
Sector-wide vendor footprint
Universal suppliers (5/5 orgs)7
Microsoft · Cloudflare · Google · Amazon · Meta · GitHub · jQuery
Highest single-org connections432
Org E (waste & energy recovery) · 151 unique suppliers
The top suppliers by reach and digital proximity across the utilities benchmark:
Supplier
In sector
Max proximity
Category
Significance
Microsoft Corporationmicrosoft.com
5/5
72% at A & D
Cloud · Infra
Azure hosting, M365 mail, Active Directory, and embedded scripts — the deepest digital proximity of any supplier in this benchmark
Cloudflare, Inc.cloudflare.com
5/5
~65% at E
CDN · Security
CDN, DNS, and DDoS protection present at every operator; high proximity at Org E despite its D-rated header configuration
Google LLCgoogle.com
5/5
~62% at E
Analytics · Cloud
Google Analytics, Tag Manager, reCAPTCHA, and Workspace services embedded across all five web estates
Amazon Technologies (AWS)amazon.com
5/5
~52% at D
Cloud · CDN
AWS infrastructure and CloudFront CDN present at all five operators; highest at Org D, the sector's largest estate
Esri / ArcGISesri.com
3/5
~38% at D
GIS · Mapping
GIS infrastructure and asset mapping platform detected at 3/5 utilities — a sector-specific supplier not seen elsewhere at this penetration
Supplier Spotlight — Universal Presence
Microsoft Corporation
microsoft.com | Present in 5/5 organisations | Avg proximity ~61% | Max 72%
Sector presence
All 5/5 organisations — the highest universality score of any supplier in this benchmark, classified High across all five
Digital proximity range
~50% (Org C) → 72% (Org A & Org D) — two separate operators reach the peak proximity value
Connection vectors
Azure cloud hosting, M365 mail and identity, SharePoint, Active Directory federation, embedded scripts, CDN delivery
Notable intersection
At Org D (wastewater), Microsoft 72% proximity coincides with Header D and 8 F-rated applications — a high-dependency, high-exposure combination
Microsoft's 72% digital proximity at Org A and Org D means these operators' external estates are more than half-defined by Microsoft infrastructure. This level of integration is both an operational strength and a concentration risk. Any Microsoft platform event — a misconfiguration, a credential compromise, or an authentication infrastructure incident — would propagate directly into the external attack surface of two essential entities in this benchmark.
Primary attack vector: Microsoft 365 credential phishing → Azure tenant access → Entra ID compromise → lateral movement into operational portals and partner integrations
Illustrative Attack Path
From public reconnaissance to operational infrastructure access
1
Reconnaissance
External estate enumeration — 28,273 assets, 1,472 supplier connections, GIS platform integrations and operational portals publicly visible
Entry
2
Header Exploitation — All 5 Orgs
Absent CSP and X-Frame-Options across all operators enables clickjacking and XSS injection into customer billing portals and operational dashboards
Sector-wide
3
Certificate & Software Exploitation — Org E
46 F-rated certificates + Software D at Org E: deprecated TLS enables interception; known CVEs in vulnerable components exploitable without authentication
Pivot
4
Application Access — Org D
8 F-rated applications within the sector's largest estate (12,435 assets) provide entry points to wastewater operational interfaces and regulatory reporting systems
Pivot
5
Impact
Infrastructure asset data (via ArcGIS), operational portal access, customer PII, grid/plant control system adjacency, NIS2 notifiable incident
Impact
Sector Findings
Priority issues identified across the utilities benchmark
- Fix Now
Security headers absent sector-wide — 5/5 organisations — No other risk category in this sector intelligence series has failed at every operator simultaneously. CSP, HSTS, X-Frame-Options, and Referrer-Policy are missing or misconfigured across all five utilities organisations, irrespective of estate size, geography, or operator type. Remediation is well-understood and implementable via CDN configuration or web server policy — but requires deliberate prioritisation.
- Fix Now
Org E — 46 F-rated certificates across a 5,393-asset estate — Deprecated TLS versions, expired certificates, and misconfigured cipher suites on a waste-to-energy operator's digital estate create interception risk on connections between operational platforms, grid interfaces, and municipal contracting systems. Combined with Software D and Header D, Org E carries three concurrent D-or-worse risk categories — the highest concentration of systemic web risk in this benchmark.
- Fix Now
Org E — Software D and 29 Fix Now priorities — Org E carries the highest Fix Now count in this benchmark and the sector's only D-rated software risk profile. Known CVEs in JavaScript libraries and server-side components embedded across its estate provide documented, unauthenticated exploit paths.
- Fix Soon
Org D — 8 F-rated applications within 12,435-asset estate — Org D is the largest estate scanned in this benchmark and carries 8 applications rated F, contributing to 16 Fix Now and 26 Fix Soon priorities. For a wastewater operator classified as an NIS2 Annex I essential entity, F-rated web applications represent direct compliance exposure alongside technical risk.
- Fix Soon
Orgs A and B — SSL service risk C — Both the Dutch drinking water operator and the Belgian water utility carry C-rated SSL risk. Deprecated TLS configurations on externally reachable services undermine the security of encrypted connections handling regulatory data, operational management traffic, and customer billing information.
- Fix Soon
Meta Platforms present across all 5 utilities organisations — An unusual finding for a sector handling sensitive infrastructure data and operating under NIS2 essential entity obligations. Meta's presence through embedded tracking pixels, social sharing scripts, and analytics integrations creates data outflow pathways from utilities' public-facing portals.
- Monitor
Esri / ArcGIS embedded at 3/5 utilities — ArcGIS serves as the infrastructure asset management backbone for water and wastewater operators — mapping pipe networks, treatment facilities, and service zones. A compromise of ArcGIS-connected interfaces could expose infrastructure topology data with significant operational security implications.
Unlock Your Organisation's Full Report
See exactly where your utilities operation is exposed
ThingsRecon scans your external attack surface from the outside in — no agents, no credentials, no internal access required. Within hours you receive a full picture of your web estate, supply chain dependencies, and prioritised remediation roadmap.
✦ Named asset inventory
✦ Fix Now / Fix Soon roadmap
✦ Supply chain exposure map
✦ Competitor benchmarking
✦ NIS2 Annex I gap assessment
✦ Certificate audit
Request your scan