Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Waterworks

The Waterworks Vendor Cyber Rating & Cyber Score

thewaterworks.com

The Waterworks is Ohio’s largest plumbing, drain and HVAC company servicing homeowners, businesses, and municipalities alike. With over 150 specialized technicians and employees – and a dedicated fleet of service vehicles — the company has the capability to respond quickly to both routine and emergency calls. Truly full-service, The Waterworks solves both large and small plumbing issues — from indoor leaks and clogs, to underground pipeline and sewer repair, to advanced hydro-jetting and excavation. The team also provides complete furnace and air-conditioning tune-ups, repairs, and full system replacements. This wide offering, all from a single convenient source, means the company forms long-lasting relationships with its customers, offers


The Waterworks A.I CyberSecurity Scoring

The Waterworks
Company Information
Website:https://thewaterworks.com/
Employees number:77
Number of followers:379
NAICS:81
Industry Type:Consumer Services
Homepage:thewaterworks.com
The Waterworks Risk Score (AI oriented)
Between 700 and 749
logo
The WaterworksConsumer Services
Updated:
06/08/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
The Waterworks Global Score (TPRM)
xxxx
logo
The WaterworksConsumer Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

The WaterworksModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-38 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
738Before Incident
SEPTEMBER 2026
737Before Incident
AUGUST 2026
774Before Incident
Cyber Attack
03 Aug 2026 • The Waterworks
Columbus Water Works: Hackers Hit New Jersey Water Systems: Twelve States Now Hit in attack on America’s Drinking Water

Cyberattacks Target U.S. Water Systems as Exposed Industrial Controls Leave Critical Infrastructure Vulnerable

736After Incident
CRITICAL-38
THE1786048180
Cyberattacks Target U.S. Water Systems as Exposed Industrial Controls Leave Critical Infrastructure Vulnerable New Jersey confirmed on Wednesday that two municipal water systems were compromised in cyberattacks involving internet-exposed industrial control systems (ICS). Operators temporarily lost remote monitoring and management capabilities, forcing a shift to manual operations. While water service remained uninterrupted and drinking water safe, the incidents exposed persistent security gaps in critical infrastructure. The attacks, investigated by the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) alongside the FBI and CISA, targeted programmable logic controllers (PLCs) devices that regulate physical processes like water pressure, chemical treatment, and pump operations. Despite New Jersey’s 2017 Water Quality Accountability Act, which mandated cybersecurity programs, incident reporting, and insurance for utilities, the compromised systems were accessible via the public internet a basic security failure. The state has not disclosed the affected utilities, leaving residents unaware of whether their water systems were breached. Investigators suspect foreign involvement, with Iran as the leading suspect, though attribution remains unconfirmed. The attacks follow a broader pattern: since July 2026, at least 12 states including Minnesota, Michigan, Wisconsin, Georgia, and New Jersey have reported similar incidents, with attackers exploiting exposed PLCs, often using default credentials. In Georgia, a July 27 water outage in Clayton County was initially dismissed as a routine pump failure before authorities linked it to unauthorized cyber activity. Nearby Columbus Water Works also detected suspicious activity the same day, prompting a switch to manual controls. In both cases, operators restored functionality, but the delayed disclosure eroded public trust. The vulnerabilities extend nationwide. Georgia Tech researchers identified over 7,000 internet-exposed industrial controllers across water systems, hospitals, airports, and military facilities, with only 30% of notified owners removing the devices. The FBI and CISA have warned of ongoing attacks targeting Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens controllers, with some incidents causing pressure loss and flooding. The U.S. water sector operates under voluntary guidelines, unlike the electric grid’s mandatory federal standards. An EPA inspector general report in 2024 found 97 water systems serving 26.6 million people with critical cybersecurity risks. Despite repeated warnings, enforcement remains lax, with utilities often lacking the resources to secure aging infrastructure. The attacks’ limited impact so far is credited to employees who recognized anomalies and operated plants manually a thin margin of safety. As remote monitoring expands to cut costs, the same access points become attack vectors. The EPA has emphasized local responsibility, but small-town water departments, often understaffed and underfunded, struggle to defend against state-sponsored cyber operations. With no federal enforcement, the risk of escalation persists. While immediate threats focus on pressure loss and operational disruptions, prolonged outages could lead to contamination. The incidents underscore a systemic failure: warnings, laws, and compliance deadlines have not translated into real-world security. The next attack may not be caught in time.
INCIDENT DETAILS -
TYPE
CyberattackUnauthorized Access
IMPACT
Systems Affected: Industrial control systems (PLCs) regulating water pressure, chemical treatment, and pump operationsDowntime: Temporary loss of remote monitoring and management capabilitiesOperational Impact: Shift to manual operations, delayed response to anomaliesBrand Reputation Impact: Eroded public trust due to delayed disclosure
JULY 2026
774Before Incident
JUNE 2026
774Before Incident
MAY 2026
774Before Incident
APRIL 2026
774Before Incident
MARCH 2026
774Before Incident
FEBRUARY 2026
774Before Incident
JANUARY 2026
774Before Incident
DECEMBER 2025
774Before Incident
NOVEMBER 2025
774Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for The Waterworks ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in September 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in August 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in July 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in June 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in May 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in April 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in March 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in February 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in January 2026 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in December 2025 ?
?
What was The Waterworks's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on The Waterworks's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with The Waterworks ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view The Waterworks's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?