| Opis: | The water and wastewater sector is a crucial pillar of critical infrastructure, ensuring public health, safety, and environmental balance. In recent years, this sector has undergone rapid digitalization, adopting smart meters, SCADA control systems, and Internet of Things (IoT) devices that enable remote management and automation.
While these technologies enhance efficiency, they also introduce significant cybersecurity risks.
Cyberattacks—such as ransomware, DDoS, unauthorized access, and data manipulation—can result in serious consequences, including water contamination, service disruptions, and threats to human health. In response, the European Union has implemented regulatory frameworks such as the NIS2 Directive, the Critical Entities Resilience Directive (CER), and the Cyber Resilience Act (CRA), aiming to ensure a high common level of cybersecurity and operational continuity.
This thesis examines cyber resilience in the Slovenian water sector by analysing the legal framework, identifying current threats, and assessing the preparedness of utility providers. The research is based on semi-structured interviews with key personnel from water utilities and focuses on practical vulnerabilities, organizational challenges, and awareness of EU cybersecurity obligations. The findings inform a set of recommendations to strengthen cyber resilience, improve policy implementation, and enhance cooperation between operators and national authorities, ensuring long-term protection of essential water infrastructure. |
|---|