Enhancing Cybersecurity in Water Plant Infrastructure with SecureAI

Authors

DOI:

https://doi.org/10.34190/eccws.25.1.4581

Keywords:

SCADA, Water Plant Infrastructure, Human Oversight, Compliance Artifacts, Dynamo Project

Abstract

Water plant industries are a critical infrastructure that relies on legacy Supervisory Control and Data Acquisition (SCADA) systems, which were not designed to address modern cyber threats. Attackers utilise these vulnerabilities to create significant risks to the industries. As an example, recent incidents such as the attack on the Demin water plant and the Oldsmar water facility, where attackers gained unauthorised remote access to these water plants' systems. This emphasises the urgency of strengthening cybersecurity in this sector. This study investigates SecureAI, an AI-driven cybersecurity tool developed through the Dynamo project. SecureAI provides real-time anomaly detection, recommends isolating protocols to contain threats early, and generates post-incident training materials to improve operator readiness. To ensure that SecureAI implemented into critical infrastructure cannot become autonomous, the EU AI Act requires mandatory human oversight for all high-risk systems. The study includes an evaluation of SecureAI’s strengths, weaknesses, and ethical safeguards that align with the EU AI Act, the NIS2 Directive, and the NIST Cybersecurity Framework. Mock-up data on attack scenarios, best practices for the deployment of SecureAI, and an incident response script designed for operator use based on SecureAI alerts. This study bridges the gap between technical detection and regulatory compliance and extends the body of knowledge on AI-enabled cybersecurity measures in water plants. Moreover, SecureAI offers a scalable, operator-centric solution that strengthens resilience while ensuring transparency, compliance and human accountability.

Author Biography

Ilkka Tikanmäki, Laurea University of Applied Scienses

MBA (Information Systems) Ilkka Tikanmäki is a Project Specialist in Business, Data Processing and Service Sector Unit at Laurea University of Applied Sciences and a doctoral student of Operational Art and Tactics at the Finnish Defence University. https://orcid.org/0000- 0001-8950-5221

Diana Marinca, Muhibba Saani Mohammed and Rakyan Kadar Slamet are students in the bachelor’s degree Programme at Laurea University of Applied Sciences in the Degree Programme in Business Information Technology, Cybersecurity.

Downloads

Published

2026-06-15