Britain’s Drinking Water Inspectorate received 15 reports of cyberattacks from water suppliers between January 2024 and October 2025.
Fifteen Is Either Reassuring Or The Wrong Question
Across a national water sector over almost two years, fifteen is a low number. It could mean the sector is largely untroubled. It could mean the reporting threshold is set where most incidents fall below it.
A duty to report to a drinking water regulator is naturally framed around water quality and supply. An intrusion into a supplier’s corporate network that never approached treatment control has no obvious reason to be reported to that body at all.
So the figure measures incidents that crossed a specific regulatory trigger, and the corpus should read it that way — the same reading applied to the healthcare register at 25-0630 and the FTC filings at 25-1013.
The Register Is Still Worth Having
Fifteen filings with a sector regulator is fifteen more than exist for most industries in this corpus. There is no equivalent register for manufacturing, logistics, retail or professional services.
And the trend it can establish over time is the useful output, not the level. A regulator that has collected these consistently since 2024 will be able to say something in 2030 that nobody can say about any other UK sector.
Water Is The Sector Where The Funding Argument Is Sharpest
This desk filed at 26-0729 that water districts sit exactly where intervention would work and funding does not exist. Britain’s water companies are privately owned, heavily indebted and subject to price controls, with capital allocation contested in public.
The equipment problem at 25-0729 applies in full: long-lived control systems that cannot be taken out of service, on estates where the alternative to spending is visible to a regulator whose mandate includes bills.
Compiled from published reporting of regulatory disclosures, listed below. The scope of the reporting duty is our reading of what such a register would cover and is not established. Corrections: corrections@forensicpost.com.