Federal authorities confirmed in late July that attackers are taking control of water and wastewater equipment reachable from the public internet, and the activity is spreading. For Nevada public entities that operate water or wastewater systems, the exposure is direct: the same controllers, the same vendor-installed remote access, and the same small-utility staffing constraints exist here. This report summarizes what happened, what existing law already requires, the three controls federal authorities recommend, and how the Enterprise Risk Management Excellence Program already assesses this exposure.