America’s Water Systems Are Still Too Exposed to Cyberattack
Key Highlights
- Water systems in multiple states have experienced cyber intrusions, exposing vulnerabilities in legacy industrial-control systems not designed for today's cyber threats.
- Experts warn that connectivity choices made decades ago have left critical infrastructure exposed, necessitating fundamental security improvements and policy changes.
- Basic security practices such as unique credentials, network segmentation, and eliminating unnecessary internet exposure are essential to prevent and detect attacks.
- Small utilities face resource challenges, underscoring the importance of federal support, shared expertise, and comprehensive risk management strategies.
- Cyber warfare now targets trust and operational control, requiring utilities to build resilience through continuous visibility, manual operation readiness, and cross-sector collaboration.
Since mid-July, water and wastewater systems in at least 12 states have reported cyber intrusions, putting a stark new face on a vulnerability security officials have warned about for years. Iranian-linked sources on Telegram have claimed responsibility on behalf of the CyberAv3ngers, a group associated with Iran’s Islamic Revolutionary Guard Corps (IRGC), while the FBI and CISA have stopped short of publicly assigning definitive blame.
But attribution may ultimately be less important than what the attacks are exposing. The question is no longer whether a determined foreign adversary can reach an American water system. It is why so many systems remain reachable in the first place.
That is the more consequential story emerging from the attacks. Beneath the headlines about Iranian hackers and compromised municipal systems is a far more systemic problem: critical water infrastructure is increasingly being operated on an industrial-control foundation that was never designed for today's cyber threat.
Legacy programmable logic controllers (PLCs) and other operational technology (OT) were built for reliability, availability and physical control; not internet-facing connectivity, remote administration, identity-based access or persistent cyber defense. Yet over decades, those systems have been connected to modern IT networks, remote-access platforms and, in some cases, the public internet.
The result is a dangerous collision between old technology and new adversaries.
Chuck Brooks, an internationally recognized cybersecurity expert, says the latest incidents should be viewed as part of a continuing campaign rather than isolated events.
“Instead of viewing this as a singular incident, security leaders should see it as part of an ongoing, opportunistic-to-directed campaign,” Brooks says. He points to previous compromises of internet-exposed PLCs and human-machine interfaces (HMIs) and warns utilities to “anticipate ongoing scanning, credential attacks, and opportunistic exploitation of still-vulnerable interfaces,” particularly as geopolitical tensions rise.
Maria Sumnicht, an OT, ICS and IoT cybersecurity expert and the National Director for Cybersecurity Task Force on National and Homeland Security, takes the issue back to its roots: connectivity was a choice.
“The reason so many ICS and PLC environments are accessible from the public internet is that someone, somewhere, decided to do this,” Sumnicht says. “Twenty-plus years ago, this was not the case. These systems were not connected to the public internet. To make changes, you had to go onsite.”
Vendor remote access has become one justification for that exposure. As Sumnicht puts it: “The best and worst answer I received at the same time was, ‘Because the manufacturers need access to perform updates without sending a representative on site.’”
Legacy programmable logic controllers (PLCs) and other operational technology (OT) were built for reliability, availability and physical control; not internet-facing connectivity, remote administration, identity-based access or persistent cyber defense.
The policy response has been equally problematic. In 2023, the federal government attempted to require cybersecurity reviews as part of water-system risk assessments. Arkansas, Iowa and Missouri challenged the effort, a federal appeals court halted implementation, and the EPA ultimately withdrew the rule. Less than a week before the first highly publicized Minnesota attacks, CISA expanded its warnings to additional PLC manufacturers.
For smaller utilities, limited resources compound the challenge. The Water Watch Center, launched by DEF CON Franklin and the National Rural Water Association, is intended to help utilities serving fewer than 10,000 people strengthen detection and response capabilities. But the experts interviewed for this story emphasize that monitoring is only one piece of the solution.
The Fundamentals Still Matter
Shane Barney, chief information security officer at Keeper Security, says the recent incidents demonstrate an access-control problem as much as a detection problem.
“When threat actors reached programmable logic controllers, changed passwords, and locked operators out of their own systems, the detection problem and the access problem arrived at the same moment,” Barney says.
His prescription is straightforward: every operator and administrator should have a unique credential tied to an individual identity; contractor access should be time-limited and scoped; and changes to privileged accounts should be immediately visible to those responsible for the system. These controls, Barney says, do not require a dedicated security team and provide the foundation for more effective monitoring.
Matt Hartman, chief strategy officer at Merlin Group, agrees that detection cannot substitute for basic OT hygiene.
“Traditional IT-focused monitoring may not detect direct interaction with a PLC,” Hartman says. For smaller utilities, he adds, “detection isn’t a substitute for the fundamentals: knowing what assets you have, securing remote access, segmenting networks, and eliminating unnecessary internet exposure.”
John Gallagher, vice president at Viakoo, puts asset visibility at the top of that list.
“The true binding constraint for small water systems is basic asset discovery and vulnerability remediation,” Gallagher says. That means knowing which devices are connected, eliminating default passwords, updating firmware and enforcing secure access before sophisticated monitoring can deliver meaningful value.
The resource gap, however, cannot be ignored.
Kevin E. Greene, chief cybersecurity technologist, public sector, at BeyondTrust, describes the situation bluntly: “Many small water systems are still operating below the cyber poverty line.”
A realistic national strategy, Greene says, must combine asset visibility, secure remote access, MFA where it can be enforced, privileged-access governance, tested manual operations, incident-response support and access to regional or shared technical expertise. It must also account for what happens when prevention fails: disaster recovery, continuity of operations, emergency management, and crisis communications.
“When a water utility loses operational control, it stops being only a cybersecurity problem very quickly,” Greene says. “It can become a public-safety and national security issue.”
Christopher Hills, chief security strategist at BeyondTrust, argues that the problem also reflects a longstanding OT priority.
“For many years, OT has prioritized uptime over security and threat actors know this,” Hills says.
Yet legacy technology does not eliminate the need for basic security. Hills points to default credentials and unnecessary public-facing access as fundamental weaknesses that can and should be addressed even when modern security controls cannot be deployed.
For environments that cannot easily adopt those controls, he argues that Zero Trust principles can establish a security boundary around OT and regulate access from both external and internal sources. The immediate priority, however, remains basic: manage or rotate default credentials and shut down direct public access that is not necessary.
Taken together, the experts point to a hierarchy of needs: know what is connected, remove unnecessary exposure, control access, secure remote pathways, segment OT networks and establish the visibility necessary to recognize abnormal activity.
The challenge is making those fundamentals sustainable for utilities that may lack the money, personnel or technical expertise to implement them independently.
The experts point to a hierarchy of needs: know what is connected, remove unnecessary exposure, control access, secure remote pathways, segment OT networks, and establish the visibility necessary to recognize abnormal activity.
OT Is Not IT
The industry has spent decades securing enterprise IT, but OT has lagged because the two environments present fundamentally different operational realities.
Industrial-control systems may be decades old, difficult to patch and unable to tolerate downtime. A security strategy designed around conventional IT assumptions — frequent updates, system replacement, and aggressive endpoint controls — cannot simply be transferred to an environment where availability and physical safety are paramount.
Sumnicht argues that the regulatory framework must recognize that distinction. USDA should incorporate industrial-control-system risk assessments into its regulations and establish cybersecurity controls tailored specifically to OT. USDA and CISA also need to address process-sensor security more explicitly because those sensors can be critical to the safe and reliable operation of industrial environments.
Internationally, examples of a broader approach already exist. BSI 96:2026, British Standards Institution guidance on food defense, explicitly recognizes SCADA systems, PLCs, sensors and cold-chain monitoring as systems requiring protection against deliberate acts, including cyberattacks, sabotage and other threats.
“The broader lesson is that OT security must be addressed in the context of the physical processes those systems control, not simply through the lens of enterprise network security,” Sumnicht says.
That means defining control-system cybersecurity separately from enterprise IT security and building OT requirements into policies, procurement and workforce training. Organizations should also independently monitor critical process sensors using physics-based validation rather than relying solely on network security controls.
“Sensor cybersecurity should become part of existing safety and reliability programs,” Sumnicht says, “ensuring that anomalous readings or manipulated data can be identified before they translate into unsafe or unreliable physical outcomes.”
That requires cybersecurity, engineering and operations to work together rather than in separate silos. The objective is not simply to bolt another security layer onto legacy OT, but to incorporate security into the operational, engineering, safety and reliability processes already governing these systems.
Done correctly, the result can be more than improved cybersecurity. It can improve operational safety, reliability, predictive maintenance and resilience.
Cyber Warfare's New Target: Trust
The significance of these attacks extends beyond compromised PLCs, changed passwords or disrupted operations. Brooks says they reflect a broader evolution in cyber warfare; one in which disruption, public unease and declining trust in essential services can be as valuable to an adversary as stolen data or financial gain.
Water systems are particularly consequential targets because they sit at the intersection of public safety and public confidence. An attack can test an operator's preparedness, demonstrate an adversary's capabilities and impose operational and psychological costs without the escalation associated with a conventional kinetic attack.
That changes what water-system cybersecurity must accomplish.
The objective can no longer be simply to prevent a breach. Governments and operators must assume that scanning, credential attacks and exploitation of exposed systems will continue. They must also build the ability to absorb an intrusion without losing operational control.
As Brooks puts it, critical-infrastructure cybersecurity must become “a fundamental component of both national and societal resilience.”
The action items are clear: remove unnecessary internet exposure; establish continuous visibility into OT assets; segment operational networks; secure remote access; strengthen privileged-identity controls; apply Zero Trust principles where appropriate; expand public-private threat intelligence sharing; exercise cross-sector incident response; and design systems for graceful degradation, manual operation and rapid recovery.
None of that can be accomplished through technology alone.
Cybersecurity must become part of how water systems are designed, procured, operated and maintained. That means investing in people, procedures and OT-specific expertise and providing smaller utilities with sustained federal support and shared capabilities rather than relying on temporary programs or philanthropic stopgaps.
The lesson from this latest wave of attacks is not simply that America's water infrastructure is vulnerable. It is that adversaries increasingly understand how to turn that vulnerability into leverage.
The utilities best prepared for the next attack will not necessarily be those with the most sophisticated security technology. They will be the ones that know what is connected, control who can access it, eliminate unnecessary exposure, recognize when something is wrong, and critically know how to keep delivering safe water when their digital defenses fail.
The time for treating OT security as an IT problem is over. Water security is operational security, public safety and national resilience. The next phase of cyber warfare will test all three.
About the Author
Steve Lasky
Editorial Director, Editor-in-Chief/Security Technology Executive
Steve Lasky is Editorial Director of the Endeavor Business Media Security Group, which includes SecurityInfoWatch.com, as well as Security Business, Security Technology Executive, and Locksmith Ledger magazines. He is also the host of the SecurityDNA podcast series. Reach him at [email protected].



