The Watchman's Chair Is Empty

Key Highlights

  • Federal cybersecurity infrastructure has been significantly weakened, with key agencies and programs being dismantled or defunded.
  • Recent attacks on water, telecom, and federal systems reveal the consequences of reduced oversight and shared intelligence.
  • Private sector operators are now the primary line of defense, requiring them to build their own cybersecurity measures.
  • Experts warn that cyber operations targeting critical infrastructure can cause disruption and erode public trust without kinetic conflict.
  • Proactive measures include removing internet exposure, enhancing operational technology visibility, and strengthening public-private information sharing.

Fellow security professionals, let's skip the pleasantries. This year's story is not a cleverer virus or a sharper ransomware strain. It's us. We spent more than two decades building the federal critical-infrastructure shield: agencies, boards, information-sharing hubs, threat-hunting teams, and we are now dismantling it in real time, while the adversary watches the demolition and takes notes.

Run the evidence again. An alleged Iranian cyberattack on water systems in more than a dozen American municipalities. Salt Typhoon walked the telecom backbone for months before anyone cleared their throat. State-linked intruders planted themselves in a Microsoft 365 environment holding federal systems last summer and all but raised their hand. Ransomware keeps hitting the places we're supposed to protect: water utilities, hospital networks, port operations, power fleets. Bleeping systems go dark on schedules.

And our answer? We tore the building down. The CISA director was shown out as a late product return. The National Cyber Director's office was abolished with a signature. The Cyber Safety Review Board, the one genuine after-action mechanism the government built, dissolved. The federal funding that kept state and local information-sharing hubs alive was yanked, and threat-intelligence teams were gutted while our detector was telling us what was at the door.

I've heard these refrains for 30 -plus years: "Security is too expensive. Security has no ROI. Security is intrusive. Security is political." All true, all stale, and all beside the point. The point is that the government-net was never a luxury. It was the radar in the tower. Since 9/11's darkest lessons sank in, the country kept watch as a whole. We shared signals, shared urgency, shared eyes. Take that away and every water plan, hospital, and substation falls back on its own two eyes, most of which were never told they'd have to be a nation's skywatcher too.

Risk at critical mass isn't a personal cloud. It's a reactor issue: the chain reaction goes whatever way it wants because we stopped manning the control hall. And make no mistake, that's what just happened. We did not lose because the adversaries got smarter (they did), but because we pre-loaded the reload door ourselves, dismantled the shield to save a few lines of dollars at precisely the moment the bills came due.

So, here's the only question worth asking in 2026: who holds this industry's line now? The answer can no longer be "the federal watchdog." It's you. Plant managers, CSOs, and CISOs serving water districts, hospitals, and energy cooperatives. The public-partnership radar is dimmer, so build your own. Test your own. Drink responsibly at the board table and tell them the truth about what it costs to have a watch when no one else is watching.

I asked nationally recognized cybersecurity guru Chuck Brooks what the most recent attacks on U.S. water systems tell us about the future of cyber warfare, and he says it highlights an ongoing trend toward cyber operations that put disruption, public unease, and a decline in trust in vital services above simple data theft or financial gain.

“Targeting water systems (and related CI) evaluates reaction preparedness, shows capabilities, and imposes operational and psychological costs with comparatively little kinetic escalation. To be ready, governments and operators must treat CI cybersecurity as a fundamental component of both national and societal resilience. This includes removing internet exposure as quickly as possible, and investing in OT-specific visibility and segmentation, along with strengthening public-private information sharing,” says Brooks.

The guard tower is empty. The enemy is already inside. That's not a metaphor; it's the audit. And the next person to report does the shifting — it's the lights going out and the pumps going silent and then asking who was on Miami duty.

Get to work. We’re out of time, and the clock is still running.

 

About the Author

Steve Lasky

Steve Lasky

Editorial Director, Editor-in-Chief/Security Technology Executive

Steve Lasky is Editorial Director of the Endeavor Business Media Security Group, which includes SecurityInfoWatch.com, as well as Security Business, Security Technology Executive, and Locksmith Ledger magazines. He is also the host of the SecurityDNA podcast series. Reach him at [email protected].

Sign up for our eNewsletters
Get the latest news and updates