America’s water systems are becoming a front line in cyber conflict

Richard Newstead via Getty Images
COMMENTARY | Recent incidents should serve as a huge warning signal, and should encourage utilities to think about cybersecurity not as a compliance but a resilience issue.
The recent wave of cyberattacks targeting water and wastewater systems across the United States should change how we think about cybersecurity.
This is no longer simply an IT problem. It is a public safety, infrastructure resilience and national security problem.
In recent months, water systems across multiple states have reported cyber incidents, including more than 30 systems in the midwest. Utilities in Cape May County, New Jersey, have also confirmed attacks. Federal authorities are investigating the broader campaign, while public reporting has raised the possibility of foreign involvement. Importantly, attribution remains under investigation and should not get ahead of the facts.
What is already clear, however, is that adversaries recognize something we cannot afford to overlook: America's water infrastructure represents an attractive target.
The Cyber-Physical Line Has Disappeared
For years, cybersecurity discussions focused primarily on protecting data, networks and information systems. Water and wastewater systems demonstrate why that definition is now inadequate.
Operational technology controls pumps, pressure, treatment processes, valves, wells and other physical infrastructure. When those systems are compromised, a digital intrusion can potentially produce consequences in the physical world.
Recent incidents reportedly involved attempts to manipulate operational technology, passwords, network settings and automated systems. Some communities experienced operational disruptions, including temporary loss of water pressure and interruptions to treatment operations.
Fortunately, the incidents reported to date have not resulted in widespread public-health consequences. But that should not become a reason for complacency.
It should be a warning signal, flashing brightly.
Small Communities Can Have National-Security Consequences
One of the greatest challenges facing the water sector is its fragmentation.
The United States has thousands of public water systems, many serving relatively small communities with limited cybersecurity personnel and budgets. Unlike a major federal agency or Fortune 500 company, a small municipal utility may not have a dedicated security operations center or sophisticated cyber-defense capabilities.
Yet the operational technology running that utility may still be accessible remotely, connected to vendors, dependent upon software providers, or exposed through internet-facing infrastructure.
The Cybersecurity and Infrastructure Security Agency and Environmental Protection Agency have repeatedly warned about internet-exposed human-machine interfaces used to operate water and wastewater infrastructure. Without appropriate controls, those interfaces can potentially allow unauthorized users to view operational information and make changes capable of disrupting treatment processes.
That creates an asymmetric advantage for an adversary.
An attacker does not necessarily need to defeat the defenses of the federal government to create disruption. Finding a poorly protected controller or remote-access system serving a small American community may be enough.
We Need to Move From Compliance to Continuous Resilience
The response cannot simply be another cybersecurity checklist.
CISA, EPA and the FBI have already provided practical recommendations: reduce public-facing internet exposure, eliminate default passwords, inventory IT and operational technology assets, conduct cybersecurity assessments, back up systems, remediate vulnerabilities and exercise incident-response plans.
Those steps are essential.
But we also need to recognize a larger issue: cyber risk is dynamic while traditional risk assessment is often periodic.
A water authority can complete an assessment today and have its exposure change within hours because a vendor is compromised, credentials are leaked, a new internet-facing asset appears, software vulnerabilities emerge, or a third-party service changes.
Critical infrastructure therefore needs continuous visibility, not only into its own environment, but into the external ecosystem upon which it depends.
That includes understanding vendors, contractors, software providers, remote-access relationships, internet-facing assets and other third parties that can create pathways into operational environments.
In modern critical infrastructure, protecting the organization increasingly means protecting the ecosystem around the organization.
Cybersecurity Is Now Part of Infrastructure Investment
There is also a policy lesson.
We cannot continue treating cybersecurity funding as separate from infrastructure funding.
When federal and state governments invest in modernizing drinking-water and wastewater infrastructure, cybersecurity and operational resilience should be built into those investments from the beginning.
That is particularly important for smaller municipalities.
Washington can publish excellent cybersecurity guidance, but a rural or municipal water authority still needs the resources and expertise to implement it. States can play a critical role by providing shared cybersecurity services, continuous risk visibility, technical assistance and funding that smaller jurisdictions could never reasonably build independently.
This should become a core component of state and federal critical-infrastructure strategy.
The Goal Must Be Resilience
The objective is not to make every water system impenetrable. No cybersecurity strategy can promise that.
The objective is to make America's critical infrastructure harder to attack, faster to detect and more resilient when attacks occur.
That means knowing what infrastructure exists. Knowing what is exposed to the internet. Knowing which third parties create dependencies. Identifying changes in risk before they become incidents. Maintaining manual operating capabilities. And ensuring that local operators have access to the same level of threat visibility that larger organizations take for granted.
America's water infrastructure is essential to public health, economic activity, emergency response and virtually every other critical infrastructure sector. CISA itself notes that water and wastewater services support the operation of critical infrastructure throughout the country.
The events of the past several days should therefore be viewed as more than isolated cyber incidents.
They are a reminder that geopolitical conflict increasingly reaches American communities through digital infrastructure.
A municipal water plant may be hundreds or thousands of miles from a battlefield, but in the modern threat environment, distance no longer provides protection.
Our cybersecurity strategy must reflect that reality.
Protecting America's water is protecting America's national security.
Mike Centrella is head of public sector at SecurityScorecard.
NEXT STORY: States risk rebuilding the cloud compliance maze




