The Water Utility Attacks Are a Warning: Cyber Resilience Cannot Be Reserved for Large Organisations
Over the past few weeks, a series of cyberattacks against water and wastewater utilities across the United States has provided another uncomfortable reminder of how geopolitics, critical infrastructure and cyber risk are increasingly colliding.
More than 30 community water systems in Minnesota were targeted during a coordinated campaign in late July, with similar incidents subsequently identified across multiple other states. Attackers gained access to operational technology used to control water infrastructure, changing passwords and network settings and, in some cases, leaving operators unable to remotely control equipment. Some incidents reportedly contributed to loss of water pressure and flooding, although there have been no reports of contaminated drinking water.
Federal authorities are still investigating and, at the time of writing, have not publicly attributed the campaign to a specific state actor. However, US officials and security researchers are reportedly examining possible Iranian involvement.
That possibility should not be dismissed as simply another geopolitical footnote, as Iran has a history here.
More importantly, these attacks expose a much larger cyber resiliency problem: some of the organisations delivering society’s most critical services are also among the organisations with the fewest resources available to defend and recover them.
Small Organisation. Critical Consequence.
When we talk about critical national infrastructure, it is easy to imagine enormous power companies, national telecommunications providers, oil companies and major government agencies. The reality is much messier.
Water infrastructure in particular is extraordinarily distributed. The United States has well over 100,000 public water systems, ranging from large metropolitan utilities to tiny organisations serving relatively small communities. Many of those smaller organisations do not have large cybersecurity teams. Some do not have any dedicated cybersecurity personnel at all.
They operate ageing infrastructure, specialist operational technology, remote facilities and equipment designed during an era when connectivity and cybersecurity were very different considerations. They also frequently depend heavily upon external engineering companies, system integrators and equipment vendors to maintain those environments.
Yet the service they provide is about as critical as it gets, creating an uncomfortable asymmetry. The reality is that the criticality of an organisation to society has almost no relationship to the size of its cybersecurity budget. An attacker does not need to compromise a huge metropolitan water company to create disruption, public anxiety or political pressure. Compromising multiple small utilities simultaneously may achieve much the same strategic objective while attacking substantially softer targets.
When looking at adversary targeting, it is important to consider motivation. Attackers do not necessarily select targets because they are technologically interesting; they select them because they produce a desired effect
Iran Has Been Here Before
For anyone who has followed Iranian cyber activity for more than a decade, the potential involvement of Iran should not be particularly surprising.
In 2012, Saudi Aramco suffered one of the most destructive cyberattacks seen at that point. Shamoon destroyed data across roughly 30,000 corporate systems, rendering huge numbers of machines unusable and forcing an enormous recovery operation.
Shamoon was not a data-exfiltration or confidentiality crisis. It was an operational one. Suppliers and contractors lost normal connectivity with Saudi Aramco, commercial processes reverted to manual workarounds, customer-facing services were disrupted and an enormous technology-replacement exercise followed. Oil continued to flow, but that should not obscure the lesson: when a systemically important organisation loses its ability to operate normally, the consequences do not stop at its network boundary.
The attacker was not simply trying to steal information from Saudi Aramco, the objective was disruption. More than a decade later, the technology may have changed, but the strategic principle has not.
Cyber provides states with an asymmetric mechanism through which relatively small groups of operators can create economic, operational and psychological effects against much larger adversaries. It is comparatively cheap, geographically unconstrained and frequently provides enough ambiguity around attribution to operate within the grey zone between espionage and overt conflict. I discussed precisely this risk earlier this year in Why an Emboldened Iran Should Worry Every CISO.
The lesson from Shamoon was not simply that Iran had the capability to develop and distribute destructive malware; it was that it demonstrated a willingness to use those cyber capabilities to create significant operational disruption to support its geopolitical objectives. The current water-sector incidents need to be considered within that much longer context.
What has changed is not necessarily the strategic objective, but the economics of achieving it. Shamoon demonstrated that attacking one enormous organisation could create widespread disruption. The water-sector incidents demonstrate the inverse possibility: widespread disruption may also be created by attacking many much smaller organisations.
The Target Has Changed, Strategic Logic Hasn’t
Saudi Aramco was an enormous strategic target, but a small municipal water authority in Minnesota is not. That fact does not necessarily make them less attractive to a nation-state. Targeting smaller organisations may represent an extremely rational evolution of the strategy.
Consider a state actor with two options:
Target a large national infrastructure provider with a sophisticated security operation, extensive monitoring, dedicated incident responders, segmented networks and substantial government attention.
Identify dozens or hundreds of smaller organisations providing regional critical services operating internet-accessible industrial equipment with comparatively limited security resources.
The second option requires significantly less effort while still generating national headlines, government intervention and public concern. The attacker is effectively trading depth of compromise for breadth of disruption. That matters because national cyber strategies have traditionally concentrated on protecting the largest and most obviously strategic targets. Distributed attacks invert that assumption. A hundred individually insignificant targets can collectively become strategically significant.
With the second option, the technical sophistication required to produce strategic consequences does not always need to be particularly high.
Sometimes the Most Important Cyberattack Isn’t the Most Sophisticated One
The cybersecurity industry is naturally fascinated by sophisticated malware, zero-day vulnerabilities and novel attack chains. Attackers, however, care about outcomes.
If an internet-accessible PLC with weak authentication provides sufficient access to disrupt a physical process, there may be little reason to develop an elaborate exploit chain.
Whatever the eventual attribution of the current campaign, there is already a well-documented precedent for Iranian-affiliated actors exploiting exactly this type of weakness. We’ve seen this previously with Iranian activity against US water infrastructure.
Beginning in November 2023, IRGC-affiliated CyberAv3ngers compromised internet-facing Unitronics PLCs used by water and wastewater organisations and other critical-infrastructure operators. CISA subsequently reported that at least 75 devices were compromised in the United States, including at least 34 within the water sector.
Many of the targeted devices were internet-accessible, with default credentials and poorly secured remote access creating obvious opportunities for compromise.. The actors subsequently demonstrated the ability to replace PLC ladder logic, change device configurations and interfere with operators’ ability to remotely manage equipment.
Attack sophistication and operational impact are not the same thing. A simple attack against the right dependency can be considerably more consequential than an extremely sophisticated compromise of something that does not matter.
Then There Is Volt Typhoon
Iran is also not the only nation-state actor interested in critical infrastructure. China’s Volt Typhoon would appear to have a different strategy. US authorities have assessed that Volt Typhoon has compromised critical infrastructure across sectors including communications, energy, transportation and water.
Volt Typhoon has made extensive use of legitimate administrative tools, valid credentials and Living off the Land techniques to minimise its footprint. US agencies have reported evidence of the group maintaining access to some victim environments for at least five years.
Rather than immediately executing destructive attacks, the observed activity demonstrates considerable patience and appears consistent with a very different strategic objective: establishing access that could potentially be used during a future crisis. So the purpose may not be to cause disruption today; it may be to establish the capability to cause disruption tomorrow. In military terminology, we term this pre-positioning.
Compromise infrastructure during peacetime. Understand the environment. Establish persistence. Identify dependencies. Maintain access. Then, if geopolitical circumstances require it, the disruptive capability already exists.
Iranian destructive operations such as Shamoon demonstrate what happens when a state decides to use cyber capability for immediate operational effect. Volt Typhoon demonstrates the danger of assuming that because nothing destructive is happening today, the environment has not already been prepared for tomorrow.
These are two different ends of the same cyber resiliency problem. At one end, “can we recover if somebody destroys our systems?” and at the other, “can we re-establish trust in services that may have been compromised years before the incident began?”
Cyber Resilience for a Ten-Person Utility
Smaller utilities cannot operate cybersecurity programmes resembling those of global banks or major energy companies, and they shouldn’t try. Cyber resiliency does not require every organisation to build a Security Operations Centre, employ dozens of threat hunters and purchase every security platform on the market.
It does, however, require organisations to understand what they absolutely must be able to continue doing when prevention controls fail. For a water utility, that starts with the physical service.
Can water continue to be treated?
Can pumps continue operating?
Can pressure be maintained?
Can operators safely control critical processes?
Can water quality still be measured?
Can regulatory reporting continue?
Can these things be done manually when the digital control environment can no longer be trusted?
This is the utility equivalent of what I describe elsewhere as the Minimum Viable Company. The objective is not to recover everything simultaneously, it is to understand the minimum collection of people, processes, technology, data and third-party dependencies required to continue delivering the critical service safely. For a small utility, that may actually make cyber resiliency planning simpler: start with the water, not the computers.
Manual Operations Are a Cyber Resilience Control
One of the most important lessons emerging from these incidents is also one of the least glamorous; manual operations matter.
Cybersecurity tends to focus on technical controls: firewalls, EDR, MFA, vulnerability management, monitoring and segmentation. All these are important. But cyber resiliency focuses on what happens when those controls fail.
If a compromised PLC cannot be trusted, can the physical process continue safely without it?
Do operators know how?
Are the procedures documented?
Where are those procedures stored?
What identities are required to gain access to those procedures?
When were they last exercised?
Are the people who understand those procedures available around the clock?
Could a new member of staff follow them during a crisis?
How long can the utility realistically remain in manual operation?
These questions about a manual process are still part of cyber resiliency. The ability to operate manually is not an embarrassing legacy workaround that should eventually disappear. For some critical services, it is effectively an out-of-band recovery capability to use while the business-as-usual recovery is taking place.
It is the operational equivalent of having a lifeboat. You hope you’ll never have to use it, but removing it because the ship has a sophisticated navigation system would be an extraordinary misunderstanding of resilience.
Recovery of OT Is Not the Same as Recovery of IT
Recovering a conventional IT server and recovering industrial control equipment are very different activities.
You need to know where the trusted PLC configurations and ladder logic are stored.
You need known-good firmware and software.
You need engineering workstations.
You need credentials.
You need vendor documentation.
You may need specialist cables, hardware and programming equipment.
You need the people capable of rebuilding and validating those systems.
You need to know that the configuration you are restoring is itself trustworthy.
I have also written repeatedly about the distinction between recovery and recovery to a trusted state. That difference becomes considerably more important when the system being restored controls pumps, valves, chemical dosing or other physical processes.
The Third-Party Dependency Is Enormous
Smaller utilities also have another issue I recently covered in my Cyber Resiliency Board Briefing on third-party recovery: a small utility may depend heavily upon a handful of external organisations for:
OT engineering.
PLC configuration.
Telecommunications.
Field Service.
Cybersecurity.
Hardware replacement.
Specialist software.
Water testing.
Digital Forensics & Incident Response.
Cloud services.
Equipment vendors.
That can create a concentration risk that may be largely invisible during normal operations.
Imagine a coordinated attack affecting 100 small utilities using similar equipment. They may depend on the same system integrators, require the same replacement PLCs, need assistance from the same specialist responders and all be competing for support from the same vendors.
Suddenly, recovery is no longer primarily a technology problem; it becomes a capacity and prioritisation problem across an ecosystem.
Your recovery plan may assume that an engineering partner will attend within four hours because that is what happened during previous isolated equipment failures. What happens when 50 of their other customers invoke the same agreement simultaneously?
Cyber resiliency planning therefore has to examine correlated failure, not simply individual failure.
What Smaller Utilities Should Be Doing Now
There is a danger with incidents like these that the recommendations immediately become an unrealistic shopping list. For smaller utilities, I would concentrate first on a relatively small number of outcomes.
Remove unnecessary Internet exposure from Operational Technology. There should be an extremely good reason for any PLC, HMI or other industrial control device to be directly accessible from the public Internet. Remote access should be deliberately engineered, authenticated, restricted and monitored rather than simply inherited from the way an integrator configured the system ten years ago.
Establish independent crisis communications. Assume normal email, identity, VPN and collaboration platforms are unavailable or untrusted. Operators need a pre-agreed way to communicate with each other, regulators, emergency services, vendors and specialist responders without depending upon the environment being recovered.
Know what is actually connected. Asset inventories need to include remote-access pathways, cellular connections, vendor equipment and undocumented connectivity. You cannot protect or recover infrastructure you do not know exists.
Eliminate default credentials. The fact that nation-state affiliated actors have successfully compromised critical infrastructure through default or absent passwords should be deeply uncomfortable.
Separate IT and OT. A compromise of email, identity or a workstation should not automatically provide a pathway into operational systems.
Protect the recovery artefacts. PLC programs, configurations, firmware, network diagrams, engineering documentation, credentials and operating procedures need protected, version-controlled and preferably immutable copies separate from the systems they are intended to recover.
Know how to operate manually. Manual operation needs to be documented, trained and exercised rather than discovered during an attack.
Know your Minimum Viable Utility. Identify the minimum people, processes, systems, equipment and suppliers required to continue providing safe water and wastewater services.
Exercise destructive scenarios. Do not simply run a tabletop where somebody announces that “IT has restored the system.”- Disconnect something. Remove remote access. State that the PLC configuration is untrusted. Make identity unavailable or compromised. Assume your normal engineering company cannot help for 48 hours. Then find out whether the service can still operate. That is how resilience becomes a capability rather than a document.
Criticality Creates a Shared Responsibility
Two weeks ago I was fortunate enough to be asked to brief several dozen staffers working for members of the U.S. Congress on the effect that regulation and national cyber authorities have had on resilience in the UK and Europe, particularly across critical national infrastructure and banking. One of the themes in that discussion was that resilience improves when responsibility is not left entirely to individual operators.
It is easy to say that every operator of critical national infrastructure should maintain sophisticated threat intelligence, deep OT security expertise, a fully rehearsed incident-response capability, replacement hardware, tested recovery procedures and 24x7 monitoring. It is much harder to explain how a small municipal utility is supposed to fund and sustain all of that.
That does not make the risk any less real, but it does mean the resilience model has to change. For many smaller CNI operators, proportionate resilience probably cannot mean building every capability themselves. It has to mean access to a shared resilience ecosystem.
That should include federal and state threat intelligence that is timely and operationally useful; sector-wide incident-response capacity that can be mobilised quickly; pooled OT expertise for technologies that individual operators may only encounter occasionally; clear security and recovery obligations on technology vendors; reference architectures that reduce unnecessary variation; emergency stocks of critical hardware; common standards for the artefacts needed to recover systems safely; and mutual-aid arrangements that allow organisations to support one another during a crisis.
The analogy is the fire service. We do not expect every small organisation to maintain its own fire brigade simply because fire is a foreseeable risk. We recognise that some risks are sufficiently consequential, sufficiently specialised and sufficiently infrequent at an individual-organisation level that the capability to respond is more effective when it is shared.
Cyber resilience for critical infrastructure should be viewed in the same way. A small water utility may never be able to justify maintaining a team of specialists in industrial control systems, malware analysis, digital forensics and cyber recovery. But the absence of those capabilities does not reduce the potential consequences if the utility is disrupted. This creates an ecosystem responsibility.
If a nation depends on thousands of relatively small organisations to deliver essential services, then national resilience cannot be based on the assumption that each of those organisations will independently develop the capabilities of a major energy company or global bank.
Resilience is not necessarily about every organisation owning every capability. It is about ensuring that the capability exists, that it can be accessed quickly, and that it has been designed and exercised before it is needed. For critical infrastructure, that may be the only realistic way to make resilience genuinely proportionate to the risk.
The Bigger Strategic Warning
The wider geopolitical lesson is that critical infrastructure, no matter how small, has become part of the battlespace.
Iran has demonstrated a willingness to use destructive cyber capabilities. China-linked actors have demonstrated an interest in persistent access and apparent pre-positioning inside critical infrastructure, while Russia has repeatedly demonstrated cyber operations capable of creating physical and operational disruption.
The increasing convergence of IT, OT, cloud platforms, remote management and third-party connectivity is creating more pathways between cyberspace and the physical world.
The uncomfortable conclusion is that many of the organisations sitting on the front line of this geopolitical competition are not defence contractors, intelligence agencies or multinational corporations. They are local water authorities, regional healthcare providers, municipal governments, schools, small energy providers and local transit authorities. Organisations that may never have imagined themselves as strategically relevant targets. Attackers get to decide what constitutes a target, not the victim.
Cyber Resilience Has to Become Proportionate, Not Optional
It would be unreasonable to expect a small water utility to defend itself against a nation state on equal terms. The objective should be to make compromise harder, limit what an attacker can reach, maintain safe operations when digital systems fail and create a credible path back to a trusted operational state. That is the difference between cybersecurity and cyber resiliency.
The recent attacks on US water infrastructure should therefore not simply trigger another round of vulnerability scanning and password changes. They should trigger a much more fundamental conversation about how small critical-infrastructure operators survive a determined cyberattack.
And when the organisation under attack provides drinking water, electricity, healthcare or another essential service, its size becomes irrelevant as a small organisation can still represent a very large societal dependency.
That is precisely why cyber resiliency cannot be reserved for organisations that can afford large cybersecurity teams.