What happened
The computers that automate water treatment across the United States were built for durability, not for an internet-connected world. Many still do their job. But after cyberattacks on the sector mounted this summer, industry officials say those ageing systems, especially internet-exposed operational technology and programmable logic controllers, remain among the easiest ways for an attacker to get in.
Tom Dobbins, executive director of the Water Information Sharing and Analysis Center, told CyberScoop the sector's most persistent weaknesses are exposed OT, vulnerable PLCs, insecure connections through integrators, and weak cyber hygiene at smaller utilities. On the PLCs, he noted that much of the equipment predates modern cyber threats and that utilities have little incentive to replace hardware that still works.
Two more sources of exposure sit on either side of the utility. Externally, integrators with unmanaged connections into operational systems give an attacker a route in. Internally, an employee who opens a malicious link becomes the entry point. At the smallest utilities, even basics such as changing default passwords and enabling multifactor authentication are difficult to sustain with limited staff.
WaterISAC is partnering with Cyware to use its threat intelligence platform, choosing it partly because of existing relationships with other sector sharing centres, to move information faster across the industry. The centre already works with the National Rural Water Association to serve 20,000 of the water sector's smallest utilities. Dobbins said the threats come from Iran, which the US government reportedly believes was behind this summer's attacks on water facilities, as well as from China and Russia. He also noted that President Trump has disputed the Iran attribution, while CISA has warned of Russian and Chinese activity.
Why this is a GRC story
Third party risk is the hardest part to govern. Integrators who hold connections into OT are suppliers with privileged access. If those connections are not inventoried, reviewed and revocable, then the question of who can touch the plant is answered by memory rather than by record.
Legacy hardware is a risk acceptance decision. Keeping equipment that works is reasonable. Doing so without a documented rationale, a compensating control and a review date converts an operational choice into an unmanaged exposure. That is exactly the kind of item a board should be asked to accept in writing.
Shared intelligence is infrastructure. A sector of thousands of small operators cannot each fund their own threat research. Sharing centres and cross sector partnerships are the mechanism that puts the same information in front of a large utility and a rural one, and their funding model is a governance question as much as a technical one.
What to watch
Watch for minimum control requirements aimed at small utilities. Voluntary guidance has been the pattern, and the summer's attacks raised the obvious question of what happens when voluntary is not enough.
Watch whether the intelligence partnerships produce measurable results. Faster sharing only reduces risk if it reaches the operators who can act on it, and the smallest utilities are both the hardest to reach and the most exposed.
Attribution: Analysis based on CyberScoop and related public reporting. This article is original commentary, not a repost of the source material.
