US National WireUS NATIONAL WIRE
TechOpinion

The Connectivity Trap: Why Our Water Infrastructure is a Cybersecurity Nightmare

Portrait of Simone Larkin
Simone Larkinthe futuristAug 7AI
The Connectivity Trap: Why Our Water Infrastructure is a Cybersecurity Nightmare

AI-generated image · US National Wire

As remote efficiency pushes critical controllers online, we are trading biological security for digital convenience.

For years, the drive toward operational efficiency has pushed the world toward total connectivity. But as reported by The Register, integrating every sensor and switch into the global network is systematically dismantling the air-gapped security that is essential for basic survival. We are not just optimizing systems; we are expanding an attack surface that our adversaries are already exploiting.

According to reporting from The Register, the vulnerability of this approach has become a matter of national security. Retired General and former NSA chief Paul Nakasone recently warned at DEF CON that programmable logic controllers (PLCs)—the devices responsible for monitoring tank levels and operating pumps—simply do not belong on the internet. The danger is not theoretical. The FBI is currently investigating attacks by malicious cyber actors targeting these operational technology devices, and at least 12 U.S. states have already seen their water systems hacked.

***Opinion:*** *We have entered a phase of 'hyper-connectivity' where the desire for remote management has blinded us to the catastrophic risk of exposure. By connecting the very switches that control our water supply to the open web, we have invited geopolitical conflict into our pipes. The efficiency gained by a remote dashboard is negligible compared to the existential risk of a compromised water system.*

The scale of the problem is staggering. As Nakasone noted via The Register, the U.S. relies on approximately 50,000 different water municipalities for 90 percent of its water. These facilities are often historically underfunded, operating with limited IT staff or, in some cases, no dedicated cybersecurity personnel at all. This creates a fragmented, porous defense line that is easily breached.

While the U.S. government has not officially attributed the attacks, the evidence points toward a specific adversary. Cynthia Kaiser, SVP of the Halcyon Ransomware Research Center, told The Register she would be "shocked if it's not Iran," stating it is "almost certain." Nakasone echoed this sentiment, noting that while federal authorities are taking a measured approach to attribution, Iran has a proven history and the capability to target these PLCs, especially given the current state of conflict.

Solving this requires more than just software patches; it requires a fundamental shift in how we perceive critical infrastructure. Nakasone is currently advocating for a partnership-based defense model. This includes initiatives like DEF CON Franklin, where hackers volunteer to secure water facilities, and Project Chimera, an open-source cybersecurity platform developed by practitioners and academics to increase resilience. Nakasone, who also serves as the founding director of Vanderbilt University’s Institute of National Security and its Wicked Problems Lab, argues that we must think differently about defense to survive this era of connectivity.

Sources

More from Simone Larkin