This past week’s cybersecurity incidents impact the Water/Wastewater Sector (WWS) have exposed a smorgasbord of issues.
I by no means want to just add more commentary on top the probably 100’s of takes and dives on the issues. But at the same time, most coverage starts and ends with limited viewpoints into and out from the details.
As a passionate cyber and security professional focused not solely on defense but also resilience and protection of the critical infrastructure our civilization relies on, I feel the need to press up against the norms and lean into the broader views without sacrificing the context details that expose the true issues.
For example, CISA’s AA26-097A advisory contains logical, technical, key actions to mitigate and respond to exposures. CISA has incredibly broad remit though and cannot account for organizational steps needed to achieve these actions.
This is where I want to lean in and draw contrasts, in hope of breaking through the ceiling on how these events have exposed numerous shortcomings impacting WWS.
Intro
The latest US federal reporting describes threat actors:
reaching programmable logic controllers at US water utilities
taking project files
disabling shutdown and alarm logic inside them
altering what the operator screens displayed
No software defect was exploited to do it. The devices were reachable and the adversary used the manufacturers’ own engineering software.
The following is a collection of facts that can be used to decide where investments should go: exposure, records, architecture and accountability.
Compromise
CISA’s AA26-097A advisory and “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs” alert present a chain of preconditions vs chain of techniques.
Break stage one and the rest are unlikely to occur.
Because later stages assume the device was already reachable, detection tooling placed at stage four is expensive insurance for what can and should be removed at stage one.
Stage five breaks conventional response assumptions because the operator’s instrumentation was compromised at the same time as the process. Plans that depends on staff noticing an anomaly on the HMI have already failed.
Reachability
Most utilities can describe a layered network with mediated remote access.
The alert’s specific warning is that the second path below exists in parallel, installed by operators, vendors or integrators, and frequently never recorded. The mediated path terminates where logging, identity and monitoring live.
The undocumented path terminates where they do not.
This is a records problem just as much as a control problem. A control can’t be applied to an untracked asset and attack surface scanning can only covers known ranges leaving everything else open.
Consequence
Cyber reporting stops at the device but boards, councils and rate commissions respond to consequence.
Because of that, I’m attempting to match controller function to the public outcome and the regulatory instrument that outcome triggers.
Only the last column of row four is a matter of cyber policy, the others are public health and environmental compliance.
Scale
Roughly 50,000 community water systems operate in the United States. Federal drinking water data shows about 8 percent of them serve about 82 percent of the population.
Federal risk assessment and emergency response plan certification under AWIA Section 2013 binds only systems serving more than 3,300 people. Systems below that receive guidance and are not required to certify anything to EPA.
But this campaign targets water entities of every size.
Sources: EPA Safe Drinking Water Information System reporting on system counts and population served; Congressional Research Service on the community water system universe; EPA guidance on AWIA Section 2013 applicability.
Sector Conditions
Practitioner knowledge and federal advisory may diverge but do not compete.
While each position is a defensible response to that party’s incentives and constraints, failures exist in the residual risks they jointly create with no owner.
A decade of position papers, conference panels and voluntary guidance have not changed this, which makes the issue more about the mechanism than the quality of the advice.
Voluntary measures do not resolve the problem of those bearing the consequence holding the most expensive remedies.
Response
While the CISA Advisory mitigation list is technically sound, it’s also organizationally flat.
It places an afternoon of work beside legislative cycles that simply can’t account for the separate weight of each.
But if we sort by horizon, it becomes usable, because it separates what a utility can do before the next board meeting from what it cannot do alone at all.
The first column is achievable by most systems with no security staff. After that, /tbd.
To highlight, the manual operations drill works after an adversary compromises the controller and the display. It’s also the only one a vendor is unlikely to propose because there’s no commodity product to attach to it.
Ownership
The asset owner is accountable for eleven of twelve actions but can’t execute several of them without parties with no obligation to help.
Finding undocumented modems depends on the integrator who installed them
Verifying logic integrity depends on manufacturer tooling
Those mismatches present the biggest structural challenge.
With secure by demand procurement, accountability could reasonably sit with a state funder rather than the individual utility.
With logic integrity, placing responsibility on the manufacturer creates an obligation to supply verification tooling that many product lines do not currently include.
In Summary
This isn’t any one particular person or party’s fault. This isn’t purely a technical issue. Tools help, processes help, advocacy helps, community helps, talking about it helps.
And highlighting the depths and breadth of an issue that is complex, cultural, financial, political and operational is just one of the many ways we can put the right pressure on the right points, to create the right results.











