You turn on the tap, expecting clean water. It’s a basic assumption of modern life. But the systems keeping that water safe are often run by people who can’t be bothered to change default passwords.
Recently, CISA sounded the alarm about Programmable Logic Controllers (PLCs) in the water sector being targeted. Almost instantly, it became a political football. Politicians started pointing fingers at Iran and other foreign adversaries, painting a picture of sophisticated state-sponsored cyber-warfare.
It makes for great political theater. It makes for terrible security.
We are so obsessed with the threat of nation-state cyber-warfare that we ignore the reality: our water supply is easily compromised not by elite hackers, but by gross negligence.
When a water utility gets compromised, it’s rarely a Mission Impossible heist. The vulnerability stems less from sophisticated foreign hacking and more from systemic domestic IT incompetence. It’s IT malpractice. It’s legacy systems left exposed to the open internet. It’s ignoring warnings that CISA and its predecessors have been screaming about for years.
Instead of fixing the problem, we get posturing. Neutrality in cybersecurity is death, and so is pointing fingers at foreign boogeymen while your own house is wide open. If your local water plant is running unpatched systems on public IPs, the threat isn’t Tehran. The threat is negligence.
The real danger to our critical infrastructure is domestic bureaucratic apathy and underfunded local IT. You don’t need a cyber-army to take down a city’s water supply. You just need an administrator who never updated the firmware or changed the factory settings on a critical controller.
We need to stop treating infrastructure security as a geopolitical chess game and start treating it like basic facility maintenance. Every citizen relies on these utilities daily for survival. Their safety is being compromised not by elite hackers, but by political posturing rather than practical security measures.
Before we worry about fighting a global cyber-war, we need to make sure our local water utilities can pass Cybersecurity 101.
FAQ
Q: Isn't it still important to protect against foreign state actors?
A: Yes, but you can't defend against a foreign state if you haven't defended against a bored teenager. Basic hygiene is the prerequisite to advanced defense.
Q: What's the practical implication?
A: Local governments need to fund IT departments properly and mandate basic cybersecurity standards for water utilities, rather than just issuing geopolitical warnings.
Q: What's the contrarian take?
A: The threat of nation-state cyber-warfare is mostly a distraction. The real danger to our critical infrastructure is domestic bureaucratic apathy and underfunded local IT.