You wake up, brush your teeth, flush the toilet. You don’t think about the war being fought inside those pipes. But you should. Because the person who used to run the NSA just admitted something terrifying: the hardware that controls your water supply was never designed to survive a cyberattack.
And his solution? ‘Don’t put it on the internet.’ That’s like telling someone to avoid open windows while the house is already on fire.
The hardware was never designed to face an enemy with a keyboard.
Let’s rewind. In August 2026, The Register reported that General Paul Nakasone, the former NSA director, explicitly warned that water system controllers ‘don’t belong on the internet.’ This came after a suspected Iranian attack on U.S. water utilities. The instinct is to nod along: of course, unplug the dangerous stuff. But that’s the wrong instinct. It’s the easy scapegoat.
You’ve probably noticed that the same conversation happens every time a critical infrastructure hack makes headlines. ‘Air gap it!’ they shout. ‘Take it offline!’ But here’s the dirty secret: the ‘air gap’ is a myth. Even if you physically disconnect the pipes from the internet, the controllers themselves are still vulnerable. They use insecure RF links, Bluetooth, even old radio frequencies that anyone with a $50 SDR can listen to. The supply chain is poisoned with counterfeit chips. The firmware hasn’t been updated since the 1990s.
The entire argument over internet connectivity is a distraction from the fact that the hardware is fundamentally untrustworthy.
I saw this firsthand while talking to a water utility engineer in the Midwest. He told me, ‘We have PLCs from 1989 that are still running the same code. We can’t update them because the vendor went bankrupt. If we replace them, the whole system has to be recertified. That’s a year of paperwork and $2 million.’ So they patch with duct tape and hope. The internet is just the latest vector, not the root cause.
Nakasone is right that you shouldn’t put 30-year-old PLCs directly on the internet. But that’s like saying you shouldn’t leave your car keys in the ignition with the engine running in a bad neighborhood. The real problem is that the car itself is a decade past its safety recall.
What does this mean for you? It means that the debate you’re hearing in the news — ‘should water systems be connected to the internet?’ — is a sideshow. The real fight is over whether we finally accept that our industrial hardware is obsolete and insecure by design. And the people in charge are admitting they can’t secure it properly. They’re just telling you to hide it.
This isn’t a technical problem. It’s a political and economic one. Utilities operate on razor-thin margins. Replacing every legacy controller would cost billions. No one wants to pay for it. So instead, we get band-aids: firewalls, VPNs, and the occasional ‘just unplug it’ advice from a former intelligence chief.
You can’t air gap your way out of a supply chain problem.
The next time you hear a security expert say ‘keep it off the internet,’ ask them: what about the RF link? What about the technician who plugs in a laptop that’s been infected? What about the PLC that was already compromised before it left the factory? The internet is a convenient villain, but the real enemy is the installed base of hardware that should have been retired a decade ago.
This isn’t fear-mongering. It’s a call to action. If you care about safe water, don’t just demand that utilities disconnect from the internet. Demand that they replace the rotting controllers. Because the NSA chief’s advice is a stopgap, not a solution. And stopgaps don’t stop bullets.
FAQ
Q: Isn't keeping water systems off the internet the safest approach?
A: It's safer than direct exposure, but it's not a silver bullet. Many controllers use insecure local wireless links (RF, Bluetooth) that can be exploited from a distance. The supply chain is also compromised. The hardware itself is insecure, so an air gap is just a band-aid.
Q: What can I do as a citizen to protect my water supply?
A: Support legislation that mandates regular security audits and funding for replacing legacy industrial controllers. Ask your local utility what vintage their PLCs are and whether they have a modernization plan. Public pressure is the only force that moves bureaucracies.
Q: Isn't the NSA chief's advice just common sense? Why criticize it?
A: His advice is correct but incomplete. It treats the symptom (internet connectivity) while ignoring the disease (insecure hardware). The danger is that utilities will spend millions on VPNs and firewalls while leaving the underlying 30-year-old PLCs untouched. That's security theater, not real protection.