❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

In most cities, nobody owns the whole network

By: Greg Otto
8 September 2026 at 06:00

Editor’s note: Waco bought the network segmentation technology described here from Elisity while Mike Searight was the city’s chief information officer. He is now a senior adviser to Elisity, a cybersecurity company.

I stood in front of a network cabinet at one of Waco’s water treatment plants, tracing what systems could reach which. The plant’s controls were on that network. So was the branch library. So was the register at the municipal golf course. During my time as chief information officer of a city with 145,000 residents, nobody had ever been asked to inventory what was on that network.

In July, intruders compromised water and wastewater treatment equipment.  Most of that equipment was reachable over public cellular networks, which means they were outside the boundary most utilities thought they were defending. None of the asset lists I have reviewed would have caught it.

Two decisions stand between a small utility and that equipment: who is accountable for the whole network, and where the funding comes from. Neither is technical. Both rest with city manager and councils. Both can be resolved this fiscal year with money already in a budget request.

What the July reports actually say

Three accounts tell different stories. CISA identified over 100 compromised systems in the water and wastewater sector during July, typically through controllers connected directly to cellular modems. The FBI and the EPA reported on July 30 that utilities in at least seven states had reported incidents to the FBI since July 27. Press accounts citing unnamed officials put the number of affected states at a dozen or more.

No federal agency has attributed the late-July water incidents to anyone, and neither will I. A joint advisory does name Iranian-affiliated actors, but for the broader campaign, which is linked to a separate set of intrusions. The advisory was revised July 22, five days before utilities began reporting. That revision expanded the known targeting from Rockwell Allen-Bradley to Schneider Electric, Siemens and potentially others., So the controller brand on the panel no longer settles anything.

The reported effects were operational: a loss of visibility and, in some cases, function. In Clayton County, Georgia, a pump station failed around 1 a.m. on July 27. The boil-water advisory lifted the next day. In early August, the authority serving more than260,000 people said unauthorized cyber activity may have caused or contributed to the disruption. That hedge is deliberate.

The exposure nobody scanned for

The standard answer: they separated the plant network years ago. That’s legitimate work. But it doesn’t matter. The vulnerable controllers never were on the city network—they ran on public cellular links. A modem installed years ago exists nowhere in the asset list and nowhere on network scans. But every carrier invoice lists every SIM the city pays for. Only accounts payable tracks them. Matching those invoices to actual devices costs nothing and can start Monday. The FBI and the EPA also tell utilities to consider isolated architectures for that equipment, and a private access point name tops their list.

Nobody owns the whole network

Most of these systems sit outside the IT department on the org chart, each with its own budget, vendors, and boss. The plant answers to public works. Cameras and card readers arrived with a building project, and most cities treat them like light fixtures. In every city I’ve worked in, exactly one person in IT understands the whole picture. When that engineer leaves, the security posture leaves with them. And nobody owns accountability for the network they all share.

Reporting rules also miss the point. Texas—my example—requires local governments to report security incidents within 48 hours, but only if they involve personal-information breaches or ransomware. An intrusion that seizes control of a controller while touching either sits outside that trigger., That’s exactly what happened in July.

The federal rule requiring a covered cyber incident to be reported within 72 hours was supposed to be finalized in October 2025; CISA is now targeting this month. But nothing determines who owns the network.

Money the utility already applies for

The second answer is there is no budget. Wrong. The fund mechanics matter more than the size of the check.

For State Fiscal Year 2026, the Texas Water Development Board added cybersecurity to the scoring criteria in its Intended Use Plan for the Drinking Water State Revolving Fund. Two questions on the Project Information Form now carry five priority points between them: Oone asks if the governing body adopted a cybersecurity awareness plan in the last five years; the other asks if a project fixes a deficiency found in a cybersecurity assessment. Five points is modest– I won’t oversell it– but this fund is a ranked competition decided at the margins.

Waco segmented five treatment plants—four drinking water and one wastewater—in 43 days against the 90 I’d promised City Council. No bond. No capital request. The utility director funded it from operating accounts using a contract already on the city’s books, rather than an RFP. They carried it to Council because the network was theirs to own.

Those were budget choices ahead of anything else. An operating line competes with a maintenance contract and can be approved this quarter, while the same money in the capital plan waits for a bond cycle. A smaller city without a CIO will not repeat that schedule. The funding mechanics are the same ones.

Every CIO knows how to segment a network. Almost nobody does it, because they are afraid of taking a plant down. Simulate before you enforce. One operating rule came out of it: being on the network allows a device nothing. Plant controls talk only to their SCADA server. Everything else is denied unless explicitly allowed.

City managers, university presidents, superintendents and chief executives are willing to invest in cybersecurity when they trust the investment will make a measurable difference. These leaders spend taxpayer dollars in public view, and the public’s trust rides on every line item as much as the money does. What earns their approval is transparency: a complete picture of what they are protecting, and evidence that critical infrastructure is defended against threats from the open internet and from inside their own network. That standard—full visibility, provable protection—is what every organization should be working toward.

Microsegmentation protects critical systems without the need for rip-and-replace. It isolates water treatment plants, 911 dispatch, public safety alerts, and traffic management from internal and external threats—all on networks cities already own. Modern platforms deploy in weeks rather than budget cycles, making this control finally achievable. Every CIO and CISO should evaluate it now. Microsegmentation is zero-trust’s foundation and the most direct defense of infrastructure residents depend on.

Somebody to call

None of this reaches a two-person utility that can’t write competitive applications. That’s where states must lean in. New York adopted what it calls the first-in-the-nation water cybersecurity rules in March with grants and free technical support. Texas has stood up a Cyber Command with an explicit water and wastewater mandate. A small city needs a number to call and people who answer.

That number now exists. On Monday, Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio — a six-month pilot that puts Texas Cyber Command, the National Cyber Director’s office, the EPA and CISA, and a dozen private cybersecurity and technology companies behind Texas water utilities. Participating systems get red-team testing, vulnerability assessments and help hardening what the assessments find, at no cost, with plans to take the model nationwide after the pilot. If you run a Texas water system, you should be reaching out immediately.

For the smallest systems, DEF CON Franklin and the National Rural Water Association have put volunteers and five managed detection providers behind them.

Where to start

Here are three things CIOs and CISO can do that do not have to wait for a grant or a budget cycle: Name one position accountable for every device on the utility network and put it in writing. Match twelve months of carrier invoices to actual devices and sites. Read your state’s Intended Use Plan scoring criteria before the next application.

Nothing in Waco moved until the first of those was settled. The other two cost nothing more than somebody’s afternoon. Most cities haven’t even put someone in the that position.

The post In most cities, nobody owns the whole network appeared first on CyberScoop.

The water sector just got it’s wake-up call. Again.

By: Greg Otto
6 August 2026 at 06:00

Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency.

Nothing about these attacks required sophisticated methods. The attackers didn’t use zero-day exploits or novel malware. They found controllers exposed to the public internet, many of them so old that they stopped receiving security patches years ago. They logged in, changed IP addresses and passwords, and locked operators out of their own equipment. In at least one case, they modified the ladder logic controlling industrial equipment. These were not Hollywood-style hacks. The controllers sat exposed and undefended.

If this feels familiar, it should. In late 2023, attackers compromised controllers at water utilities across several states, including the widely reported incident in Aliquippa, Pennsylvania. The federal government issued guidance then, too. One of the crucial differences between then and now is that attackers have grown in ambition. They’ve moved from defacing screens to disrupting operations across dozens of systems at once, exploiting the fact that third-party integrators often deploy the same vulnerable configuration across many small utilities. 

The uncomfortable truth is that this was preventable. The reason it wasn’t stopped is more structural than technical. The United States has roughly 50,000 community water systems. Most are small, publicly funded, and run by operators whose primary job is keeping water safe and flowing. Cybersecurity ranks far below that, if it ranks at all. The devices in question are often a decade or more old and replacing them takes capital these utilities don’t have. Rules governing water cybersecurity remain mostly voluntary. Attackers understand these economics perfectly. We should too, yet these attacks keep happening.

 But inaction is a choice. The defenses that work here cost little and require no exotic technology. The FBI and EPA guidance is sound, and every water and wastewater organization should act on it this week, not later. Here’s how:

  • Get controllers off the public internet. No PLC should be reachable from the outside world. Remote access should go through a secure gateway that mediates, monitors, and logs every connection. That includes cellular modems, which are the overlooked entry point in nearly every audit.
  • Fix passwords. Default and shared credentials are still the most common way in. Strong, unique passwords are the cheapest security control available.
  • Restrict communication between devices. Firewall rules and access control lists should allow only expected communication between known control system devices. Block traffic from hosting providers and other sources that have no business touching a water plant.
  • Lock the logic. Keep physical and software key switches in the run position except during authorized updates. This prevents unauthorized changes to configuration and firmware.
  • Practice running manually. The utilities that survived these attacks best were the those that switched to manual operations quickly. That skill requires constant practice.
  • Verify, don’t assume. Nearly every utility believes its PLCs aren’t internet-exposed, right up until an inventory proves otherwise. You can’t protect what you can’t see. Most operators are surprised by what a complete asset inventory reveals: forgotten modems, integrator-installed remote access, devices nobody knew were still online.

Every attack like this follows the same pattern. Attackers change configurations, reset passwords, and modify project files. Every one of those actions creates a signal on the network before operations degrade. In this most recent case, one victim only noticed ladder logic discrepancies across multiple sites. Catching intrusions shouldn’t depend on a sharp-eyed engineer having a good day. Continuous monitoring of OT environments exists to turn those signals into alerts within minutes instead of days. That difference is the difference between an incident report and a boil-water notice.

Water systems have the least margin for error and, too often, the fewest resources to defend themselves. The FBI and EPA have told us plainly what’s happening and what to do about it. The attackers are betting we won’t follow through. For the third time in three years, they’re testing that bet.

Let’s finally prove them wrong.

The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop.

❌
❌