The US needs a real plan to defend its water systems
Op-ed says US water utilities need a federal cybersecurity plan after foreign attacks and rising AI-enabled threats.
A CyberScoop op-ed argues the United States still lacks a real plan to defend water systems after Iranian hackers attacked utilities in 12 states. It cites the 2026 threat assessment, Volt Typhoon's penetration of critical infrastructure, and AI systems such as Anthropic's Claude Mythos discovering zero-days. The EPA withdrew a 2023 cybersecurity interpretation after opposition and legal challenges, while roughly 45,000 systems serve 3,300 people or fewer and sit outside strong oversight. Senators Klobuchar and Schiff proposed the Water Safety Shield Act, with about $600 million annually, alongside EPA, FBI, and CISA guidance and a Texas pilot.
- Iranian hackers attacked water systems in 12 states this summer.
- About 80 percent of US water systems lack basic cyber hygiene.
- EPA withdrew a 2023 cyber memo after legal and sector opposition.
- Proposed Water Safety Shield Act would fund about $600 million a year.
- Author urges zero-trust and formal methods for larger utilities.
Full article1,780 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Here’s what it would take: stronger defenses for large utilities, hands-on help for smaller systems and federal support to make both happen.
Listen to this article
0:00
Learn more.
The summer’s cyberattacks by Iranian hackers on water systems in 12 states underscored how vulnerable U.S. water systems are to foreign adversaries. A broad attack on water infrastructure could have consequences comparable to a public health crisis that impacts the country’s entire population.
The threat to water has long been clear. As the 2026 Annual Threat Assessment from the U.S. intelligence community states “Cyber actors from China, Russia, Iran, North Korea, and ransomware groups . . . pose critical threats to U.S. networks and critical infrastructure.”
Advances in artificial intelligence have heightened those vulnerabilities. Advanced AI models, such as Anthropic’s Claude Mythos, have demonstrated the ability to identify thousands of zero-day vulnerabilities in critical software systems, including major operating systems and browsers. Other systems, including some developed in China, are demonstrating similar capabilities. AI systems can now “plan, test, and execute attacks in rapid cycles,” ranging from minutes down to seconds.
U.S. water systems are vulnerable to cyberattacks for technical, legal and practical reasons.
Technical: About 80% of U.S. water systems lack even basic cyber hygiene, a weakness exploited in the summer attacks. Even systems that serve most of the population (approximately 450 large and 4500 medium-sized water systems) have not adopted advanced cybersecurity capabilities used in other sectors where failure can have catastrophic consequences, including aviation, rail, mass transit, medical devices, finance, and nuclear power.
Legal: The Environmental Protection Agency lacks clear statutory authority to impose broad cybersecurity requirements on water systems. In 2023, EPA issued a memo interpreting existing regulations to strengthen the cybersecurity of water systems. The action met widespread opposition from the water sector as well as formal legal challenges, and the EPA ultimately withdrew the memo. The agency retains limited authority. It can require water systems to complete risk and resilience assessments, maintain emergency response plans and, in emergencies, address critical cybersecurity flaws.
Practical: Most U.S. water systems are small. Some 45,000 serve 3,300 persons or fewer. Because of their size, many fall outside the EPA’s regulatory authority and below the “cyber poverty line,” lacking the funding, staff and expertise necessary for effective cybersecurity.
Not surprisingly, the summer attacks drew attention from the administration and Congress. The EPA ,in partnership with the FBI, and CISA each issued guidance on remedial actions, including disconnecting operational technology, from the internet where feasible and adopting robust password practices.
Sens. Amy Klobuchar, D-Minn., and Adam Schiff (D-Calif., introduced the Water Safety Shield Act, a bill that would require tiered cybersecurity standards for the water sector and dedicate a proposed $600 million annually to water cybersecurity. It would go beyond earlier, less prescriptive efforts to improve resilience in the sector.
The administration has also established a pilot program with Texas and private-sector cybersecurity companies to identify and address water-system vulnerabilities at no cost to utilities. These efforts are well intentioned, but they do not address the underlying causes of the problem.
Large and midsize U.S. water systems have long been targets of sophisticated adversaries. China’s Volt Typhoon revealed deep Chinese penetration of critical infrastructure, including water systems, that support national security, economic security, and civil society. Those systems remain vulnerable because many have not adopted well-known protections, such as zero-trust architecture. More fundamentally, the software on which they depend remains vulnerable to exploitation.
Policymakers have struggled to respond for two reasons: the cost and complexity of adopting stronger technical defenses, and the highly fragmented nature of the water sector. A relatively small number of large systems serve about half the U.S. population. Roughly 49,000 systems serve the rest, including the 80% of the systems serving 3,300 people or fewer. Those smaller systems serve about 7% of the population.
Despite these challenges, the capabilities needed to significantly strengthen U.S. water-system security are well known and widely used in other sectors where failure can be devastating, including those listed above.
A five-part federal program could provide high-level cybersecurity for U.S. water systems.
Establish stronger technical capabilities. Water systems should adopt zero-trust architecture, which permits only authenticated, minimum-necessary access to resources and segments networks so that a breach in one area does not compromise the entire system. Such architecture could have blocked the unauthorized intrusions used in the summer attacks. Zero-trust systems are already widely used across multiple sectors, and commercial providers can support their adoption. The Department of Defense has certified several companies to provide zero-trust architecture for department components.
Water systems should also use formal methods to reduce or eliminate vulnerabilities in software that cannot safely fail. Although the summer attackers did not appear to exploit flaws in the water systems’ code, a high-level adversary such as China would be likely to do so.
Formal methods range from “memory-safe” programming languages, which prevent coding errors that leave computer memory open to attack, to rigorous mathematical proofs that verify that software behaves as intended. They also support secure “microkernels,” which strictly separate software functions and make it far more difficult for an attacker to move laterally through a system.
Safe code development draws on the principles of formal methods but is a more practical, semi-formal approach. AI tools developed by companies including Google and CrowdStrike can identify and help repair software vulnerabilities, a process sometimes called “code mending.” Water systems should use such tools to defend against advanced adversaries.
Developing formally verified code for water systems would not be simple. But much of the software that directs the mechanical operations of water utilities comes from a small group of companies, including Siemens, Schneider, and Rockwell Automation. Those companies have the technical expertise to develop more secure code where it is necessary. Secure microkernels are also commercially available.
Support large water systems. Congress should require large water systems to adopt zero-trust architecture, code-mending tools, and formal methods for critical software. The requirements should be phased in over time. The legislation should also provide tax credits to help cover the costs of developing, implementing, and maintaining these protections.
Assist midsize water systems. The federal government should establish a program that provides technical expertise and financial support to midsize water systems, including municipal utilities. The program should help them adopt zero-trust architecture, code-mending tools, and formal methods for software development.
Midsize systems will likely need a longer phase-in period than large utilities. A federally funded cohort of experts drawn from government and the private sector could provide the necessary support. Regional teams, organized by geography or technical specialty, could address the different needs of different water systems.
Create a safe operations posture for small water systems. Few, if any, systems serving 3,300 people or fewer are run by organization with substantial cybersecurity resources. Many cash-strapped systems rely on remote monitoring because on-site service is beyond their budgets. But remote monitoring can create serious risk when industrial devices are exposed directly to the public internet without proper firewalls or virtual private networks.
The summer attacks primarily exploited such exposed devices. The EPA, FBI, and CISA guidance said the affected systems could be protected by locking them into “run” mode, which prevents remote reprogramming. That step may reduce immediate risk, but it also requires systems to be operated in person.
Small utilities therefore need either the staff and funding for manual operations or secure remote-access systems operated by trained personnel.
A voluntary cybersecurity corps could help address the budget and staffing challenges facing small water systems. One model would follow the National Guard approach: State governors would oversee the effort, while the federal government would provide funding. A state-led program could begin with water systems and later expand to other vulnerable critical-infrastructure sectors.
The Texas pilot, which brings together the state, the federal government and private-sector companies, could serve as a model. It could also serve as a test for a regional approach, something we suggested in a prior op-ed.
Build an AI-capable cybersecurity cohort. The proposed cohort should include specialists in artificial intelligence, including experts from leading AI companies. They could use AI tools to develop and deploy cybersecurity programs, including zero-trust architectures and code-mending systems, for utilities of all sizes. AI is advancing rapidly and applying it to protect water systems should be a national priority. The AI specialists should work with major industrial-technology companies, including Siemens, Schneider, and Rockwell, as well as directly with the water systems, both larger and smaller.
U.S. water systems face a significant and growing threat. The Trump administration, Congress, states and private sector should work together urgently to ensure that every American can rely on safe, clean water.
Franklin D. Kramer is a former assistant secretary of defense for international security affairs.
Robert J. Butler is the co-founder and managing director of Cyber Strategies LLC, served as the first deputy assistant secretary of defense for space and cyber policy, and served as the Chief Security Officer for IO Data Centers, a global data center enterprise, among other cybersecurity-related roles in both corporate and government organizations.
Melanie J. Teplinsky is an adjunct professor and senior fellow in the Technology, Law and Security Program at American University (AU), Washington College of Law. She previously practiced technology law at Steptoe & Jonson LLP and served on the pre-IPO advisory board for CrowdStrike.
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
Technology
Threats
AI policy circles targeted in China-linked phishing operation
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Policy
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program