Skip to main content
CybersecurityInfrastructure

Ex-NSA Chief Warns of Water System Cyber Risks

Control room with industrial equipment and computer screens at a water treatment plant.

"These PLCs should not be connected to the internet," retired General and ex‑NSA chief Paul Nakasone told reporters at DEF CON, speaking bluntly about the recent intrusions that have touched water systems in at least a dozen U.S. states.

Paul Nakasone at DEF CON: higher standards and measured attribution

Nakasone, identified in reporting as a retired general and former director of the National Security Agency, pressed for stronger cyber defenses while addressing reporters at the security conference. "We have to have higher standards," he said, and argued that defending water infrastructure requires a different mindset and broader partnerships than the nation currently employs. He said federal authorities are "taking a measured approach" to attributing the recent attacks but added that he sees "an actor here that has certainly shown a history of being able to do this" and that the actor "certainly have[s] the capability" to target water systems.

FBI investigation and the question of blame

In late July the FBI announced it was investigating incidents it described as attacks by "malicious cyber actors" aimed at operational technology devices, including programmable logic controllers (PLCs). The reporting cites private‑sector researchers who say they suspect Iranian intruders are behind the recent disruptions to water and wastewater facilities; Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center, told The Register at DEF CON that "I'd be shocked if it's not Iran" and that "It's almost certain it's Iran." Neither the FBI nor anyone in the Trump administration has officially blamed Iran, however, and the public record of the federal response remains one of investigation rather than formal attribution.

PLCs, attack surface, and why water systems are vulnerable

The intrusions center on programmable logic controllers — devices that ingest sensor data such as tank levels and can turn pumps on and off. The source material notes Iran‑linked crews have targeted PLCs at water facilities "for years." Nakasone warned the scale and structure of U.S. water delivery complicate defense: "We’ve got 50,000 different water municipalities in the United States, 90 percent of our water comes from these 50,000," he said, describing an enormous and disparate attack surface composed largely of historically underfunded facilities with limited or no dedicated cybersecurity staff.

DEF CON Franklin and Project Chimera: volunteer and academic efforts

Nakasone pointed to collaborative efforts as part of the response. DEF CON Franklin, a project started two years ago at the annual conference, convenes volunteer hackers to help secure water facilities. Separately, Nakasone is identified as founding director of Vanderbilt University's Institute of National Security and its Wicked Problems Lab, and is working on Project Chimera — a cybersecurity platform being developed by academics and cybersecurity practitioners and "built on open‑source technologies to boost critical infrastructure resilience." He framed these efforts as examples of the sort of partnership approach he believes is necessary: "You defend with a series of partners, in a much more involved approach than we have right now."

How technologists, policymakers, and water utilities are positioned

  • Technologists and security teams: The immediate technical focus identifies PLCs as sensitive, high‑impact devices that should not be internet‑exposed; private‑sector researchers are already publicly pointing to likely nation‑state tradecraft in the recent incidents.
  • Policymakers and regulators: Federal investigators are probing the incidents but have not issued formal attribution; officials quoted in the reporting call for higher standards and broader partnership models to protect a widely distributed network of municipal providers.
  • Water utilities and operators: Many of the roughly 50,000 municipalities that supply 90 percent of the country's water face a large attack surface and limited cybersecurity staffing, making them focal points for volunteer, academic, and public‑private efforts such as DEF CON Franklin and Project Chimera.

The account in The Register places a spotlight on a predictable but uncomfortable fact: core operational devices that control pumps and tanks remain a high‑value target and, in many cases, are reachable in ways they should not be. The public mix of ongoing FBI investigation, private researchers’ strong suspicions about Iran, and calls from a former intelligence chief for higher standards and broader partnership leave a clear, specific task on the table — reduce internet exposure of PLCs, expand coordinated defenses, and marshal volunteer and academic resources to close glaring gaps before another set of facilities is disrupted.

Original reporting at The Register