Skip to main content
Threat IntelligenceEmerging Threats

Utilities Face Unseen Network Threats

Industrial control room with equipment and modem in foreground, natural light through large window.

CISA identified over 100 compromised systems in the water and wastewater sector during July, typically through controllers connected directly to cellular modems.

CISA, the FBI and the EPA on the late‑July incidents

Three official accounts describe overlapping but not identical pictures. CISA reported more than 100 compromised systems in the water and wastewater sector in July, often through controllers attached to cellular modems. The FBI and the EPA said utilities in at least seven states reported incidents to the FBI since July 27; press accounts citing unnamed officials put the number of affected states higher. No federal agency has attributed the late‑July water incidents to any actor. A joint advisory named Iranian‑affiliated actors, but tied that attribution to a broader campaign; the advisory was revised July 22, five days before utilities began reporting, to expand known targeting beyond Rockwell Allen‑Bradley to include Schneider Electric, Siemens and potentially others.

The exposure nobody scanned for: public cellular links

Many controllers were never on the municipal network: they ran over public cellular links and therefore existed outside the boundary most utilities thought they were defending. A modem installed years ago does not appear on asset lists and is invisible to standard network scans. Yet every cellular carrier invoice lists every SIM a city pays for—matching those invoices to actual devices and sites costs nothing and, the author notes, “can start Monday.”

Accountability: who owns the whole network

Most of the affected systems sit outside the IT department in organizational terms: the plant reports to public works, cameras and card readers arrive with building projects, and each system often has its own budget, vendors and boss. In every city the author worked in, “exactly one person in IT understands the whole picture,” and when that engineer leaves “the security posture leaves with them.” Reporting rules can compound the problem: Texas requires local governments to report security incidents within 48 hours only when they involve personal‑information breaches or ransomware—an intrusion that seizes control of a controller without touching those triggers may therefore fall outside state reporting requirements. The federal rule requiring a covered cyber incident to be reported within 72 hours was expected to be finalized in October 2025; CISA is now targeting this month for finalization.

Money is a mechanics problem: Waco’s segmentation case

The funding barrier is often a procurement and accounting choice rather than a lack of money. For State Fiscal Year 2026, the Texas Water Development Board added cybersecurity to scoring in its Intended Use Plan for the Drinking Water State Revolving Fund: two questions on the Project Information Form now carry five priority points—one asks whether the governing body adopted a cybersecurity awareness plan in the last five years, the other whether the project fixes a deficiency found in a cybersecurity assessment. In Waco (population 145,000), the city segmented five treatment plants—four drinking water and one wastewater—in 43 days against a 90‑day goal. There was no bond and no capital request; the utility director used operating accounts and a contract already on the city’s books rather than an RFP. That choice—funding from an operating line that can be approved this quarter instead of waiting for a bond cycle—made the work fast and possible.

Project Watershed 250, state help, and assistance for the smallest systems

States and federal offices are stepping in with programs and pilots. New York adopted water cybersecurity rules in March with grants and free technical support. Texas has stood up a Cyber Command with a water and wastewater mandate. On Monday in San Antonio, Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250, a six‑month pilot that brings Texas Cyber Command, the National Cyber Director’s office, the EPA, CISA and about a dozen private cybersecurity and technology companies to support Texas water utilities. Participating systems receive red‑team testing, vulnerability assessments and hardening assistance at no cost, with plans to scale the model nationwide after the pilot. For the smallest systems, DEF CON Franklin and the National Rural Water Association have mobilized volunteers and five managed detection providers.

What this means for CIOs, city managers, and small utility operators

  • CIOs and CISOs: name one position accountable for every device on the utility network and put it in writing; simulate segmentation before enforcement and adopt the operating rule that “being on the network allows a device nothing” — plant controls should speak only to their SCADA server and everything else should be denied unless explicitly allowed.
  • City managers and councils: funding mechanics matter—operating lines, existing contracts and project scoring in state Intended Use Plans can enable faster fixes than waiting for bond cycles.
  • Small utility operators: reach out to available programs immediately—Project Watershed 250 for Texas systems, or volunteer and managed detection support through DEF CON Franklin and the National Rural Water Association for the smallest systems.

Two nontechnical decisions most often stand between a small utility and exposed controllers—who is accountable for the whole network, and where the funding comes from. Both can be resolved this fiscal year using ordinary budget mechanics already described in the source material; matching a year of carrier invoices to devices and naming one accountable position cost little beyond time. Those are the first steps that, in the author’s experience, finally make measurably different protections possible.

https://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/