Skip to main content
Threat IntelligenceEmerging Threats

Water Sector Grapples with Cyber Threats as Attacks Persist

Water utility workers monitor industrial control systems and machinery in a treatment plant control room.

"We have been under attack, and our enemies, the threat actors, are stepping up their activity as the U.S. is involved in a number of conflicts around the world," Tom Dobbins, executive director of the Water Information Sharing and Analysis Center (WaterISAC), told CyberScoop.

Tom Dobbins and WaterISAC’s assessment of the summer attacks

Dobbins framed the sector’s summer experience as a wake-up call: cyberattacks mounted against water facilities exposed long-standing technical and organizational gaps. He said the U.S. government reportedly believes Iran was behind this summer’s water facility attacks, though he noted that the president disputed that attribution despite alerts from the Cybersecurity and Infrastructure Security Agency (CISA). Dobbins also identified China and Russia as potential sources of threat activity, saying CISA had warned of potential threats from those nations as well.

Exposed operational technology and PLCs as primary weak points

At the core of WaterISAC’s warnings are two repeatable, concrete vulnerabilities: internet-exposed operational technology (OT) and programmable logic controllers (PLCs). Dobbins told CyberScoop that exposed OT “are a major challenge,” and that PLCs represent an “obviously” vulnerable point. He said PLCs have been the “main point of entry” for hackers in the sector, in part because much of the equipment was developed “pre-cyber threats and activities” and remains in use because it is still operational.

Those two vulnerability classes — OT exposed to the internet and aging PLCs — were the ones most commonly linked to the summer attacks, according to Dobbins’ assessment shared with CyberScoop.

Integrators and employees: the external and internal vectors

Dobbins highlighted two operational channels by which attackers can reach water systems. Externally, integrators with remote connections into OT provide a pathway: “If those integrators are working and they have a connection into an OT system that’s not managed discretely, then a threat actor can come in through an integrator and get into a system,” he said. Internally, otherwise well-intentioned employees can trigger intrusions through phishing — opening a malicious link can hand attackers access.

He also pointed to basic cyber hygiene gaps at smaller utilities — changing passwords and implementing multifactor authentication — as persistent shortfalls that increase exposure.

WaterISAC’s Cyware partnership to speed threat sharing

To accelerate information flow across the fragmented water sector, WaterISAC announced a partnership with Cyware to use the company’s threat intelligence platform. Dobbins said Cyware was selected in part because of its existing relationships with other industry information sharing and analysis centers (ISACs). Tom Stockmeyer, managing director of government and critical infrastructure at Cyware, said the company is “thrilled to add water to the portfolio and start enabling cross-sector sharing.”

WaterISAC already works with the National Rural Water Association to serve 20,000 of the sector’s smallest utilities; Dobbins said Cyware’s platform would help WaterISAC analysts and support faster sharing of actionable intelligence across that broad membership base.

What this means for small utilities, CISA, and integrators

  • Small utilities: The National Rural Water Association partnership means WaterISAC is explicitly focused on the smallest systems, where Dobbins says basic cyber hygiene is often the hardest to maintain. Those utilities are likely to be prioritized for guidance and threat feeds through the new Cyware-enabled sharing arrangements.
  • CISA: Dobbins pointed to CISA’s public alerts on the summer incidents and suggested the agency’s technical expertise is central to attribution and warning — even as attribution statements prompted public pushback from the president.
  • Integrators: Because integrator connections can serve as a route into OT, integrators will be a focal point for defensive attention. Dobbins’ comments underline the need for clearer controls around third-party remote access and discrete management of integrator connections.

WaterISAC’s narrative is stark and tightly focused: aging, internet-exposed OT and legacy PLCs, combined with insecure integrator links and uneven cyber hygiene at small utilities, were the avenues most commonly associated with this summer’s attacks. The organization’s new Cyware partnership is a tactical response — designed to speed sharing and triage the sector’s many small, resource-constrained members — but the underlying picture Dobbins paints is structural: many systems were built before cyber threats were prominent and remain in service because they still work. Whether faster intelligence sharing will be enough to blunt repeat incidents will depend on how quickly those technical and operational gaps are addressed.

Source: CyberScoop — WaterISAC reckons with range of threats after summer of cyberattacks