Are US Water Systems Safe from Foreign Cyberattacks?

Are US Water Systems Safe from Foreign Cyberattacks?

Donald Gainsborough stands at the intersection of high-stakes diplomacy and the gritty reality of domestic policy as the leader of Government Curated. With a career defined by navigating the labyrinth of federal legislation, he has become a leading voice on the protection of the nation’s most vital assets. In light of the recent and alarming breaches within the American water sector, Gainsborough offers a sobering perspective on the vulnerabilities that persist within our local utilities. This conversation delves into the systemic failures that allow foreign adversaries to reach into the heart of American communities, the logistical nightmare faced by plant operators during a digital blackout, and the complex geopolitical tensions that ensure there is never a true ceasefire in the realm of cyber warfare.

The following discussion explores the recurring issue of exposed industrial control systems and the policy gaps that hinder a unified defense. We examine the specific operational disruptions in the Midwest, where manual overrides became the last line of defense against potential public health crises. Gainsborough also analyzes the strategic motives behind these coordinated efforts and provides a forward-looking assessment of how the lifecycle of critical infrastructure must be reimagined to survive an era of persistent digital escalation.

Many utilities still leave programmable logic controllers exposed to the public internet despite repeated warnings. What specific systemic failures or policy gaps lead to such critical vulnerabilities remaining unaddressed?

The persistence of these vulnerabilities is a stinging indictment of what some in the industry describe as an “unserious” approach to public health and national security. Even after CISA updated its advisory on July 22, we saw suspicious activity reported by several public water utilities just four days later, between July 26 and 27. The fundamental failure lies in the disconnect between federal guidance and local execution; we have small utilities managing a patchwork of aging equipment that has been stitched together by various contractors over several decades. When a technician is frustrated by the complexity of remote access, they often take the path of least resistance—leaving a programmable logic controller connected to the open web with a default password. It is a heartbreaking reality where the desire for operational convenience outweighs the dire warnings issued in April and again in July, effectively leaving the front door unlocked for any motivated adversary.

The recent breaches in Minnesota saw operators locked out of their own systems, forcing manual intervention. Could you elaborate on the logistical reality of a utility trying to maintain safety when their automated controls go dark?

When the screens go black in a facility like the one in Braham, the atmosphere shifts from controlled automation to a state of high-sensory emergency. On that Sunday and Monday, operators were suddenly severed from the digital interfaces that manage the city’s well and water treatment plant, meaning they could no longer rely on software to balance chemical levels or pressure. They had to step away from their desks and physically navigate the plant to operate valves and pumps by hand, a grueling process that is both labor-intensive and prone to human error. In more than 30 community water systems across the state, the fear of a boil-water notice became a tangible weight, as the disruption of facilities threatened the very access to safe drinking water. While officials reported no immediate impact on water quality, the sight of veteran operators scrambling to manually override digital commands illustrates just how thin the line is between a normal day and a public health catastrophe.

With investigators suggesting these incidents are “aligned” with Iranian cyber campaigns, how should we interpret the timing of these strikes relative to the broader five-month conflict involving regional powers?

We have to understand that in the modern era, there is no such thing as a ceasefire in the digital domain, even when kinetic strikes pause. These Minnesota attacks represent a clear escalation in a campaign that U.S. officials have been tracking since the earliest days of the war, particularly after strikes began in late February. By targeting critical infrastructure like the interfaces in Aliquippa, Pennsylvania, or the 30 systems in the Midwest, these actors are sending a message that they can bypass traditional borders to impact American citizens in their homes. Even as traffic through the Strait of Hormuz sits at a standstill and military strikes fluctuate on a Wednesday or Thursday, the cyber front remains hyperactive because it is viewed as standard procedure. These attacks are not isolated incidents; they are synchronized with a broader geopolitical strategy that includes breaching industrial-control equipment across multiple sectors and even targeting the personal communications of high-ranking officials.

Infrastructure specialists often describe our water systems as a “patchwork of aging equipment.” How does this decades-old complexity complicate the implementation of modern cybersecurity standards across the country?

The complexity of our water and wastewater systems is perhaps our greatest defensive hurdle, as these facilities are often a graveyard of legacy technology and modern upgrades that don’t always communicate well. Cybersecurity cannot simply be an after-the-thought software patch; it must be treated as a core infrastructure requirement that spans the entire asset lifecycle, from initial design and construction through to modernization and eventual replacement. When a utility is dealing with components maintained by a dozen different contractors over 20 years, identifying every internet-connected pump or valve becomes a Herculean task. This structural fragmentation means that a single overlooked device can jeopardize an entire community’s health, making the physical sabotage of equipment a very real and looming threat. To move forward, we must stop viewing these systems as mere utilities and start treating them as the sophisticated, high-risk environments they truly are, requiring the same level of investment as our most sensitive military assets.

What is your forecast for the security of American water infrastructure?

I expect to see a continued and aggressive surge in activity targeting internet-connected programmable logic controllers, as adversaries have now proven they can successfully trigger boil-water notices and disrupt facilities at scale. The trend of “standard procedure” cyberattacks will likely intensify regardless of any preliminary diplomatic agreements, as the digital theater allows for high-impact disruption with a degree of deniability that kinetic warfare lacks. We are entering a period where the “unserious” era of infrastructure management must end, or we will face a scenario where manual operation becomes a permanent necessity rather than a temporary emergency measure. The coming years will see a forced consolidation of smaller, vulnerable utilities into more competent, well-funded entities, as the federal government realizes that leaving public health in the hands of unmonitored, exposed systems is a risk the nation can no longer afford to take.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later