August 4, 2026 12:56 pm

Cyber attacks open a window for reform

It finally happened.

After years of isolated incidents, last month a wave of cyberattacks, likely of Iranian origin, struck U.S. water utilities. Almost all of the victims were small municipal water systems.

For more than fifty years, water sector leaders have recognized that organizational fragmentation is a systemic challenge for safe drinking water in America. The evidence is clear: despite the noble efforts of small system operators, larger utilities deliver better service, maintain greater regulatory compliance, operate more sustainably, are more affordable, and are less vulnerable to cyberattack. Yet American drinking water remains staggeringly fragmented, with tens of thousands of water utilities operating more than 50,000 community water systems.

Decades of white papers, policy reports, blue ribbon committees, and peer-reviewed scientific studies have spotlighted the problems of fragmentation and the blessings of consolidation. All that illumination hasn’t brought enlightenment.

But last month’s cyberattacks left the water sector singed…

…and maybe finally ready for reform.

TL:DR

Foreign cyberattacks exposed an alarming truth: America’s fragmented water sector is dangerously vulnerable and puts lives at risk. Consolidation is now a national security imperative. If decades of data didn’t persuade us, maybe cyberterrorism will.


What happened

Thousands of small, perennially under-resourced municipal water systems run on internet‑exposed Programmable Logic Controllers (PLCs), legacy SCADA systems, and insecure remote access tools. Without in-house expertise, small utilities rely on vendors, contractors, and consultancies for technology implementation. In the most recent attacks, multiple victims had nearly identical network setups installed by such third‑party integrators. Thin, overworked staff used default settings, shared credentials, and simple passwords; no VPNs, no multi-factor authentication, no segmentation, no firewalls.

This summer’s cyberattacks were not sophisticated; our enemies didn’t need elite cyber ninjas to take down community water systems. They needed Shodan, a working knowledge of default passwords, one lazy or gullible phishing target, and a free afternoon.

My first faculty job was at Colgate University, a small liberal‑arts school. Even twenty years ago, Colgate had stronger cybersecurity protocols than many (most?) small water utilities have today. That’s not an indictment of small system operators; it’s the reality of organizational scale. Our college with 2,800 students had a cybersecurity team; a water system serving 2,800 people probably has one or two operators, a part‑time clerk, no IT staff, and a SCADA system installed in the 1990s by an guy who retired five years ago.

Our foreign adversaries went hunting for soft targets, and oh boy did they find some.


Cue the takes

Earlier this week, a New York Times Op-Ed by Jen Easterly used these attacks to argue for more federal investment in cybersecurity. She decries the Trump Administration’s Cybersecurity and Infrastructure Security Agency (CISA) rollbacks, and argues that CISA’s voluntary federal programs “reduced the risk of a cyberintrusion becoming a public-health catastrophe.” It stands to reason that a former CISA leader and current cybersecurity industry executive thinks more federal bureaucracy and more federal dollars are the solutions. 

With respect, Easterly misdiagnoses the problem and comes to the wrong solutions. The vulnerabilities exploited in these attacks were structural: the predictable consequences of a water sector riven by fragmented governance and chronically weak capacity. Federal agencies can conduct tabletop exercises, issue advisories, and shovel out grant money.* But Uncle Sam’s wallet can’t secure a utility with one operator, zero cybersecurity staff, and technology that predates the iPhone. 


The real problem

Small utilities do heroic work with limited resources; they simply cannot meet cybersecurity threats posed by online actors with bad intentions. Beyond their bigger rate bases, a large utility has wide expertise and a deep bench that a small utility never will. What if a cyberattack hits when your operator is sick? Or on vacation? Or asleep? What if the only person who knows how to reboot the SCADA or close a valve manually is at a dentist appointment?

More than technology, cybersecurity is about organizational capacity. No bag of grant dollars, no tech bulletin newsletter, no platoon of circuit riders can defend small water systems from cyberattack sustainably. If a utility’s entire staff can ride to work in a Honda Civic, it’s not ready for 2026.


A Focusing Event?

Political scientist John Kingdon argued that major policy change often follows a focusing event: a high-profile crisis that puts a longstanding problem on the national political agenda. A focusing event can open a “policy window,” a brief period when politically difficult policies suddenly become actionable. The water sector has  seen some notable focusing events over the years: the Cuyahoga River Fire inspired the Clean Water Act; the 1993 Milwaukee Cryptosporidium outbreak triggered new microbial contaminant rules and helped drive the 1996 Safe Drinking Water Act Amendments; the Flint Water Crisis led to a new Lead & Copper Rule and $15 billion in funding for lead service line replacements. None of those disasters produced meaningful consolidation.

Cybersecurity is different, because small water utilities’ capacity problems are now national security problems—in the middle of an international armed conflict. Today small water system cybersecurity is politically salient in a way that rate structures and asset management are not. The consolidation window is open.


Now do you believe?

My work indicates that utility organizations serving at least 20,000 connections (population of around 50,000 or more) can achieve the organizational economies of scale for water system success. Organizational consolidation isn’t a panacea (nothing is!), but it’s a necessary step toward ending the vulnerabilities exploited in last month’s attacks. Larger utilities can retain cybersecurity professionals, replace legacy technology, enforce password policies, deploy multi-factor authentication, and monitor ongoing vulnerabilities. These are not luxuries—they’re prerequisites for operating critical infrastructure today.

Mountains of data demonstrate that consolidation can improve affordability, sustainability, performance, resilience, and regulatory compliance. All that evidence hasn't been enough to get us there. But foreign adversaries have discovered just how easy it is to compromise small utilities and threaten the health and livelihoods of the people who they serve. The water sector’s fragmentation is a national security liability. Stubborn, parochial resistance to consolidation puts small town Americans’ lives at risk in a time of war.

If decades of data won’t drive consolidation, maybe the reality of cyberterrorism finally will. Some find religion when they see the light, some when they feel the heat.



*The overworked, part-time clerk administering that small town utility probably isn’t going to apply for a federal cybersecurity grant.

Apologies to Ray Wylie Hubbard.

Leave a Reply

Your email address will not be published. Required fields are marked *

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}

Citations are the lifeblood of my profession.
Please use my work - and reference it when you do.