🤚 The Open-Palm Valve
Retired General Paul Nakasone, the former NSA chief, used DEF CON to say the quiet infrastructure sentence out loud: water system PLCs should not be connected to the internet. According to The Register, the warning followed attacks on water systems in at least 12 US states, with investigators and private-sector researchers looking closely at suspected Iran-linked activity.
A programmable logic controller, or PLC, is one of those unglamorous little boxes that makes civilization happen without asking to be followed on LinkedIn. It watches tank levels, opens valves, turns pumps on and off, and generally performs the industrial equivalent of keeping everyone from drinking municipal regret. Naturally, humanity connected some of them to the internet, because no tragedy is complete until remote access has entered the chat.
The FBI said in late July that it was investigating attacks by malicious cyber actors targeting operational technology devices, including PLCs. The Register notes that Iran-linked crews have targeted such devices for years, and that some private researchers suspect Iranian intruders are behind recent disruptions at water and wastewater facilities. Official attribution remains measured; the risk, however, does not wait politely for a press conference.
👐 The Two-Handed Treatment Plant
Water systems are a particularly cruel cybersecurity problem because they are essential, local, fragmented, and frequently underfunded. A bank can hire a red team and still complain about budget season from a glass tower. A small utility may be protecting pumps, chlorination, telemetry, billing, and public trust with three people, a maintenance truck, and a firewall last updated during the moral panic over QR codes.
This is not merely about hackers being clever. It is about defenders being structurally exhausted. Operational technology was often designed for reliability and safety first, then retrofitted for connectivity because remote management looked economical, convenient, and sufficiently magical at the time. The problem with magic is that it tends to come with a portal.
Once industrial control equipment is reachable, misconfigured, poorly segmented, or guarded by weak credentials, the attacker no longer needs cinematic sophistication. They need patience, reconnaissance, and the institutional negligence buffet that modern infrastructure keeps accidentally catering. The result is not just stolen data; it is the possibility of disrupted pumps, altered settings, unavailable treatment processes, and public officials explaining why the water plant briefly became an internet-of-things escape room.
🌿 The Gentle Awakening
There is a broader lesson here that security professionals have been trying to tattoo onto procurement forms for decades: connectivity is not automatically modernization. Sometimes it is just exposure with a dashboard. A PLC connected to the public internet is not “smart infrastructure.” It is a civic asset standing on a balcony during a drone convention.
The defensive basics are not mysterious. They are merely unfashionable, operationally annoying, and therefore easily neglected until a hostile actor discovers the facility’s remote access panel before the budget committee discovers the maintenance backlog.
- Remove direct internet exposure for PLCs and other operational technology wherever possible.
- Segment OT from IT networks so a compromised email account does not become a pump-room invitation.
- Use strong authentication and monitored remote access, especially for vendors and maintenance connections.
- Patch and inventory assets, because you cannot defend the mystery box under the server rack.
- Plan incident response for physical operations, not just laptops and policy PDFs.
Nakasone’s comment lands because it is not a novel strategy. It is a return to physical common sense. If a device controls water, it should not be lounging around on the internet like a bored intern waiting to click a phishing link.
👑 The Gold-Leaf Reckoning
The luxury version of national security is not a new threat-intelligence portal with brushed-metal typography. It is making sure the machinery that handles water, power, hospitals, transportation, and food processing is not administered like a forgotten WordPress plugin from 2014.
Attacks on water systems are not glamorous in the way espionage campaigns and zero-day auctions can be glamorous to people who have made poor lifestyle choices. They are worse: they are intimate. They touch taps, neighborhoods, schools, hospitals, and the primitive social contract in which citizens expect the fluid emerging from municipal pipes to remain boring.
If suspected state-linked actors are probing these systems, the answer cannot be a press release scented with resilience. It has to be funding, standards, segmentation, training, visibility, and the long overdue retirement of internet-facing industrial equipment from its career as a public monument to optimism.
Water is civilization’s most basic premium service. Perhaps we might stop managing it like a beta feature.
“Your pump controller has accepted a connection request from geopolitics.” — The Slap of Wisdom Department of Municipal Humility, standing beside a valve that should never have had a public IP address