[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9NvlfgicYWBRGdFTWeyQruGYOiDveTRj8SauxYNoSYw":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"e07d9d24-4cec-4cec-b0f5-a2d2ce3da1ee","The US needs a real plan to defend its water systems","the-us-needs-a-real-plan-to-defend-its-water-systems-d567c1","Here’s what it would take: stronger defenses for large utilities, hands-on help for smaller systems and federal support to make both happen. The post The US needs a real plan to defend its water systems appeared first on CyberScoop.","Iranian cyberattacks on US water systems highlight significant vulnerabilities due to poor cyber hygiene, lack of regulatory authority, and the small size of many utilities. Advanced AI further exacerbates these risks by enabling rapid vulnerability identification and attack execution. While some legislative and pilot programs are underway, they may not fully address the systemic issues of cost, complexity, and fragmentation in defending critical water infrastructure.","US water systems face critical cyber threats from nation-states and AI, lacking adequate defenses and regulatory","The summer’s cyberattacks by Iranian hackers on water systems in 12 states underscored how vulnerable U.S. water systems are to foreign adversaries. A broad attack on water infrastructure could have consequences comparable to a public health crisis that impacts the country’s entire population. The threat to water has long been clear. As the 2026 Annual Threat Assessment from the U.S. intelligence community states “Cyber actors from China, Russia, Iran, North Korea, and ransomware groups . . . pose critical threats to U.S. networks and critical infrastructure.” Advances in artificial intelligence have heightened those vulnerabilities. Advanced AI models, such as Anthropic’s Claude Mythos, have demonstrated the ability to identify thousands of zero-day vulnerabilities in critical software systems, including major operating systems and browsers. Other systems, including some developed in China, are demonstrating similar capabilities. AI systems can now “plan, test, and execute attacks in rapid cycles,” ranging from minutes down to seconds. U.S. water systems are vulnerable to cyberattacks for technical, legal and practical reasons. Technical: About 80% of U.S. water systems lack even basic cyber hygiene, a weakness exploited in the summer attacks. Even systems that serve most of the population (approximately 450 large and 4500 medium-sized water systems) have not adopted advanced cybersecurity capabilities used in other sectors where failure can have catastrophic consequences, including aviation, rail, mass transit, medical devices, finance, and nuclear power. Legal: The Environmental Protection Agency lacks clear statutory authority to impose broad cybersecurity requirements on water systems. In 2023, EPA issued a memo interpreting existing regulations to strengthen the cybersecurity of water systems. The action met widespread opposition from the water sector as well as formal legal challenges, and the EPA ultimately withdrew the memo. The agency retains limited authority. It can require water systems to complete risk and resilience assessments, maintain emergency response plans and, in emergencies, address critical cybersecurity flaws. Practical: Most U.S. water systems are small. Some 45,000 serve 3,300 persons or fewer. Because of their size, many fall outside the EPA’s regulatory authority and below the “cyber poverty line,” lacking the funding, staff and expertise necessary for effective cybersecurity. Not surprisingly, the summer attacks drew attention from the administration and Congress. The EPA ,in partnership with the FBI, and CISA each issued guidance on remedial actions, including disconnecting operational technology, from the internet where feasible and adopting robust password practices. Sens. Amy Klobuchar, D-Minn., and Adam Schiff (D-Calif., introduced the Water Safety Shield Act, a bill that would require tiered cybersecurity standards for the water sector and dedicate a proposed $600 million annually to water cybersecurity. It would go beyond earlier, less prescriptive efforts to improve resilience in the sector. The administration has also established a pilot program with Texas and private-sector cybersecurity companies to identify and address water-system vulnerabilities at no cost to utilities. These efforts are well intentioned, but they do not address the underlying causes of the problem. Large and midsize U.S. water systems have long been targets of sophisticated adversaries. China’s Volt Typhoon revealed deep Chinese penetration of critical infrastructure, including water systems, that support national security, economic security, and civil society. Those systems remain vulnerable because many have not adopted well-known protections, such as zero-trust architecture. More fundamentally, the software on which they depend remains vulnerable to exploitation. Policymakers have struggled to respond for two reasons: the cost and complexity of adopting stronger technical defenses, and the highly fragmented nature of the water sector. A relatively small number of large systems serve about half the U.S. population. Roughly 49,000 systems serve the rest, including the 80% of the systems serving 3,300 people or fewer. Those smaller systems serve about 7% of the population. Despite these challenges, the capabilities needed to significantly strengthen U.S. water-system security are well known and widely used in other sectors where failure can be devastating, including those listed above. A five-part federal program could provide high-level cybersecurity for U.S. water systems. Establish stronger technical capabilities. Water systems should adopt zero-trust architecture, which permits only authenticated, minimum-necessary access to resources and segments networks so that a breach in one area does not compromise the entire system. Such architecture could have blocked the unauthorized intrusions used in the summer attacks. Zero-trust systems are already widely used across multiple sectors, and commercial providers can support their adoption. The Department of Defense has certified several companies to provide zero-trust architecture for department components. Water systems should also use formal methods to reduce or eliminate vulnerabilities in software that cannot safely fail. Although the summer attackers did not appear to exploit flaws in the water systems’ code, a high-level adversary such as China would be likely to do so. Formal methods range from “memory-safe” programming languages, which prevent coding errors that leave computer memory open to attack, to rigorous mathematical proofs that verify that software behaves as intended. They also support secure “microkernels,” which strictly separate software functions and make it far more difficult for an attacker to move laterally through a system. Safe code development draws on the principles of formal methods but is a more practical, semi-formal approach. AI tools developed by companies including Google and CrowdStrike can identify and help repair software vulnerabilities, a process sometimes called “code mending.” Water systems should use such tools to defend against advanced adversaries. Developing formally verified code for water systems would not be simple. But much of the software that directs the mechanical operations of water utilities comes from a small group of companies, including Siemens, Schneider, and Rockwell Automation. Those companies have the technical expertise to develop more secure code where it is necessary. Secure microkernels are also commercially available. Support large water systems. Congress should require large water systems to adopt zero-trust architecture, code-mending tools, and formal methods for critical software. The requirements should be phased in over time. The legislation should also provide tax credits to help cover the costs of developing, implementing, and maintaining these protections. Assist midsize water systems. The federal government should establish a program that provides technical expertise and financial support to midsize water systems, including municipal utilities. The program should help them adopt zero-trust architecture, code-mending tools, and formal methods for software development. Midsize systems will likely need a longer phase-in period than large utilities. A federally funded cohort of experts drawn from government and the private sector could provide the necessary support. Regional teams, organized by geography or technical specialty, could address the different needs of different water systems. Create a safe operations posture for small water systems. Few, if any, systems serving 3,300 people or fewer are run by organization with substantial cybersecurity resources. Many cash-strapped systems rely on remote monitoring because on-site service is beyond their budgets. But remote monitoring can create serious risk when industrial devices are exposed directly to the public internet without proper firewalls or virtual private netwo","https:\u002F\u002Fcyberscoop.com\u002Fus-water-system-cybersecurity-ai-threats-op-ed\u002F","https:\u002F\u002Fcyberscoop.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F3\u002F2024\u002F05\u002FGettyImages-1321415832.jpg","2026-10-05T10:00:00+00:00","2026-10-05T12:00:24.240326+00:00",8,[18,21,24,27,30,32],{"name":19,"type":20},"Claude Mythos","product",{"name":22,"type":23},"Anthropic","vendor",{"name":25,"type":26},"Volt Typhoon","threat_actor",{"name":28,"type":29},"AI","technology",{"name":31,"type":29},"zero-trust architecture",{"name":33,"type":20},"Water Safety Shield Act","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":34,"icon":36,"name":37,"slug":38},null,"Policy","policy",[40,45,47,52],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":46},{"id":34,"icon":36,"name":37,"slug":38},{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":53},{"id":54,"icon":36,"name":55,"slug":56},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]