The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

The Water Is Essential. The Locks Are Plastic.

Marcus Webb
2026-08-07
# The Water Is Essential. The Locks Are Plastic. Energy & Utilities is sitting at #4 on the targeting table this week. With 97 stories in seven days, it's a sector that usually drifts into the background of my notes until something breaks in the physical world. Usually, we spend our time arguing over whether a CVSS 8.8 actually deserves its rating or if a vendor is lying about a "fix" that only mitigates a symptom. But the current activity suggests a different problem. It isn't a failure of patching; it's a failure of basic physics. The wire is currently dominated by a series of reports on US water systems. Two municipal water systems in New Jersey were hit recently, and CBS News is reporting that wide swaths of the nation's water infrastructure are essentially unguarded. We love to use the phrase "Critical Infrastructure." It sounds imposing. It implies a level of fortification and federal oversight. In reality, it often describes a PLC controller running firmware from 2012, connected to a network that hasn't seen a firewall rule change since the Obama administration. The evidence is in the attribution. Iran has appeared in 10 stories this week across various sectors, with a specific focus on these water utilities. When state actors target municipal water, they aren't looking for credit card numbers or a quick payout from a ransomware demand. They're mapping dependencies. They're testing how long it takes for a local government to realize their chemical dosing levels have been altered. The argument usually goes like this: OT (Operational Technology) is too fragile to secure. The engineers claim that if you run a vulnerability scanner against a 20-year-old pump controller, the whole system will crash and the town will lose pressure. They argue that patching is impossible because the downtime required for a reboot isn't an option in a "critical" service. That's a convenient excuse for laziness. If a device is too fragile to be patched or scanned, you don't leave it on a public-facing IP with default credentials. You isolate it. You air-gap it. You put it behind a jump box that actually requires MFA. The "fragility" argument is often used to justify why the locks are effectively made of plastic. This reminds me of the Colonial Pipeline mess from a few years back, though the parallel breaks down at the objective. Colonial was primarily an IT failure, involving a leaked password and a lack of MFA on a VPN, that forced an OT shutdown for safety's sake. What we're seeing now in the water sector is more direct. Attackers aren't just hitting the billing department; they're knocking on the door of the actual machinery. There's a second-order effect here that most people are ignoring. Everyone focuses on the water utility itself, but look at the targeting table again. Healthcare is currently #3 with 132 stories this week. A hospital cannot function without clean, running water. If you compromise the municipal supply for a city, you've effectively neutralized every clinic and surgical center in that zip code. You don't have to breach the hospital's EMR system if you can just turn off their taps. We can contrast this with the Technology sector, which remains #1 with 343 stories this week. In Tech, the volume is high because the attack surface is infinite and the rewards are digital. It's a game of version numbers and zero-days. But in Utilities, the reward is leverage. If you want to know if things are actually improving, stop reading the press releases about "enhanced cooperation" between federal agencies and local municipalities. Instead, look for how many of these water systems are actually moving their controllers off the public internet. Until then, we're just waiting for a report that tells us someone changed the chlorine levels in a mid-sized city because they forgot to change 'admin/admin'.
◼
← More from the Desk Live Wire →

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.