HullChaser

America's Water Systems Under Attack

· outdoors

Water Under Attack: America’s Vulnerable Infrastructure

The recent wave of cyberattacks on American water facilities serves as a stark reminder that our supposedly robust infrastructure is woefully unprepared for hybrid threats. These attacks target the very systems keeping us alive – water treatment plants, hospitals, and financial networks – leaving us vulnerable to malicious actors.

The incident in Braham, Minnesota, where public works crews restored service within 90 minutes, is an encouraging anecdote, but it’s a Band-Aid solution for a problem that requires systemic change. The Biden Administration and the EPA have sounded the alarm on possible cyberattacks, but their warnings have largely fallen on deaf ears.

In contrast, our European allies are light-years ahead in hardening their systems through “total defense” initiatives. Finland and Estonia offer instructive examples of what a whole-of-society approach to homeland security looks like. Their strategies prioritize public-private partnerships, information sharing, and resilience-building exercises.

The US can learn from these models by adopting a comprehensive approach that includes public-private partnerships, information sharing, and resilience-building exercises. However, Washington’s response has been woefully inadequate. The Trump Administration’s gutting of cybersecurity capabilities has left our critical infrastructure vulnerable to attack.

Cutting nearly a third of the federal cyber agency’s workforce at a time when small utilities need it most is akin to removing fire departments from major cities. Renewing the State and Local Cybersecurity Grant Program would be a good starting point, but making it permanent and allocating a significant share for water treatment plants is merely a drop in the bucket.

We need more than just grant programs; we need a fundamental shift in our approach to homeland security. One step in the right direction would be setting response floors for water municipalities – measured not in dollars or technology standards, but in hours. If electric utilities can operate under binding federal cyber standards, why shouldn’t water treatment plants have equivalent protections?

The EPA should be given authority to impose time-based standards, such as requiring every system above a modest size to be able to run manually for 72 hours and demonstrate it through annual drills. This would ensure that critical systems remain operational even in the face of a cyberattack.

However, this is just a starting point. We need to build the bench of skilled professionals capable of responding to these threats. With over 50,000 small water systems in the US, most lacking dedicated IT staff, governors can act quickly by leveraging existing resources – cyber teams within the National Guard on standing state active duty orders.

A country that can afford 11 aircraft carriers can certainly afford to train its water operators to turn a valve by hand. Resilience is not a consolation prize for failed deterrence; it’s a powerful tool in itself, forcing adversaries to think twice about whether an operation will succeed. The recent cyberattacks on American water facilities should be a wake-up call – a stark reminder that our infrastructure is more vulnerable than we’d like to admit.

It’s time for Washington to take concrete steps toward creating a whole-of-society approach to homeland security, rather than simply responding to crises after they’ve occurred. The future of America’s critical infrastructure depends on it.

Reader Views

  • TT
    The Trail Desk · editorial

    The Biden Administration's warnings about cyberattacks on America's water systems have yet to inspire meaningful action. One crucial aspect missing from the conversation is the role of state and local governments in facilitating public-private partnerships to address this crisis. By empowering regional stakeholders with resources and expertise, we can create more agile responses to emerging threats. Without this shift in approach, we risk perpetuating a patchwork system that's merely treating symptoms, not fixing the fundamental vulnerabilities within our infrastructure.

  • JH
    Jess H. · thru-hiker

    What's really missing from this conversation is any consideration of just how underfunded and understaffed many water treatment plants already are. I've hiked through rural America, passing by towns where the plants are barely scraping by on aging equipment and skeleton crews. If we're not careful, this cyberattack vulnerability could be just a symptom of a deeper infrastructure crisis – one that no amount of grant programs or public-private partnerships can fix without a serious injection of resources into these neglected systems.

  • MT
    Marko T. · expedition guide

    We're talking about the water we drink and the air we breathe being held hostage by cyber threats. It's not just about patching holes in our infrastructure, but fundamentally rethinking how we protect critical systems. Public-private partnerships are essential, but let's be real – without clear legislation and dedicated funding, these initiatives will remain pie-in-the-sky concepts. Washington needs to take a hard look at the State and Local Cybersecurity Grant Program and actually invest in it, not just tweak it for PR purposes.

Related articles

More from HullChaser

View as Web Story →