Weaknesses most commonly linked to this summer's water attacks: 2 (Source: WaterISAC's Tom Dobbins, via CyberScoop (September 30, 2026))
Equipment that works is the problem
Most security failures start with something broken. In water utilities, the trouble is equipment that has not broken. The computers that run water treatment were engineered to last for years. Exposure to the internet was never part of the design brief. Tom Dobbins leads the Water Information Sharing and Analysis Center (WaterISAC). He told CyberScoop that this legacy is now one of the sector's easiest openings for attackers.
The idea worth taking from this story is simple. Reliability can turn into risk. A machine that keeps doing its job removes the reason to replace it. Dobbins said the equipment still works and still has value. So utilities have little incentive to upgrade it.
Think of a house with wiring from the 1950s. The lights come on, so nobody rewires it. The wiring suited the world it was built in. That world has changed.
One caveat matters. Age alone is not the entry point. The report ties the risk to old systems that can be reached from the internet.
What happened this summer
Cyberattacks on the water sector grew this summer, according to CyberScoop. Dobbins named two weaknesses that were most often linked to those attacks. One is operational technology (OT) exposed to the internet. The other is vulnerable programmable logic controllers (PLCs).
He said PLCs have been the "main point of entry" for hackers across the sector. Dobbins also said attackers are stepping up their activity while the U.S. is engaged in several conflicts abroad.
Who was behind the attacks is disputed. CyberScoop reports that the U.S. government is believed to blame Iran. President Trump has questioned that. Dobbins pointed to a CISA release naming Iran. He added that CISA has raised possible threats from Russia and China as well. The defensive steps below do not depend on who is right.
How the weak points work
OT is the hardware and software that run physical processes, such as pumps and valves. A PLC is a small industrial computer that carries out those instructions. Many were made before cyber threats were a concern. Dobbins said they date from a "simpler, gentler time."
The risk grows when such a device can be reached from the internet. Anyone who finds it can try to talk to it. Dobbins said older systems like these should not be accessible from the internet.
He named further weak points across the sector. The report does not link these to this summer's attacks.
The first is integrators, the outside firms that install and support control systems. Suppose an integrator has a link into an OT system that is not managed separately. Dobbins said an attacker could come in through that firm.
The second is employees. A good employee trying to do the right thing can still click a malicious link in a phishing email.
The third is basic hygiene at smaller utilities. Dobbins said it can be hard for them to keep up with changing passwords and adding multifactor authentication.
Who is stretched thinnest
Many observers see water as behind other sectors on cyber defense. CyberScoop points to money and technology limits. Smaller utilities also find the basics hard to keep up. Large and small utilities can face the same threat actors.
WaterISAC is responding by sharing threat information faster. It announced a partnership with Cyware on Wednesday to use Cyware's threat intelligence platform. Dobbins said Cyware was chosen partly because it already works with other industry sharing groups. Cyware's Tom Stockmeyer said the deal would enable sharing across sectors.
Better sharing helps defenders learn faster. It does not take an exposed controller off the internet. The report does not say how many utilities have exposed equipment. The size of that gap is unknown.
What leaders should ask
The lesson reaches beyond water. Any organization that runs physical systems may hold equipment that works and is therefore never replaced. That includes factories, buildings and logistics operators. Five questions follow from the report.
Which control systems can be reached from the internet, and does anyone own that list? If the answer is unclear, that is the first finding.
Which contractors have links into operational systems? Are those links managed apart from everyday IT access?
Do the people who run older systems use multifactor authentication and unique passwords? Dobbins named these basics as a struggle for smaller utilities.
Where equipment cannot be replaced soon, what keeps it off the internet in the meantime?
Does the organization belong to the sharing group for its sector, and does someone read what arrives?
Durable equipment saves money until the day its age becomes the way in.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CyberScoop.





