Introduction
In an era where cyberattacks are becoming increasingly sophisticated, the security of critical infrastructures is more crucial than ever. According to Paul Nakasone, former NSA chief, water system controllers should never be connected to the Internet. This statement follows suspected Iranian attacks targeting essential US infrastructures.
The Current Threat Landscape
In July 2026, the FBI revealed that at least 12 US states had their water systems hacked. These attacks targeted operational technologies, notably programmable logic controllers (PLCs). These devices, essential for managing water levels and pump controls, are prime targets for cybercriminals.
Private sector researchers, like Cynthia Kaiser from the Halcyon Ransomware Research Center, attribute these attacks to Iran-linked actors. Although the US government hasn't officially blamed Iran, the history of previous attacks supports this hypothesis.
Why Water Systems Are Vulnerable
US water systems are often underfunded. With limited resources, these infrastructures lack dedicated cybersecurity personnel. Moreover, the diversity of facilities makes protection complex. In 2025, a GAO (Government Accountability Office) report highlighted that 60% of water facilities didn't have a formal cybersecurity plan.
The Dangers of the Internet of Things (IoT)
The increased connectivity of IoT devices in water systems heightens vulnerabilities. In 2023, a Gartner study predicted that by 2027, over 75% of critical infrastructures will use IoT devices for automation. However, these devices are often deployed with minimal protection, making water systems easy targets.
Possible Solutions
Network Segmentation
One of the recommended solutions is network segmentation. By isolating critical systems from publicly accessible networks, companies can significantly reduce the risk of intrusion. In 2024, a SANS Institute study showed that 70% of companies that segmented their networks saw a reduction in security incidents.
Regular Updates and Patching
Regular system updates and patching are essential. Tools like vulnerability scanners can help identify flaws before they are exploited.
Training and Awareness
Training staff on cybersecurity best practices is crucial. A Cybersecurity Ventures survey in 2025 revealed that 95% of successful cyberattacks were due to human error.
Conclusion
Paul Nakasone's statement highlights a critical issue: the need to protect our essential infrastructures. Companies must act swiftly to implement robust and proactive security measures.
Let's discuss your project in 15 minutes.