Hack Attacks on Water Systems
Main audience: USA people

Cyber attacks recently occurred on the control systems of water utilities in at least a dozen USA states. Newsweek’s coverage said more than anything I saw in the UK about exactly what was done. Relying on an alert from the FBI, they said “internet-facing” Programmable Logic Controllers (PLCs) were hacked to modify IP addresses and passwords.
This tells me a lot. Process control is one of my specialties.
Layers of computers run a modern factory, refinery, water treatment plant, waste water treatment facility, etc. PLCs are small, fast computers. Each one is dedicated to tending a limited amount of machinery so it can keep a close eye on everything the equipment does and raise alarms or send adjustments to machinery quicker than the blink of an eye whenever something changes. PLCs concentrate on doing that job. They don’t have resources to spare for much of anything else, including cyber security which tends to be basic.
Best practices at my client sites include protecting PLCs (and their bigger cousins Distributed Control Systems) by keeping them behind a firewall. It’s more sophisticated than the one that runs on your personal computer as part of your security software. Only people and computers with explicit permission can get behind the firewall where they can communicate with the PLCs. To hack into those PLCs, first it’s necessary to hack through the firewall.
There are more steps a site can take to protect its process control systems from intrusion, but that’s enough to give you the general picture.
For decades, people who understand computerized process control systems have fretted about vulnerability of process control systems at water utilities across the USA. Many water utilities are small and don’t have deep pockets. Their IT isn’t the best. They can’t afford to upgrade it often. If they don’t have a firewall to protect their PLCs and DCSs, or if it’s outdated or its setup has any flaws, hackers can reach those systems and bash through their weak built-in security.
Even at larger water utilities, it’s easy to see IT security as secondary to physical security to ensure water supplies are not contaminated. Nobody has a delusion that they can manage and do quality control manually on a tablet press churning out a tens of thousands of tablets per hour in a pharmaceutical factory. It’s more tempting to believe water pumps and relief valves, which don’t run at breakneck speeds, can be overseen and operated manually if anything goes wrong with process control systems.
I’m not happy about cyber attacks on water systems, and not happy that some of those systems had to fall back on manual procedures (which means the attack got through there). But it is not much of a surprise and disruptions triggered by the hackers were not severe.
Cyber attacks on power grids would have larger effects. Power utilities interconnect. Power distribution in the USA is so complex, manual procedures cannot be quick enough for some of the adjustments that have to be made to keep it all operating. When a portion of a grid goes down, with a little bad luck it can have a ripple effect, taking down adjacent grids. Remember the whopper of an outage in Spain? Bad things can happen quickly and spread quickly.
This bundle of cyber attacks went for an industry that is a relatively soft infrastructure target where harm would be limited.
It was a warning.
But by whom and for what purpose?
I don’t yet trust anything I have seen or heard about who did the attacks. Nearly everything I hear blames Iran. Was it Iran? Maybe—in which case this was a warning, a message that Iran is capable of directly affecting people who live in the USA if the USA continues to bomb people who live in Iran. They have appropriate expertise.
However, it could have been done by some other nation for reasons only they know, such as goading the USA to spend more military resources and government attention in the Middle East to keep attention away from somewhere else.
For that matter, it could have been done by the current regime in the USA as a false flag operation easily blamed on Iran to justify continuing to wage war there.
Water systems getting hacked has been anticipated for years. How to harden utility IT systems against hackers is reasonably well understood.
Who did it and why will cast more light than technical details of how it was done. If we are patient and don’t jump to conclusions before enough evidence emerges, whoever did it may eventually tip their hand. Then we can see what else needs to be done besides beefing up cyber security.


We think of attacks by foreign entities as arriving by way of planes or missiles or even ships, which could happen. Attacking by means of disrupting or contaminating water supplies, however, can also have a devastating effect without the attacker taking the risk of an assault by air, land or sea. Who did it? Who knows? How do we retaliate against an unknown enemy? And what devastation! One thing we must have is drinkable water. Of course, the culprit could be a native with a grudge or a warped sense of humor. In any case, this is alarming.