Some companies see cybersecurity as a cost center. We see things a little different. LEARN MORE >

Our seasoned Chief Information Security Officers bring strategic guidance to your leadership team, helping you right-size your cybersecurity operations.


A full suite of manage solutions from our US-based Security Operations Center (SOC)—staffed 24x7x365 by a full team of experienced analysts.


You can count on our IR team to contain the damage from a cyberattack, investigate the origins of the breach and build better protections for the future.


Why Inversion6

With an abundance of solutions and providers, the task of choosing the right option is critical and can sometimes be overwhelming.

Contact Us
BLOG

The Michigan Water Attacks Were a Message

Here’s How I Read Them

city scape with code above it

Key Takeaways

  • The attackers got inside the perimeter and then did nothing. When a capable adversary establishes presence and chooses not to act, the presence is the message.
  • These operations are engineered for psychological and political effect. Headlines, unease, and a news cycle that carries the adversary's message free of charge.
  • Poor cyber hygiene makes the sector the perfect stage. An easy hit validates the story the adversary wants to tell.
  • We have seen this playbook before. Volt Typhoon and the wider set of Chinese intrusions into U.S. critical infrastructure ran the same pre-positioning approach.
  • There is a cost even when nothing breaks. Responding burns defender resources, materially and psychologically.
  • Two responses: keep cool, and get prepared on the assumption that someone eventually does more than posture.

In our recent post on the Michigan water attacks, my colleagues at Inversion6 laid out the practical response all businesses should be taking. I'd endorse every word of it — map your exposure, get OT off the open internet, treat this as real risk management.

That advice stands. What I want to add is the part that occupies my attention as a threat intelligence guy: these attacks were as much about being seen causing trouble as they were causing trouble.


What Does It Mean When Attackers Get In And Do Nothing?

In most of these cases, the attackers got inside the perimeter, and then… not much happened. To a lot of people that reads as luck, or incompetence or good defense. But it can be read a different way. When a capable adversary establishes presence and chooses not to pull the trigger, the presence is probably the main message.

These operations are built to make people nervous. They're built to grab headlines. And they're built for political effect. Hack a water utility in Michigan and you instantly get population that feels a little less safe and a news cycle that carries your message free of charge.


Why Is Critical Infrastructure The Perfect Stage?

Critical infrastructure is the perfect stage this psy-op due to the overall poor state of cyber hygiene. An easy hit validates the story the adversary wants to tell: We are soft, they are strong and everyone should take their capabilities seriously. It plays to an audience closer to home, too. A successful operation impresses their proxies and sympathizers who want to believe (insert adversary here) is a power that reaches far past their borders and can operate on par with the big rivals.


Have We Seen This Playbook Before?

We've seen this play before. Volt Typhoon and the wider set of Chinese intrusions into American critical infrastructure were about exactly this kind of pre-positioning and psychological pressure. In my read, Iran is running essentially the same playbook: get inside, get noticed and chip away at public confidence that our institutions can actually stand up to a determined nation-state — whether that's Iran, North Korea, Russia or China.


Is There A Cost Even When Nothing Is Damaged?

And there's a cost to us even when nothing breaks. Every one of these events forces a response, and responding burns resources — materially and psychologically — on the defender's side. That's the elegance of it, from their chair. Signaling that you could do damage is often a more powerful weapon than the damage itself.


How Should Security And Business Leaders Respond?

So how should security and business leaders hold all this? Two things.

  • First, keep cool.
    Fear is clearly a big part of the objective here, so refusing to freak out is itself a form of defense. Take critical-infrastructure security seriously as a matter of national resilience and fund it like you mean it, but don't let every headline control your emotions the way it was engineered to do.
  • Next, get prepared
    Even if fear is the point, it's reasonable to assume one of these bad actors will eventually do more than show off symbolically. That makes the practical hygiene from our earlier post critically important, whether your protecting a small public utility, or a massive public company.


More in this series


Read the signal, then close the gap.

Inversion6 helps organizations translate threat intelligence into a defensible plan — mapping OT and IoT exposure, standing up continuous threat exposure management, and building the response capability to act when posturing turns into damage.

LEARN MORE →