In our recent post on the Michigan water attacks, my colleagues at Inversion6 laid out the practical response all businesses should be taking. I'd endorse every word of it — map your exposure, get OT off the open internet, treat this as real risk management.
That advice stands. What I want to add is the part that occupies my attention as a threat intelligence guy: these attacks were as much about being seen causing trouble as they were causing trouble.
In most of these cases, the attackers got inside the perimeter, and then… not much happened. To a lot of people that reads as luck, or incompetence or good defense. But it can be read a different way. When a capable adversary establishes presence and chooses not to pull the trigger, the presence is probably the main message.
These operations are built to make people nervous. They're built to grab headlines. And they're built for political effect. Hack a water utility in Michigan and you instantly get population that feels a little less safe and a news cycle that carries your message free of charge.
Critical infrastructure is the perfect stage this psy-op due to the overall poor state of cyber hygiene. An easy hit validates the story the adversary wants to tell: We are soft, they are strong and everyone should take their capabilities seriously. It plays to an audience closer to home, too. A successful operation impresses their proxies and sympathizers who want to believe (insert adversary here) is a power that reaches far past their borders and can operate on par with the big rivals.
We've seen this play before. Volt Typhoon and the wider set of Chinese intrusions into American critical infrastructure were about exactly this kind of pre-positioning and psychological pressure. In my read, Iran is running essentially the same playbook: get inside, get noticed and chip away at public confidence that our institutions can actually stand up to a determined nation-state — whether that's Iran, North Korea, Russia or China.
And there's a cost to us even when nothing breaks. Every one of these events forces a response, and responding burns resources — materially and psychologically — on the defender's side. That's the elegance of it, from their chair. Signaling that you could do damage is often a more powerful weapon than the damage itself.
So how should security and business leaders hold all this? Two things.
Inversion6 helps organizations translate threat intelligence into a defensible plan — mapping OT and IoT exposure, standing up continuous threat exposure management, and building the response capability to act when posturing turns into damage.