As we've covered at Inversion6, water and wastewater utilities in at least a dozen states have now reported cyberattacks on their operational technology. Minnesota alone has had more than thirty facilities affected.
As the former CISO for the state of Wisconsin, I spent two years trying to address this problem. I mostly failed. Here's why.
I became Wisconsin's CISO in 2023. That same year, the Environmental Protection Agency (EPA) made a rule requiring a cybersecurity review as part of the sanitary surveys each state already conducts on public water systems. States and water industry groups immediately sued, arguing the agency had exceeded its authority and mandatory audits would impose a heavy cost on small towns and private operators.
So, the EPA withdrew the rule, instead making cybersecurity assessments a "strong recommendation."
Next, we tried persuasion. Working with the CIO and CISO at the Wisconsin Department of Natural Resources, we asked facilities to let the state help them assess where they stood. We didn't want to punish anyone. We just wanted to give operators good documentation they could use to build a case for more funding and resources.
Most said no, even to "free" federally funded assessments via CISA. Wisconsin has more than 600 municipal water and wastewater facilities, and thousands more that are local or privately held. When I left the CISO role two years later, exactly two had registered for the voluntary assessments.
I didn't like it, but I understand the reasoning behind their refusal.
These operators are not ignorant or indifferent to these risks. What they told me, in so many words, is that a list of findings they had no staff or budget to fix was not actually assistance. In their mind, it was just more liability.
Once a vulnerability is documented; someone must answer for it. If the money to address it doesn't exist, then an assessment simply converts an invisible threat into a visible problem, while changing nothing on the ground.
Bottom line, who wants to highlight a problem when there's nobody willing to pay for the solution?
It's frustrating because I know this work can be done, because I've seen it happen. In preparation for the Republican National Convention in Milwaukee, local water and wastewater facilities were tested and controls were put in place. It took months, not years and it happened because there was federal attention, an immovable deadline and resources behind it.
Obviously, we can't create a national political convention in every county across our county.
However, we can do more to make remediation much more realistic as we move forward.
Here's three changes would matter more than any mandate.
I hope these latest attacks prove to be the warning shot that inspires action.
The people running these plants are not the problem. For years they have been asked to document risks that nobody has been prepared to help them remediate.
So far, they have largely refused; and that's a rational response given the circumstances.
To change their answer, we need to change what we're offering.
Inversion6's CISO advisory practice helps organizations right-size security investment to actual risk — building a roadmap where remediation is budgeted, not just documented.