PLCs on the public internet are an open goal for attackers, says ex-NSA chief
Retired General Paul Nakasone, former director of the NSA, had a blunt message at DEF CON this week: stop putting water system controllers on the internet. It's not a complicated ask, but apparently it still needs saying.
The comments come after the FBI confirmed in late July that it is investigating a wave of attacks against operational technology devices at water and wastewater facilities across at least 12 US states. The targets include programmable logic controllers, the industrial hardware that monitors tank levels, manages sensor data, and controls pumps. Unglamorous stuff, but critical infrastructure in the most literal sense.
Iran is the prime suspect, though neither the FBI nor the Trump administration has formally pinned the blame. Private sector researchers are less cautious. Cynthia Kaiser, SVP at Halcyon's Ransomware Research Center, told The Register she would be "shocked if it's not Iran." Iranian-linked groups have been probing and targeting water facility PLCs for years, so this wouldn't exactly be a plot twist.
Nakasone stopped short of direct attribution but wasn't subtle about his thinking. "There's an intent," he said. "We're in conflict with Iran." He acknowledged the feds are taking a measured approach to attribution, which in diplomatic terms usually means they know but aren't ready to say it publicly.
The structural problem here is significant. US water infrastructure is a sprawling, fragmented mess of around 50,000 separate municipal systems, most of them chronically underfunded, understaffed, and in many cases running without a single dedicated cybersecurity employee. That's a vast attack surface with limited means to defend it.
"We have to think differently about how we defend it," Nakasone said, which is the kind of statement that sounds obvious until you look at the current state of play and realise almost nothing has changed despite years of warnings.
He pointed to DEF CON Franklin, a community initiative now two years old, where security researchers volunteer their time to help water facilities get their defences in some kind of order. It's an admirable project, and also a fairly damning indictment that volunteer hackers are filling gaps that federal policy has left open.
Nakasone is also involved in Project Chimera, an open-source cybersecurity platform being developed by academics and security practitioners aimed at improving critical infrastructure resilience. He now leads Vanderbilt University's Institute of National Security and its Wicked Problems Lab, which is at least a correctly named institution given the circumstances.
His broader point is that defending systems this dispersed requires genuine partnerships across government, industry, and the security community. Whether that actually materialises, or whether water facilities remain easy targets for state-sponsored actors with patience and a grudge, remains to be seen.