RSS Amplifier

The Cabreza Independent · Jun 14, 2026

Water Protection Needs Focus & Energy

0
Sign in to vote or save

Jason Rivera · The Cabreza Independent

Within the past couple of months there have been numerous “events” which when put together paint a picture of discombobulation, or stagnation.

Just to be clear up front, while these facts present a bit of a mess, no one individual or entity named or otherwise is at fault.

Everyone within and around critical infrastructure protection and security are doing their best with what they have, what they know and what they think needs to happen.

But that is not to say we don’t need to do better:

  1. We need to discuss and present detailed understandings of issues themselves, along with guidance

  2. We need to communicate more accurately and with fully scoped intent

There are 170k exposed ICS/OT assets, confirmed offensive AI against CI utilities, guidance against giving data to AI, including defensive, and ¾ of water infrastructure is insecure.

  • Within the past few months, the longstanding issue of exposed critical infrastructure assets is getting attention.

  • Around the same time AI was purportedly attributed and recorded as offensively, operationally capable.

  • More recently, water agencies came out to advise utilities not to share information with “AI service providers.”

  • A vaguely termed “AI service providers” could very well include OEMs and cybersecurity vendors.

  • The EPA has published that a little more than 1 of every 4 water systems has passed basic risk requirements.

  1. A purported 170,000 industrial systems are sitting on the public internet.

Context: A “vulnerability” present in the system or software is not required in order to gain control. All that’s minimally required is a successful login.

1a. The first ICS alert titled ICS-ALERT-11-343-01 - Control System Internet Accessibility was published to the ICS-CERT site almost 15 years ago on December 09, 2011, revealing the presence and accessibility of ICS.

  1. CISA confirmed APT targeting of internet-exposed PLCs with confirmed operational disruption in water/wastewater and energy.

Context: An Advanced Persistent Threat (APT) group level of funding or skill is not required to achieve disruption. At this stage, all that’s required is motive.

See also US ATG hardening, Czech and French articles and advisories, and our recent article diving into CI Fortify.

  1. AI is purportedly operationally capable of exposing and penetrating ICS/OT in utilities.

Context: Anyone close enough to ICS/OT security, cybersecurity and/or AI like me would assumedly read this and agree on the feasibility, at minimum.

  1. US Water agencies (EPA, Water-ISAC, AWWA) recently advised utilities not to share information with “AI service providers.”

Context: Siemens would fall into this category, with their AI app that evaluates meter trends to reduce non-revenue water losses. Claroty too, with their AI agent to give context to customers, on their data, within the platform. So assumedly Dragos as well, with their (likely) upcoming (sounding same or similar) AI something soon.

If more or better detailed information was confidentially provided to water and wastewater utilities, please reach out.

16-June Update: I asked the Water-ISAC about their position based on separate but related support they put out on LinkedIn here.

They stated: “WaterISAC believes there could be value for utilities in using AI to better understand their natural environments and what modeling can tell them about preparing for hazards like extreme precipitation and flooding. At the same time, utilities should be careful with any information about their specific operations they provide to AI or AI-service providers to ensure these details don’t fall into the wrong hands and be put to malicious use against them.”

  1. The EPA also alerted that 70% of inspected systems violate basic risk requirements.

Context: Basic measures such as changing default passwords and shared logins for all staff explicitly cited.

  • A new vendor tool will be announced or released to rotate credentials. It will address the symptom, not the cause. Some utilities will buy it, if they can. Others will make best efforts or do nothing because they don’t have the resources.

  • Cybersecurity will keep chasing (and lending their time to frontier model marketing departments) whatever Mythos, Fable headlines come next while the best practices, or lack thereof which led us here, continue being passed over.

  • Well-meaning agencies will continue well-intended guidance which will continue to hinder legitimate AI use-cases and water utilities will maintain a 30% pass rate on basic risk requirements.

  • We take the time to understand and communicate this “problem.” Our fellow humans who deploy these systems may not be in cybersecurity, may not have processes or procedures enabling change and may be prioritized, by order of their internal or external customer, just to get it up and running.

    • Also, OEMs are not exactly incentivized to productize unique, one-time or rotation credential capabilities without ample, pre-purchase stage demand

  • Tools can and will help, and accompany and be accompanied by operational, deployment and post-deployment training, processes, procedures and performance incentives (yes, this) so that continuity of best practice and discipline can be achieved.

  • Well positioned and suited sector agencies and communities will recognize the technological current state and do more to expand, coordinate and collaborate. Every entity in a position to support should be responsible for how protected or unprotected critical infrastructure sectors are, as their bottom line.

  • Capital, media, government agencies and the cybersecurity industry will prioritize and invest more into fundamental, hygiene level capabilities for all our critical infrastructure utility owners and operators.

You know which I’m hoping for but only time, clarity and motive will decide.

To everyone in water/wastewater, sorry that this is the reality. Many people in ICS/OT and CIP just want to help. If we’re missing something, anything, which could better position us to do so, please let us know.

Read the original on cabreza.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.