Image

The Water Utility Hacks Are a Warning for Defense Contractors * The Gateway Pundit * by Guest Contributor

Arek Socha (qimono), Wikimedia Commons

This story originally was published by Real Clear Wire

By Darron Makrokanis

The recent wave of cyberattacks targeting U.S. water utilities is not a series of isolated incidents but part of a broader campaign targeting vulnerable infrastructure. Federal agencies, including CISA, have warned that additional attacks are likely. Defense contractors should pay attention because these attacks offer a preview of how adversaries are likely to approach smaller and mid-sized defense contractors.

These incidents are a reminder of how our adversaries think, how they operate, and where they believe they can achieve the greatest return for the least amount of effort. While Iran-nexus cyber groups are not the most advanced threat actors, low skill does not mean low risk. If you’re part of the Defense Industrial Base (DIB), there are several important lessons to learn before similar campaigns reach the defense supply chain.

Lesson One: Attackers Target the Weakest Links

Attackers frequently target the organizations with the fewest resources. Many of the recent campaigns focused on smaller and mid-sized water utilities rather than the nation’s largest metropolitan systems. That shouldn’t surprise anyone. Smaller organizations often have fewer cybersecurity personnel, tighter budgets, and less mature security programs. The same reality exists throughout the DIB.

For years, many small and medium-sized defense contractors assumed they were simply too small to be targeted. Not only is this a misread of the threat environment, but in many cases, it is the exact opposite of reality. Foreign adversaries understand that a smaller subcontractor with weaker defenses can provide valuable intelligence, sensitive technical data, or a pathway into larger defense programs.

Lesson Two: Basic Cybersecurity Still Matters

Many of the recent intrusions relied on familiar weaknesses, including vulnerable internet-facing devices, exposed remote access services, default or absent credentials, and end-of-life equipment no longer receiving security updates.

These were not sophisticated “zero-day” exploits. Attackers simply connected to internet-accessible controllers, then changed passwords and IP addresses to lock legitimate operators out of their own systems.

Defense contractors sometimes assume that sophisticated nation-state adversaries require equally sophisticated defenses. In practice, attackers often succeed because organizations fail to implement basic security controls consistently.

Earlier this year, we analyzed 130 real-world techniques used by prominent Iranian threat groups and mapped them against the security controls in NIST SP 800-171, the cybersecurity baseline that underpins the Department of War’s Cybersecurity Maturity Model Certification (CMMC). The highest-leverage controls including monitoring, configuration management, baseline hardening, and malicious code protection, address these same underlying failures. Secure configurations and hardened baselines help prevent devices from being exposed with default credentials in the first place, while monitoring and malicious code protection help determine whether an intrusion is detected before significant damage occurs.

That is precisely why these foundational controls sit at the heart of CMMC. While compliance is often viewed as a regulatory exercise, many of its controls are designed specifically to prevent the kinds of attacks now affecting critical infrastructure.

Lesson Three: AI Is Accelerating the Threat

The scale and speed of these campaigns should concern every executive, because automation is fundamentally changing the economics of cyberattacks.

Threat actors no longer need to handcraft attacks against every organization they wish to target. Automated reconnaissance, vulnerability scanning, credential harvesting, and increasingly AI-enabled capabilities allow adversaries to identify and exploit thousands of potential targets simultaneously. AI will only make this process faster, cheaper, and more scalable, lowering the barriers for less sophisticated actors while increasing the volume of attacks that defenders must confront.

As attack velocity increases, organizations will need to adapt just as quickly, adopting new technologies and strengthening the policies, procedures, and defensive capabilities needed to keep pace.

Lesson Four: Operational Disruption Is Often the Target

Organizations must broaden how they think about cyber risk. Historically, much of the conversation has centered on data theft, intellectual property, or espionage. The attacks against water utilities remind us that operational disruption is equally important.

To cause that disruption, attackers are increasingly targeting operational technology (OT), such as industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. While defense contractors may not operate water treatment plants, they do operate manufacturing equipment, robotics, testing environments, production lines, logistics infrastructure, and other operational technologies that support the warfighter.

Protecting operational resilience is just as important as protecting sensitive information. The Department of War’s Office of the Chief Information Officer has recently highlighted this same issue, underscoring the growing importance of securing operational technology across the defense ecosystem.

Lesson Five: Attribution Is Complicated

The recent attacks also reinforce another reality: attribution takes time. Cyber threat actors routinely employ anti-forensic techniques to obscure their identities. In other cases, false flag operations may be used to implicate other nations. Even when the U.S. government has high confidence in the responsible party, diplomatic, military, or intelligence considerations may delay or limit what is disclosed publicly.

Whether responsibility ultimately rests with Iranian state actors, affiliated hacktivist groups, or another threat actor altogether, organizations cannot afford to wait for definitive public attribution before acting. Incident response cannot depend on knowing exactly who launched the attack.

Every organization must assume that defending its own environment is its responsibility from the moment suspicious activity is detected. Waiting for certainty is not a cybersecurity strategy.

Lesson Six: Attacks Are Geopolitically Motivated

Defense contractors cannot ignore the geopolitical dimension of modern cyber conflict. Cyber operations are increasingly used as instruments of national power. They are designed not only to disrupt operations, but also to send political messages, influence public perception, create uncertainty, and demonstrate capability.

We’ve seen Iranian actors target organizations associated with Israel during periods of heightened regional conflict. Russian operations often coincide with military objectives. Chinese cyber campaigns focus on long-term strategic positioning and intellectual property theft related to national security programs and capabilities.

Critical infrastructure operators and the DIB should assume they exist within this broader geopolitical landscape. Consequently, defense companies should recognize that they may be targeted not only for what they do, but also for what they represent.

Heed the Warning

U.S. adversaries consistently exploit the same patterns: under-resourced organizations, weak cyber hygiene, exposed systems, and fragmented security programs. Those patterns exist across every sector, including the Defense Industrial Base.

Cybersecurity is no longer simply an IT function or a regulatory obligation. It is an operational capability that directly supports national security. The organizations that recognize this reality, invest in strong cybersecurity fundamentals, and build resilient operations will be far better positioned for the threat environment ahead.

The water utility attacks should not simply be viewed as someone else’s problem. They should be viewed as an opportunity for every defense contractor to ask one simple question: If this campaign had targeted us instead, would we have been ready?


Darron Makrokanis is Chief Revenue Officer at Summit 7, where he helps more than 1,500 organizations across the Defense Industrial Base strengthen their cybersecurity posture. He is a former U.S. Navy intelligence officer who supported Naval Special Warfare and special operations units through the Office of Naval Intelligence. A cybersecurity and national security executive, Makrokanis previously held senior leadership roles at Booz Allen Hamilton, Tenable and Splunk, working extensively with the Department of War, Intelligence Community and defense contractors. He also served in law enforcement.

This article was originally published by RealClearDefense and made available via RealClearWire.

Ad block users: Some site features may not work correctly while an ad blocker is enabled, because they break scripts and content this website depends on. If you can’t see comments below, for example, please disable your ad blocker.

SHARE THIS POST