When news breaks that a foreign actor has targeted critical infrastructure, the headlines often focus on one question: Who did it? Was it a nation-state? A foreign intelligence service? A ransomware group operating overseas? Those are important questions, but I believe they're overshadowing a far more important one. Would we care as much if the attacker were American? We should. Critical infrastructure doesn't care about nationality. Water treatment plants, dams, electrical grids, hospitals, and transportation systems don't distinguish between a command issued from another continent or another country. The consequences can be exactly the same, and that is where we need to focus.
The Wake-Up Call You Needed.
The question that should concern defenders is not only who was behind the keyboard. It's why they were able to get there in the first place. Over the last several years, a series of incidents involving dams, water utilities, and critical infrastructure systems have highlighted a troubling reality. Different countries. Different organizations. Different attackers. Yet the same problem keeps emerging: systems responsible for essential public services remain exposed through pathways that adversaries can discover, access, and potentially exploit.
One of the most recent examples occurred at Norway's Lake Risevatnet dam. Attackers gained access to an internet-connected control system and opened a water valve, increasing water flow for several hours. Investigators later determined that weak password protections contributed to the compromise. While the resulting impact was limited and no major physical damage occurred, the event demonstrated something that should concern every defender. Unauthorized individuals were able to reach operational technology responsible for controlling physical infrastructure.
The significance of the incident was not the amount of water released. It was the fact that cyber intruders crossed the line between information systems and physical operations.
The Norway incident exposed several recurring challenges:
- Weak authentication remains one of the most common attack paths into OT environments.
- Internet-exposed control systems provide opportunities for remote manipulation of physical processes.
- Security failures do not need to cause a catastrophe to reveal serious weaknesses.
- Critical infrastructure operators often rely on operational safeguards and manual intervention as the final layer of defense.
- Real-world consequences are often avoided because of safety mechanisms and operator response rather than security controls alone.
The lesson from Norway is simple. The impact was limited. The exposure was not.
References
- Industrial Cyber: Lake Risevatnet Dam Hack Exposes Industrial Cyber Gaps
- https://www.bleepingcomputer.com/news/security/hacker-opened-water-valve-at-norwegian-dam-using-weak-password/
Similar warning signs have appeared much closer to home. In November 2023, the Municipal Water Authority of Aliquippa, Pennsylvania, became the target of a cyberattack attributed to the Cyber Av3ngers hacktivist group. Attackers compromised an internet-connected Unitronics programmable logic controller (PLC) used within utility operations.
Operators quickly detected the issue and shifted affected processes to manual control, ensuring that water treatment and distribution continued without disruption.
Many discussions surrounding the incident focused on attribution. The more important lesson was what the attackers were able to reach. A publicly accessible industrial control device supporting a critical public service was discovered, targeted, and manipulated remotely.
Aliquippa reinforced several realities:
- Internet-facing industrial devices still exist throughout critical infrastructure sectors.
- Threat actors actively scan for exposed operational technology.
- Many utilities continue to operate aging infrastructure that was not originally designed with cybersecurity in mind.
- Manual operating procedures remain one of the most important safeguards available to operators.
- Attackers do not need to compromise an entire utility to generate operational concerns or public attention.
The success of the response should not overshadow the lesson. Attackers reached the control environment. The outcome could have been significantly different under other circumstances.
References
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
- https://www.reuters.com/world/us/us-water-utilities-urged-secure-systems-after-pennsylvania-hack-2023-11-29/
- https://www.municipalwaterauthorityofaliquippa.com/
On to Minnesota we go.
Officials disclosed a cyber intrusion involving water treatment infrastructure in Mankato. While drinking water remained safe and no contamination occurred, investigators found that unauthorized access had been obtained within portions of the utility's environment.
Like Norway and Pennsylvania, the incident highlighted the growing risks associated with connected infrastructure. Water utilities increasingly rely on remote connectivity, vendor support mechanisms, integrated business systems, and internet-connected operational technology. These capabilities improve efficiency and reduce operational costs, but they also create additional attack paths.
The concern is not simply that access occurred. It's what that access represents. Water utilities are no longer isolated industrial environments. They are connected operational ecosystems that must balance availability, efficiency, reliability, and security simultaneously.
The Minnesota incident reinforced several important realities:
- Water infrastructure remains an attractive target because it provides essential public services.
- Remote access solutions create additional attack surfaces when not properly secured.
- Utilities often face the same cyber threats as large enterprises while operating with significantly fewer resources.
- Operational technology increasingly inherits risks from connected IT systems and third-party suppliers.
- Visibility into assets, access paths, and connectivity is now essential for effective defense.
Like Norway and Pennsylvania, the lesson was not necessarily the impact. The lesson was the access.
References
Discovery Has Become Easier Than Ever, and AI Knows it, too.
What makes today's threat landscape different is that finding exposed infrastructure no longer requires extraordinary skill, resources, or insider knowledge. A decade ago, identifying an exposed industrial control system often required specialized expertise and extensive reconnaissance. Today, publicly available platforms such as Shodan and Censys continuously scan the internet and index exposed devices, services, and systems. Security teams use these platforms to understand their attack surface. Attackers use them too.
An adversary no longer needs to randomly search the internet, hoping to find a vulnerable target. With a few simple queries, they can identify remote access gateways, programmable logic controllers, industrial control systems, building automation platforms, and other operational technology assets connected to the internet. The threat is no longer limited to sophisticated nation-state actors.
A cybercriminal seeking profit, a hacktivist pursuing a cause, a lone individual looking for attention, or a nation-state conducting reconnaissance can all leverage the same discovery capabilities. Artificial intelligence is accelerating this shift. Defenders can use AI to identify exposed assets, correlate threat intelligence, prioritize vulnerabilities, and improve visibility across complex environments.
Attackers can use many of the same capabilities to:
- Automate reconnaissance.
- Identify exposed systems at scale.
- Analyze software versions and configurations.
- Correlate public intelligence sources.
- Prioritize vulnerable targets.
- Accelerate decision-making during targeting activities.
The danger is not that AI suddenly gives everyone advanced offensive capabilities. The danger is that it reduces the time, expertise, and effort required to identify exposed infrastructure. The same technologies helping defenders secure their environments are helping adversaries discover what defenders overlooked. Organizations should therefore assume that any internet-facing asset has already been discovered, cataloged, and assessed by someone. The question is no longer whether exposed infrastructure can be found. The question is whether it remains secure after it has been found.
This reality also challenges how organizations think about vulnerability management. A medium-severity vulnerability affecting an internet-facing water treatment system may present a far greater risk than a critical vulnerability on an isolated administrative server.
As I discussed in "Moving Beyond Traditional Risk Labels: Redefining Patch Management," organizations should prioritize vulnerabilities based on operational impact and business risk, not solely on severity labels.
Reference
Foreign Or Domestic? Not Important: Focus Up Here.
This is why attribution cannot be the primary focus. Whether an attack originates from a nation-state, cybercriminal organization, hacktivist movement, malicious insider, or individual acting alone, the defender's responsibility remains unchanged: Prevent unauthorized access to systems that support public safety. The operators at the Lake Risevatnet dam, the personnel at Aliquippa, and the defenders responsible for water infrastructure in Minnesota all faced the same challenge.
Not determining the attacker's nationality. Preventing access. Because once an adversary reaches a system controlling water treatment, water flow, power generation, transportation operations, or other critical services, nationality becomes secondary to consequence. The intrusion either succeeds. Or it doesn't.
What Critical Infrastructure Operators Should Prioritize.
Critical infrastructure operators should assume their internet-facing assets are being continuously discovered and evaluated by both security researchers and malicious actors.
That reality demands the following:
- Strong authentication and multifactor authentication wherever possible.
- Removal of unnecessary internet exposure.
- Segmentation between IT and OT environments.
- Comprehensive asset inventories.
- Continuous monitoring and anomaly detection.
- Regular vulnerability assessments and penetration testing.
- Business-impact driven vulnerability prioritization.
- Secure remote access solutions with least-privilege access.
- OT-specific incident response plans.
- Manual operational contingencies.
- Routine validation of backup and recovery procedures.
The Bottom Line
Critical infrastructure only knows one thing: Whether we secured it or whether we didn't.
Photo by Erik van Dijk on Unsplash