Retired General Paul Nakasone, former director of the National Security Agency, has advocated for disconnecting water system controllers from the internet, citing recent suspected Iranian cyberattacks on US water facilities. Speaking at the DEF CON conference, Nakasone emphasized the need for higher cybersecurity standards, stating that programmable logic controllers (PLCs) used in water systems should not be internet-connected.
The FBI confirmed in late July that it is investigating attacks by "malicious cyber actors" targeting operational technology devices, including PLCs. These devices are crucial for monitoring sensor data, such as tank levels, and controlling pumps in water and wastewater infrastructure. While neither the FBI nor the current administration has officially attributed the attacks, some private-sector security researchers strongly suspect Iran-linked groups are responsible.
Cynthia Kaiser, SVP at Halcyon Ransomware Research Center, expressed confidence at DEF CON that Iran is behind the recent disruptions, noting that Iranian actors have a history of targeting such devices for years. Nakasone echoed this sentiment, pointing to Iran's proven capability and intent in cyber warfare, given ongoing conflicts. He believes the federal government is taking a "measured approach" to public attribution.
Nakasone highlighted the significant vulnerability of US water systems, which comprise approximately 50,000 municipalities and supply 90 percent of the nation's water. These facilities often suffer from underfunding, limited IT staff, and a lack of dedicated cybersecurity personnel, creating a vast and exposed attack surface.
To address these vulnerabilities, Nakasone stressed the importance of collaborative defense strategies. He pointed to initiatives like DEF CON Franklin, a two-year-old project where volunteer hackers assist in securing water facilities. Nakasone is also involved with Vanderbilt University’s Institute of National Security and its Wicked Problems Lab, as well as Project Chimera, an open-source cybersecurity platform designed to enhance critical infrastructure resilience. He emphasized that effective defense requires a more involved, partnership-driven approach than currently exists.






