Advertisement
Advertisement
Advertisement
8 September 2026·9 min read·By Erik Vanderwall

In most cities, nobody owns the whole network

An op-ed argues that water utilities' network segmentation is irrelevant when controllers are on public cellular links, and calls for accountability and funding changes.

In most cities, nobody owns the whole network

The Network Nobody Owns

Nobody owns the whole network in most cities, and that single fact is why water treatment plants across the country remain dangerously exposed. I learned this firsthand while serving as chief information officer for Waco, a city of 145,000 residents. Standing in front of a network cabinet at one of our water treatment plants, I traced which systems could reach which. The plant’s controls were on that network. So was the branch library. So was the register at the municipal golf course.

Nobody had ever been asked to inventory what sat on that network. Not once.

What July’s Attacks Actually Revealed

In July, intruders compromised water and wastewater treatment equipment across the United States. The critical detail: most of that equipment was reachable over public cellular networks, placing it entirely outside the boundary most utilities thought they were defending. None of the asset lists I have reviewed would have caught it.

In most cities, nobody owns the

Three separate accounts tell different stories. The scope isn't clear at all. CISA identified over 100 compromised systems in the water and wastewater sector during July, typically through controllers connected directly to cellular modems, which suggests a broad attack surface that could affect many more utilities than the official reports indicate. But the FBI and the EPA reported on July 30 that utilities in at least seven states had filed incident reports since July 27, a much narrower figure that contrasts sharply with the agency's own count. Press accounts citing unnamed officials put the number of affected states at a dozen or more, so we've got conflicting numbers that don't add up cleanly. It's a mess.

No federal agency has blamed anyone for the late-July water incidents. But a joint advisory does point to Iranian-affiliated actors for the broader campaign, which is tied to a separate set of intrusions, and that distinction matters because the advisory was revised on July 22, five days before utilities first reported problems. The revision expanded known targets from Rockwell Allen-Bradley to Schneider Electric, Siemens, and potentially others. So the controller brand on the panel settles nothing anymore.

The reported effects were operational. A loss of visibility. In some cases, a loss of function. In Clayton County, Georgia, a pump station failed around 1 a.m. on July 27. The boil-water advisory lifted the next day. In early August, the authority serving more than 260,000 people said unauthorized cyber activity may have caused or contributed to the disruption. That hedge is deliberate.

The Exposure Nobody Scanned For

The standard answer from utility managers goes something like this: we separated the plant network years ago. That’s legitimate work. But it doesn’t matter here.

The vulnerable controllers never were on the city network. They ran on public cellular links. A modem installed years ago exists nowhere in the asset list and nowhere on network scans.

Market Context: According to Black Cell, 73% of OT devices remain unmanaged in 2026.
But every carrier invoice lists every SIM the city pays for. Only accounts payable tracks them. Matching those invoices to actual devices costs nothing and can start Monday.

The FBI and the EPA also advise utilities to consider isolated architectures for that equipment. But a private access point name tops their list of recommendations, and it's a straightforward step they can take to wall off critical systems from broader network exposure, though it's not the only option they've outlined. Don't overlook that detail.

An Organizational Blind Spot

Most of these systems sit outside the IT department on the org chart, each with its own budget, vendors and boss. The plant answers to public works. Cameras and card readers arrived with a building project, and most cities treat them like light fixtures. In every city I’ve worked in, exactly one person in IT understands the whole picture. When that engineer leaves, the security posture leaves with them.

And nobody owns accountability for the network they all share.

Reporting rules also miss the point. Texas, my example, requires local governments to report security incidents within 48 hours, but only if they involve personal-information breaches or ransomware. An intrusion that seizes control of a controller while touching neither sits outside that trigger. That’s exactly what happened in July. The federal rule requiring a covered cyber incident to be reported within 72 hours was supposed to be finalized in October 2025; CISA is now targeting this month. But nothing in any rule determines who owns the network.

Money the Utility Already Applies For

The second objection is that there is no budget. Wrong.

Texas is hardening its water defenses. For State Fiscal Year 2026, the Texas Water Development Board added cybersecurity to the scoring criteria in its Intended Use Plan for the Drinking Water State Revolving Fund, so that's a real shift. Two questions on the Project Information Form now carry five priority points between them. One asks if the governing body adopted a cybersecurity awareness plan in the last five years. The other asks if a project fixes a deficiency found in a cybersecurity assessment. And that's it.

Five points is modest. I won’t oversell it. But this fund is a ranked competition decided at the margins.

Waco segmented five treatment plants, four drinking water and one wastewater, in 43 days against the 90 I’d promised City Council. No bond. No capital request. The utility director funded it from operating accounts using a contract already on the city’s books, rather than an RFP. They carried it to Council because the network was theirs to own.

Those were budget choices ahead of anything else. An operating line competes with a maintenance contract and can be approved this quarter, while the same money in the capital plan waits for a bond cycle.

A smaller city without a CIO will not repeat that schedule. But the funding mechanics are the same ones.

Segmentation Without the Fear

Every CIO knows how to segment a network. Almost nobody does it, because they are afraid of taking a plant down. Simulate before you enforce.

One operating rule came out of Waco’s experience: being on the network allows a device nothing. Plant controls talk only to their SCADA server. Everything else is denied unless explicitly allowed.

City managers, university presidents, superintendents, and chief executives will invest in cybersecurity when they trust the money actually moves the needle. They spend taxpayer dollars in public view. So the public's trust rides on every line item as much as the cash does, and that pressure makes them cautious, deliberate, and frankly skeptical of vague promises. It's transparency that earns their approval. What wins them over is a complete picture of what they're protecting, plus hard evidence that critical infrastructure can withstand threats from the open internet and from inside their own network. But that evidence can't be fuzzy. Show them the defenses, and they'll open the wallet.

Microsegmentation protects critical systems without the need for rip-and-replace. It isolates water treatment plants, 911 dispatch, public safety alerts and traffic management from internal and external threats, all on networks cities already own. Modern platforms deploy in weeks rather than budget cycles. Microsegmentation is zero-trust’s foundation and the most direct defense of infrastructure residents depend on.

Somebody to Call

None of this reaches a two-person utility that can’t write competitive applications. That’s where states must lean in.

New York adopted what it calls the first-in-the-nation water cybersecurity rules in March, pairing those mandates with grants and free technical support for utilities that can't shoulder the burden alone. Texas has stood up a Cyber Command with an explicit water and wastewater mandate. But a small city needs a number to call. It needs people who actually answer.

That number now exists. On Monday, Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio, a six-month pilot that puts Texas Cyber Command, the National Cyber Director’s office, the EPA and CISA, and a dozen private cybersecurity and technology companies behind Texas water utilities. Participating systems get red-team testing, vulnerability assessments and help hardening what the assessments find.

For the smallest systems, DEF CON Franklin and the National Rural Water Association have put volunteers and five managed detection providers behind them.

Where to Start

Here are three things CIOs and CISOs can do that do not have to wait for a grant or a budget cycle:

  • Name one position accountable for every device on the utility network and put it in writing.
  • Match twelve months of carrier invoices to actual devices and sites.
  • Read your state’s Intended Use Plan scoring criteria before the next application.

Nothing in Waco moved until the first of those was settled. The other two cost nothing more than somebody’s afternoon. Most cities haven’t even put someone in that position. Until they do, nobody owns the whole network, and the water keeps flowing through systems that remain one misconfigured modem away from the open internet.

Frequently Asked Questions

What does the article say about who owns the network in most cities?

The article states that nobody owns the whole network in most cities. This is highlighted as a key reason why water treatment plants remain exposed, as no one has been tasked with inventorying what sits on the network.

Why were the water treatment controllers vulnerable despite typical network separation?

The vulnerable controllers were not on the city network but ran on public cellular links. These modems were installed years ago and were not captured in asset lists or network scans, making them invisible to standard defenses.

How did Waco fund the segmentation of its treatment plants without a bond or capital request?

The utility director funded the segmentation from operating accounts using a contract already on the city's books. This allowed the work to proceed without a bond or capital request, and it was completed in 43 days against the 90 promised to City Council.

What is recommended as a first step for CIOs and CISOs to address network ownership?

Name one position accountable for every device on the utility network and put it in writing. The article emphasizes that nothing moved in Waco until this step was settled, and it is one of three actions that do not require waiting for a grant or budget cycle.

Who launched Project Watershed 250 and what does it offer to Texas water utilities?

Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio. It is a six-month pilot providing participating systems with red-team testing, vulnerability assessments, and help hardening what the assessments find, involving Texas Cyber Command, the National Cyber Director's office, the EPA, CISA, and private companies.

Erik Vanderwall
Written by
Security and Privacy Correspondent

Erik Vanderwall reports on information security, data breaches and the defenders working to keep systems safe. He follows the constant contest between attackers and the people trying to stop them.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement