The constraint in U.S. water security sits well below the firewall. The sector spans more than 144,000 public water systems, including roughly 50,000 community systems supplying year-round drinking water, each operated as an independent utility with its own budget, staffing, and security posture. Suspected Iran-linked attacks are now making that fragmentation visible in real time.
A control layer built for efficiency, not adversaries
Most of the digital systems now targeted were originally engineered for uptime and operational reliability. Security was a secondary consideration, Kevin Morley, federal relations manager for the American Water Works Association, told Axios. Configurations built before cybersecurity was a design criterion are now exposure points.
The AWWA sent a letter to Congress this week urging federal support for utilities as critical infrastructure, and the organization is advocating for nationwide minimum cybersecurity requirements. Morley describes the current moment as a cultural shift: operators are only beginning to internalize the full scope of what a successful attack could disrupt.
Funding mechanics that lock the gap in place
Water rates set by local municipalities are the primary revenue lever for most utilities, which turns every infrastructure investment into a local political decision. Rate increases are politically difficult to pass. Andrew Whelton, professor of civil and construction engineering and sustainability engineering at Purdue University, told Axios the funding and infrastructure challenges have accumulated across successive administrations, not within any single one.
Small community systems carry the sharpest exposure. Many operate with only a handful of employees, leaving them dependent on state agencies and industry associations for cybersecurity expertise. Those same utilities are also managing aging pipes, pumps, and treatment equipment while absorbing additional stress from more frequent wildfires, floods, and drought.
What the vulnerability count actually shows
The EPA identified vulnerabilities at 277 water systems last year and worked with those utilities to address them. That figure represents identified, disclosed gaps across a base of tens of thousands of systems.
Whelton points to Louisville, Colorado, which rebuilt parts of its network after the 2021 Marshall Fire contaminated the system and caused it to lose pressure. The redesign incorporated resilience against both wildfires and cyberattacks, treating each as an operational reality. Morley put the sector's position plainly: "Cybersecurity is an acute threat layered on top of chronic challenges."
Related reading
- Oil surges 7% after Iran fires ballistic missiles at U.S. forces
- Anthropic's Mythos built fake identities to deceive humans in fresh cybersecurity incident
- UK watchdog: OpenAI and Anthropic models targeted real people during cyber evaluations
- Ro Khanna's 'Data Center Bill of Rights' arrives as AI power plant politics reach the primary ballot