The attacker scales, and the defender is a town of 1,800
Event dated 4 August 2026 · Published 2 September 2026 · 5 sources
Most published security advice, including nearly everything on this site, assumes an organisation. It assumes somebody maintains an asset inventory, somebody reviews the logs, somebody decides whether a finding applies, and somebody is available at two in the morning. The advice is sound and the assumption is doing a great deal of unexamined work.
A water utility serving a town of eighteen hundred people may have one person responsible for every computer it owns, alongside billing, meter reading and whatever else the week requires. There is no security function to address advice to. There is a person, and the person is busy.
Why the controllers and not the office
Going for the office network is the ordinary path: reach a workstation, take credentials, move sideways, and eventually arrive somewhere that matters. It is well trodden and it is also where whatever defences exist have been placed, because that is where the products are sold.
Going directly for a programmable controller skips all of it. These are small, purpose-built computers that open a valve or start a pump on command. Many were designed decades ago for an environment with no hostile network, so authentication is frequently weak or optional, and a command that arrives is a command that gets executed.
That is what produces the effects reported here. Pressure loss and flooding are not data breaches with a physical metaphor attached; they are what happens when a valve does something the operator did not ask for. The consequence lands in the street rather than in a notification letter.
What "coordinated across thirty systems" actually means
Not thirty separate operations. The same model of controller, deployed by dozens of small utilities that made the same reasonable purchasing decision, reachable in the same way — so one technique, developed once, applies everywhere it is found.
That is the same arithmetic that 86,000 identical firewalls produced in June, arriving in a sector where the buyers are municipalities rather than enterprises. Standardisation is what makes small utilities able to run industrial equipment at all. It is also what lets an operator scan for the model and work through the results.
The asymmetry nobody has solved
An attacker's cost per additional target is close to zero once the technique exists. A utility's cost per additional control is a person, or a contract, funded from a budget set by a town council against competing demands like replacing pipes that are actually leaking.
So the two sides scale in opposite directions, and the gap widens on its own without anybody making a mistake. That is not a failure of the utilities and it is not solved by telling them to try harder — which is, in practice, what most guidance amounts to when it reaches an organisation with nobody to receive it.
What survives when there is no security team
Very little of the standard list, and it is worth being honest about which parts. Threat hunting, log review, tabletop exercises and vulnerability management programmes all require sustained attention from somebody whose job it is. Recommending them here is recommending a hire.
What does survive is the small set of measures that are done once and then hold. A controller that cannot be reached from the internet cannot be commanded from the internet, and confirming that is an afternoon's work rather than a programme. Default credentials changed once stay changed. A manual procedure for operating the plant without its control system, written down and practised twice a year, works whatever happens to the network.
Those three are not a security posture. They are what is achievable by an organisation with no security function, and the difference between a utility that has done them and one that has not is larger than any difference between two well-resourced utilities running different products.
Where the capacity has to come from
Not from the utilities, because it is not there and no amount of guidance creates it. The realistic sources are shared: a state or regional body that does the monitoring for many small systems at once, a purchasing arrangement that makes secure defaults the ones that arrive in the box, or a vendor obligation that puts authentication in the controller rather than in a document telling somebody to configure it.
Each of those moves the work to where the capacity is. That is the only structural answer to an asymmetry of this shape, and it is a policy question rather than a security one — which is an uncomfortable conclusion for a security publication to reach, and the accurate one.