
“For instance, in 2024, the Environmental Protection Agency’s Office of Inspector General examined 1,062 drinking-water systems serving more than 193 million citizens. It found critical or high-risk cybersecurity vulnerabilities at 97 systems serving approximately 26.6 million Americans. Another 211 systems serving more than 82.7 million people had portals that were visible from outside their networks.”
So what do water system hacks in Minnesota have to do with your business?
3 Takeaways
First, these cyberthreats had long been KNOWN to the institutions involved. That is, even if a vulnerable water system didn’t know its own exact cyber vulnerabilities, it had been repeatedly warned about the basic steps it needed to take to better protect itself….steps apparently not taken by the hacked systems.
Risk becomes riskier if you don’t acknowledge and address it. Ignoring a clear threat to your business is exceptionally dangerous. We try to avoid “scare tactics,” but the reality is we see businesses in the CSRA attacked regularly. These business owners aren’t stupid or incompetent. It’s simply that cyber threats aren’t high enough on the risk matrix that many business owners consider. That is, until their revenue and reputation are significantly damaged.
Incidentally, you might think that the water system hack is a special case, as the US is at war with the Iranian regime (apparently) behind the attacks. But the reality is somewhat different: cybercriminals looking only for money don’t have political considerations to prevent them from making their attacks. Iranian hackers didn’t suddenly discover these vulnerabilities. They’d known about these for a long time. The hackers only exploited them now because of the conflict between the US and Iran. Cybercrooks looking for money are not restricted by political situations – once they see an opening, they will take it.
Second, as we have said repeatedly here, there are no more “small fish” in the cybersecurity world. Every business owner must change the “it won’t happen to us because we aren’t X large institution.” Cyber-scams are quicker and cheaper to run than ever before, so it is very much worth a hacker’s time and effort to target ANY business with open digital doors. You simply don’t hear about all the hacks that happen locally because a local business doesn’t call the local news to report itself being hacked. Mostly, a business just hopes the fallout goes away. “Incident response” is another necessary task that businesses should consider…but that’s a blog topic for a different day.
Third, AI has vastly amplified the speed and scope of cyber-attacks. As the article above says, “AI is making cyberattacks cheaper, faster and easier to execute at scale – and it’s a threat we must not ignore.” For all the concern about how business owners should use AI in their own operations, maybe a greater consideration is to understand the threat from AI-enabled cyberthreats.
Finally, good IT doesn’t mean good cybersecurity. Most folks think these are one and the same. But managing Help Desk tickets and installing hardware is not the same as good cybersecurity. You need to make sure that whoever manages your IT has real expertise, tools, monitoring capacity, and ability to train your employees.
Conclusion
The lesson from these water-system attacks isn’t that every business needs to panic. It’s that known risks don’t become less dangerous because we choose not to address them. Cybersecurity threats are getting faster, cheaper, and more accessible to attackers. And businesses of every size are potential targets.
Good IT is an important part of the equation, but cybersecurity requires more: identifying your risks, closing the obvious gaps, monitoring for threats, and making sure your people know what to look for.
You don’t have to be a water system to have an open digital door. You just need one that hasn’t been properly secured.
