Over the summer, a coordinated cyberattack targeted operational technology at more than 30 community water systems in Minnesota. The FBI later reported similar incidents in at least seven states. The ramifications were significant enough for Congress to get involved, prompting the introduction of the “Water Cyber Shield Act” last week, which would increase cybersecurity funding and empower the EPA to help prevent future attacks on water infrastructure.
These incidents should serve as a wake-up call. Protecting critical infrastructure is fundamentally a homeland security mission, but much of the infrastructure at risk, like our water utilities, hospitals, transit systems, and school districts, is operated by state and local institutions. In Minnesota, operators knew how to run their plants by hand when the screens went dark. The technology failed. The people did not. But that kind of readiness is not always guaranteed.
That is why technical talent should be considered part of America's critical infrastructure. Without the people who can secure, modernize, and manage essential systems, even the best technology falls short. Experienced operators are indispensable during an emergency, but local institutions also need technical staff who can reduce exposure before an incident, maintain inventories and access controls, and connect operational expertise with modern cybersecurity practice.
Essential services today also increasingly depend on connected systems, spread across institutions of very different sizes and capacities. Federal warnings and state responses are helpful, but every organization’s cybersecurity capability depends on whether it can hire people with the necessary expertise to defend against threats. Some estimates suggest we’re not there yet. GAO has found wide differences in cybersecurity capabilities across the water sector, along with workforce skills gaps that make those vulnerabilities harder to address.
Join the conversation as a VIP Member