Security1 publisher2 min readPublished
WaterISAC speeds threat sharing for water utilities still running exposed, pre-cyber PLCs
WaterISAC is adding Cyware's threat intelligence platform to speed alerts to US water utilities, including 20,000 small systems it serves with a rural partner. Its director says utilities have little incentive to replace old controllers that still work, so the answer is faster warnings.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Internet-exposed OT and programmable logic controllers were the two weaknesses most commonly linked to this summer's attacks on US water facilities.
- President Trump has disputed that Iran was behind the summer attacks, even though CISA alerts pointed to Iran.
- Dobbins said CISA has also warned the sector about potential threats from Russia and China.
- WaterISAC announced the Cyware deal on Wednesday and said it picked the company partly for its existing ties to other industry ISACs.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Faster alerts do not take a controller off the internet. The fix Dobbins names for older exposed systems is disconnection, and each utility has to carry that out on its own network.
- exposure A utility that lets an integrator keep an unmanaged connection into OT takes on that integrator's security weaknesses as its own.
- cost The work an alert calls for, such as enforcing MFA or changing passwords, falls on small utilities that Dobbins says already struggle to keep up with it.
- contradiction Operators hear Iran from CISA and doubt from the White House, so they have to choose which attribution to plan defenses around; WaterISAC's director has chosen CISA's.
Dobbins called PLCs the sector's "main point of entry" and said the equipment dates back to a "simpler, gentler time" [9]. The other routes he described come down to who holds access. "If those integrators are working and they have a connection into an OT system that's not managed discretely, then a threat actor can come in through an integrator and get into a system," he said [14]. Then there is phishing, aimed at someone Dobbins described as "actually a good employee who's tried to do the right thing" [15].
Closing the first route does not require new hardware. "OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible to the internet," Dobbins said [7].
On replacing the controllers themselves, he did not expect utilities to move. "A lot of the equipment was developed pre-cyber threats and activities," he said. "The equipment, it's still valuable, it still is operational, so there's not a huge reason for or incentive for utilities to upgrade it." [10]
WaterISAC's response is speed [2]. The ISAC already reaches the smallest utilities through a partnership with the National Rural Water Association, and Dobbins said Cyware would help its analysts further [6]. Tom Stockmeyer, Cyware's managing director of government and critical infrastructure, said the company could help by drawing on its relationships with other ISACs [18]. "We're thrilled to add water to the portfolio and start enabling cross-sector sharing," he said [17].
On attribution, Dobbins sided with CISA over the president. The US government reportedly believes Iran was behind this summer's water facility attacks [4]. "I'll say that CISA maybe is more expert in this area than maybe the president," Dobbins said. "The president may not have been fully briefed when he made that comment." [12]
He tied the wider rise in activity to US involvement abroad. "We have been under attack, and our enemies, the threat actors, are stepping up their activity as the U.S. is involved in a number of conflicts around the world," he said [3].
His account describes sustained pressure from three countries: Iran, China and Russia [4]. The reporting documents one summer of attacks, which the government reportedly attributes to one of them [4]. It does not name the utilities hit or say how many there were [8].
What to watch
- Whether CISA publishes technical indicators or victim counts for this summer's water attacks, the evidence that would settle the disputed Iran attribution.
- How fast Cyware-backed alerts reach the smallest utilities served through the National Rural Water Association, and whether those sites can act on them.
- Any federal or state requirement to take older OT off the internet, the fix Dobbins named that needs no new equipment.