Former NSA chief urges utilities to remove water-system controllers from the public internet

Retired General Paul Nakasone, the former director of the National Security Agency, has called for stronger protections around US water infrastructure following a series of suspected intrusions affect...

Retired General Paul Nakasone, the former director of the National Security Agency, has called for stronger protections around US water infrastructure following a series of suspected intrusions affecting facilities in at least 12 states.

Speaking to reporters at DEF CON, Nakasone said programmable logic controllers (PLCs) used by water and wastewater operators should not be directly reachable from the internet. These devices collect operational information, such as reservoir and tank levels, and can control equipment including pumps.

The FBI said in late July that it was investigating attacks by “malicious cyber actors” against operational technology devices. Security researchers have linked the recent activity to Iranian operators, citing a history of Iran-associated campaigns against water-sector PLCs. However, neither the FBI nor the Trump administration has publicly assigned responsibility for the latest incidents.

Nakasone said authorities appeared to be taking a cautious approach to attribution, while noting that Iranian groups have previously demonstrated the capability and apparent intent to target such systems. Cynthia Kaiser, senior vice president of the Halcyon Ransomware Research Center, separately told reporters that she considered Iranian involvement highly likely.

A large and uneven attack surface

US water infrastructure is spread across roughly 50,000 municipalities, according to Nakasone, and many operators have limited funding, small technology teams or no dedicated cybersecurity staff. That combination can make it difficult to apply consistent security controls across facilities with very different equipment and operating practices.

He argued that protecting the sector will require closer cooperation between government, utilities, researchers and the security community, rather than relying solely on individual operators. One example is DEF CON Franklin, an initiative in which volunteer hackers work with water organizations to identify and address weaknesses.

Nakasone is also involved with Vanderbilt University’s Institute of National Security and its Wicked Problems Lab. In addition, he is working on Project Chimera, an open-source cybersecurity platform intended to improve the resilience of critical infrastructure.

The comments reinforce long-standing guidance for operational technology environments: limit internet exposure, separate control networks from business systems, restrict remote access and monitor devices for unusual activity.