MSC Security
← All posts
Government·September 2, 2026·4 min read

Water Under Attack: Fortifying State & Local Infrastructure Against Nation-State Hackers

Recent cyberattacks on U.S. water systems and critical infrastructure highlight the urgent need for enhanced cybersecurity in state and local government. This piece explores how nation-state actors exploit vulnerabilities and what measures organizations can take.

Recent disclosures reveal that cyberattacks on U.S. water systems were more extensive than initially reported, impacting over 100 systems across 12 states. These incidents, attributed to Iranian state hackers, underscore a growing threat to critical infrastructure, particularly at the state and local government levels. Concurrently, the Justice Department and FBI have actively dismantled platforms used by state-sponsored hackers from China targeting U.S. critical infrastructure, including government entities like NASA and the Federal Reserve, demonstrating the persistent and evolving nature of these threats.

The Rising Tide of Cyber Threats to Critical Infrastructure

The acknowledged cyberattacks on water systems specifically targeted programmable logic controllers (PLCs), which are vital components managing water infrastructure operations. The scope of these attacks – impacting a significant number of systems in states such as Minnesota, Wisconsin, and Michigan – brings into sharp focus the vulnerability of foundational services.

Experts highlight that limited funding and regulatory frameworks often hinder local utilities' ability to effectively detect and respond to such sophisticated cyber incidents. This creates a critical gap, leaving essential services exposed to nation-state adversaries who possess advanced capabilities and resources.

Nation-State Adversaries and Their Targets

The threat landscape extends beyond water systems. The Justice Department and FBI's recent actions against Chinese state-sponsored hackers reveal a broader pattern of targeting critical infrastructure across various sectors. These actors, associated with the PRC, utilized platforms like QScan and QTRouter to compromise U.S. organizations, including sensitive government agencies. Attorney General Todd Blanche and FBI officials emphasized the commitment to proactively combat these threats, dismantling tools used by hostile state actors and protecting national security.

This ongoing combat against state-sponsored hacking campaigns serves as a stark reminder that no sector, especially critical infrastructure and government, is immune. The sophisticated nature of these attacks demands a proactive and robust cybersecurity posture.

Addressing Vulnerabilities: A Call for Proactive Defense

The reality of widespread cyberattacks on critical infrastructure underscores the urgent need for state and local government entities to bolster their defenses. The challenge often lies in resource constraints, but the cost of inaction far outweighs the investment in cybersecurity.

Leveraging Expert Assessments and Best Practices

Organizations like CISA provide valuable resources, including Risk and Vulnerability Assessments (RVAs). These assessments offer tailored analyses and recommendations to improve cybersecurity posture by identifying potential vulnerabilities. CISA's annual reports, such as the FY23 RVA report, detail findings, including attack path analysis in relation to MITRE ATT&CK®, outlining tactics and techniques commonly used by threat actors.

CISA encourages organizations to apply recommended defensive strategies to enhance their cybersecurity posture, which is a crucial step for local governments and utilities.

Key areas for state and local government to focus on include:

  • Comprehensive Vulnerability Management: Regularly identifying and addressing weaknesses in systems, including operational technology (OT) like PLCs, is paramount.
  • Threat Intelligence Integration: Understanding the tactics, techniques, and procedures (TTPs) of nation-state actors, as highlighted by CISA and law enforcement, allows for more targeted defenses.
  • Incident Detection and Response: Building capabilities to quickly detect, analyze, and respond to cyber incidents can minimize damage and disruption.
  • Regulatory Clarity and Funding: Advocating for and implementing clearer cybersecurity regulations and securing adequate funding are essential for smaller, resource-constrained entities.
  • Supply Chain Security: Recognizing that third-party vendors and contractors can introduce vulnerabilities, especially in OT environments, requires careful vetting and continuous monitoring.

MSC Security's Role in Fortifying Public Sector Defenses

MSC Security provides comprehensive cybersecurity, compliance, and IT services tailored to regulated and mission-driven organizations, including government and critical infrastructure. Our expertise helps state and local entities navigate the complex threat landscape posed by nation-state actors.

  • Managed Detection & Response (MDR): Our MDR services provide 24/7 monitoring, threat detection, and rapid response capabilities, crucial for identifying sophisticated attacks that might otherwise go unnoticed by under-resourced internal teams.
  • Compliance Management: We assist organizations in achieving and maintaining compliance with critical frameworks (e.g., CMMC, HIPAA, SOC 2), enhancing their overall security posture and addressing regulatory gaps.
  • AI Security: Implementing AI-driven security measures to better detect and analyze advanced threats, particularly those leveraging novel techniques.
  • Risk and Vulnerability Assessments: Similar to CISA's offerings, we can conduct thorough assessments to pinpoint weaknesses in IT and OT environments and provide actionable recommendations.
  • IT Staffing & Managed IT: For organizations with limited internal resources, our managed IT services and staffing solutions provide access to expert cybersecurity and IT professionals.

By partnering with MSC Security, state and local government entities can proactively defend against nation-state cyber threats, safeguard critical infrastructure, and ensure the continuity of essential public services.

Key takeaways

  • Cyberattacks on U.S. critical infrastructure, including water systems, are more widespread than initially reported, primarily targeting operational technology like PLCs.
  • Nation-state actors, such as those from Iran and China, are actively targeting government entities and critical infrastructure using sophisticated hacking platforms.
  • Limited funding and regulatory clarity often leave local government and utility entities vulnerable to advanced cyber threats.
  • Proactive measures, including comprehensive vulnerability management, strong incident detection, and leveraging expert assessments, are critical for defense.
  • Managed cybersecurity services offer a viable solution for state and local governments to bolster their defenses against persistent and evolving nation-state threats.

Sources