TECH Signal 636 2 feeds carried it
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
Retired NSA chief Paul Nakasone told reporters at DEF CON that programmable logic controllers at US water utilities should not be exposed to the public internet, after researchers attributed attacks on at least a dozen state water systems to Iranian operators.
For engineers who build or operate industrial control systems, the message is that internet-reachable PLCs are being framed as indefensible, not merely risky, and that the remediation path leans heavily on volunteer and open-source efforts because the affected water sector is too under-resourced to do it alone. The attribution to Iran is still unofficial, which means incident response coordination has to proceed without confirmed state-level naming, complicating any defensive mandate that depends on it.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Nakasone publicly argued that water-sector PLCs should be air-gapped from the public internet, in the context of attacks on at least 12 US states' water systems.
Private-sector researchers including Halcyon's Cynthia Kaiser said attribution to Iran is 'almost certain,' though neither the FBI nor the Trump administration has officially named a culprit.
The scope cited is roughly 50,000 water municipalities supplying 90 percent of US water, with limited or no dedicated cybersecurity staff, and DEF CON Franklin plus Project Chimera are positioned as the response channel.
THE CLUSTER