The Register60%
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks 50%
8/7/2026, 12:53:10 PM
BS Summary: This article contains 26 faulty reasoning types, including Hasty Generalization, Availability Heuristic, and Attempt to Sell a Product or Service, with Representativeness Heuristic as the most egregious example at 28.7% saturation with 119 hits. Analysis detected 974 faulty-reasoning hits from 414 analyzed words, generating a BS Score of 42.6% and a BS Rank of 50% (15,126 of 30,190 articles). This article is better (less manipulative) than 50.10% of the article peer group.
With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON.
“We have to have higher standards,” Nakasone said.
“These PLCs should not be connected to the internet.”
In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs).
Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years.
Some private-sector security researchers say that they suspect Iranian intruders are behind the recent cyberattacks disrupting water and wastewater facilities.
“I'd be shocked if it's not Iran,” Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register at DEF CON on Friday.
“It's almost certain it's Iran.”
Neither the FBI nor anyone in the Trump administration, however, has officially blamed Iran.
Nakasone said he believes that the feds are “taking a measured approach” to attribution.
“But I see an actor here that has certainly shown a history of being able to do this,” he added, referring to earlier Iranian cyberattacks targeting water facilities’ PLCs.
“They certainly have the capability,” Nakasone said.
“There's an intent … we're in conflict with Iran.”
US water systems present a massive attack surface across disparate facilities that are historically underfunded and have limited IT staff, and sometimes no dedicated cybersecurity employees.
“We have to think differently about how we defend it,” Nakasone said.
“Let's talk about the attack surface that we're looking at right now.
We’ve got 50,000 different water municipalities in the United States, 90 percent of our water comes from these 50,000.”
Defending these water systems requires partnerships, he added, pointing to DEF CON Franklin, a project launched two years ago at the annual event with hackers volunteering their time and talent to help secure water facilities.
Nakasone also serves as founding director of Vanderbilt University’s Institute of National Security, and its Wicked Problems Lab.
He's also working on Project Chimera, a cybersecurity platform being developed by academics and cybersecurity practitioners, and built on open-source technologies to boost critical infrastructure resilience.
“How do you defend better?
You defend with a series of partners, in a much more involved approach than we have right now,” Nakasone said.
®
Speakers
3speakers51%attributed speech203writer words
Selected voice
100%flagged-word coverageCynthia Kaiser
27 attributed words13% of attributed speech100% writer coverage
Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.
Loading…
Loading…
Loading…
Loading…
Analysis
Hover over highlighted words in the article to view the associated bias or fallacy analysis.