Two to four hours. That’s how long a hospital can operate if its water supply is cut off. Water is life. Its absence means delayed care, degraded care, increased morbidity, and even increased mortality. Delivery of clean water is a life-safety critical function. When water delivery is interrupted, it has immediate impacts on public health and safety. It is therefore a core government responsibility to ensure that the more than 50,000 community water systems across the United States can continue to operate.
Unfortunately, water delivery, like other life-safety critical functions, is increasingly at risk. Hackers affiliated with the Iranian government have accessed utilities across the country, executing malicious commands on their systems and forcing facilities to temporarily shut down. These recent incidents have exposed what cybersecurity experts have long known: our society is built on fragile foundations.
How fragile? Consider that, in many cases, the programmable logic controllers (PLCs) that hackers are targeting have functionally unpatchable security flaws. In traditional cybersecurity circles, we worry about how to bring down patching times and prioritize remediation. However, when the machines are controlling not just sensitive data, but the physical processes that undergird our very society, patching is not even an option. All a malicious actor needs to do is find one of these devices exposed online, and they can take control.
Cybersecurity practitioners are often accused of peddling in FUD—fear, uncertainty, and doubt. Given the massive vulnerabilities in our water systems, why haven’t we seen more attacks? Surely we are not as susceptible to disruption from a simple scan of IP addresses as these doomsayers would have us believe, or so the argument goes.
Unfortunately, these arguments mistake a lack of intent for a lack of capability. Cyber criminals go where the money is. Water utilities with small margins and smaller bank accounts are not high on the list. Similarly, even nation-state actors, from Iran to the PRC’s People’s Liberation Army (behind the “Volt Typhoon” hacks), have been dissuaded from directly knocking out water for fear of provoking an intense response from the U.S. government. They have stolen our secrets or even knocked medical manufacturers offline, but they have not yet used the access they already have in water utilities to devastating effect. But their failure to act must not be read as an endorsement of our resilience. On the contrary. Our adversaries are maintaining access precisely as a point of leverage. Their probes today are a reminder of our fragility in the face of a contingency tomorrow.
The cold rationality of it all is frightening. Our adversaries know they hold American lives in their hands, and each day, they get to decide whether to exercise this power. But what is downright terrifying is how AI is changing the landscape.
Most immediately, AI is democratizing cyber operations. This is not the first such revolution. Ransomware-as-a-service, for instance, dramatically reduced the expertise required to run a successful extortion enterprise. But past revolutions were human-directed, driven by human motivations, including financial or geopolitical gains. There was a very small market for crime targeting operational technology (OT), so specialists in OT payloads never found a home in the criminal underground.
Today, however, individuals with the intent to do us harm for non-financial reasons, such as violent extremists, might find themselves with access to knowledge about the inner workings of cyber-physical systems (CPS). AI models, whether jailbroken from their guardrails or designed without them, have the potential to walk these non-traditional threat actors through the steps needed to cause deadly harm.
Beyond malicious use by new entrants to the cyber threat landscape, AI agents may also do the hacking themselves. Over the past several months, models in testing have broken out of their “sandbox” environments and hacked other companies—all without any explicit direction to do so from their humans-in-the-loop. Despite the agents being directed to complete relatively benign tasks, they have ended up trawling the web for exposed credentials and used them to break into code repositories. The “motivations” of these machines are inscrutable. But it is not hard to imagine them using similar techniques to find exposed OT and exploit it, even when the reason for doing so is opaque to human cyber defenders.
The technology underpinning life-safety functions is fragile. The threat environment is rapidly worsening. What’s to be done?
The good news is that we still have time. The capability and intent gap is shrinking, but it still exists. And incidents like OpenAI’s hack of HuggingFace are exactly the indications and warnings that should move us to take action.
The bad news? While there have been numerous efforts to apply new cyber-capable AI tools to the IT stack, they have not yet reached down into the OT foundations. What’s worse, while AI can certainly help drive improvements in OT software quality, the reality for many owners and operators in the water sector is that bringing in AI tools is more likely to make things worse than to lower their risk. When a system has the potential to crash when it sees unusual traffic, having a non-deterministic program in the loop looks more like a hindrance than a helper.
At the end of August, RAND researchers called for a rapid series of convenings to address vulnerabilities in critical infrastructure software. The same week, IST launched Fragile Foundations, a 100-day sprint to better understand and provide suggested mitigations for AI-fueled cyber risk in life-safety critical infrastructure. Across five working groups, co-chaired by leaders with industry and government experience, Fragile Foundations aims to rapidly close the maturity gap between cyber-AI conversations in the IT space with the arguably more consequential ones in the OT context.
Efforts like these are vital because of the risk we have already accepted. We built our society on undependable technology, and we have relied on the restraint of our adversaries to keep our citizens safe. That strategy was never sound; today, it is downright dangerous.
We need new approaches that are cognizant of the very real differences between IT systems with three-year refresh cycles and OT systems designed to last a quarter century, between services that are unavailable daily for an hour or two for maintenance and those that might shut down for a couple of hours a year. We need to recognize that, sometimes, the best solutions are orthogonal to the cyber domain: an analog pressure arrestor can prevent a pipe from bursting, whether the change in pressure came from a cyber attack or a more conventional hazard.
Most importantly, we need to move fast. Technology is evolving at a breakneck pace, and we need to keep up. We need to sprint as if our lives depend on it because, at a very real level, they do.
Nicholas Leiserson is the President of the Center for Advancing Cybersecurity at the Institute for Security and Technology (IST), where he previously served as the SVP for Policy. A legislative strategist and technologist, he has spent 15 years addressing cybersecurity risk and resilience and managing multidisciplinary teams of senior professionals at the White House and on Capitol Hill. He was integral in the creation of the Office of the National Cyber Director (ONCD) and served as one of its first employees where he built the infrastructure for an office that grew to over 80 people in two years.