• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Red River Valley Amateur Radio Club

Amateur Radio in and around the Red River Valley Area of Northeast Texas

  • Home
  • About
    • Contact Us
    • Leadership
  • Membership
    • Member Login
    • The Benefits of Membership
    • Join Us/Renew
    • Profile
    • Member Directory
    • Logout
  • Forums
  • Sponsor
  • Search
  • Ham News
  • History
    • Honor Roll
    • Silent Key
    • Club History
    • Storm Chase 3/25/2019
    • February 2019 Meeting
    • Field Day
      • Field Day 2019
      • Field Day 2005
  • Education/Testing
    • Want to become a ham?
    • Testing – ARRL Volunteer Examiner Administered
    • Current DX Spots
    • APRS® Messaging System
  • Library
    • Meeting Minutes
    • “Unofficial” Call Sign List
    • RRVARC Net Call Up Script
    • Manuals – Operating, Instruction, Literature, Spec Sheets, etc.
    • Band Plan Illustrations
    • Cross Band Repeater Operation – Charles Penry (WA5VHU) – Recommended Best Practices
    • How to obtain an official copy of your FCC license
    • Governing Documents – Approved
    • Club Reports and Recurring Obligations
    • Governance Project
    • RRVARC-WB5RDD INVENTORY LIST
  • Club Repeaters
  • Shop
  • Officers Only
    • Media Contacts
    • Treasurer’s Reports
    • Texas Required Filings
    • Membership Applications
    • Website Management
    • Website Updating – Tips – Tricks
    • Cellular Hot Spots
Home » Topics » General Ragchew » Water Cybersecurity: The “War Game” Is Starting to Look Less Hypothetical

Water Cybersecurity: The “War Game” Is Starting to Look Less Hypothetical

  • This topic has 2 replies, 3 voices, and was last updated 4 weeks, 1 day ago by Cliff Leath (KI5OPP).
Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • August 11, 2026 at 5:03 am #49329
    Phillip BeallPhillip Beall (W5EBC)
    Keymaster

      All,

      A few weeks ago I posted a WIRED article describing a war game built around a large-scale cyberattack on the U.S. water system. We talked about what could happen if thousands of utilities were disrupted, the cascading effects on hospitals, food, communications and other infrastructure, and—most importantly—what ordinary people might realistically do to become a little more resilient.

      I followed that with another post looking at the smaller-scale attacks already occurring against municipal water systems and some practical options for our area, including stored water, wells and rainwater catchment.

      Unfortunately, this subject keeps becoming less theoretical.

      On August 10, The Washington Post published a detailed piece titled “Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks.”

      Original article:
      https://www.washingtonpost.com/national-security/2026/08/10/us-water-systems-are-low-hanging-fruit-cyberattacks-experts-warn-after-suspected-iranian-hacks/

      The original article is behind a paywall. For anyone who would like to read it and does not have access to The Washington Post, an archived copy is also available here:

      http://archive.today/L1szh

      The Post reports that cyber incidents involving water systems have now been identified in at least twelve states, with at least 30 systems affected in Minnesota alone. U.S. intelligence agencies reportedly believe Iran’s Islamic Revolutionary Guard Corps is behind the current campaign, although the government has not yet made a formal attribution.

      That distinction is important. “Suspected Iranian hackers” is not the same thing as a publicly proven attribution, and I don’t think we gain anything by getting ahead of the evidence.

      But who is doing it is almost secondary to the lesson the attacks are giving us.

      The troubling part is how little sophistication may be required

      America has more than 150,000 water systems, and their cybersecurity capabilities vary enormously. A major metropolitan utility may have dedicated cybersecurity personnel and sophisticated monitoring. A small rural water system may have a handful of employees trying to keep pumps, tanks, wells, treatment equipment and billing systems running on a limited budget.

      That makes smaller systems attractive targets—not necessarily because an adversary particularly cares about a town of 500 or 5,000 people, but because an exposed system may simply be easier to reach.

      One Arkansas rural-water official quoted by the Post made essentially that point: small communities tend to wonder why a foreign government would possibly care about them. His answer was that attackers may simply go after whatever they can reach.

      That may be the most important sentence in the entire discussion.

      We tend to imagine critical-infrastructure cyberwarfare as somebody breaking into a giant control room serving New York, Dallas or Los Angeles.

      The reality may be much less dramatic.

      An internet-connected controller in a small town can be critical infrastructure too.

      There is also a useful success story

      One part of the article that particularly caught my attention involved Cedar Rapids, Iowa.

      Their water-control systems are essentially isolated from the public internet. According to the city’s utilities director, people have repeatedly suggested connecting the system externally, and he has consistently refused because of the hacking risk.

      As a result, Cedar Rapids was largely insulated from this particular type of attack.

      There is an old security principle hiding in there:

      Something that cannot be reached remotely is considerably harder to attack remotely.

      That doesn’t eliminate every threat. Physical access, insiders, compromised equipment and other problems still exist.

      But sometimes resilience isn’t about buying the newest piece of cybersecurity technology. Sometimes it means asking whether a critical machine needs to be connected to the Internet in the first place.

      The political argument shouldn’t obscure the engineering problem

      The Washington Post article spends considerable time discussing attempts by the EPA and Congress to impose cybersecurity requirements on water utilities.

      In 2023, the EPA attempted to require cybersecurity assessments as part of water-system security reviews. Arkansas, Iowa and Missouri challenged the approach in court, arguing in part that EPA had exceeded its authority and that the requirements would impose costs on small communities. The EPA eventually withdrew the policy. New legislative proposals are now being considered, including approaches that would establish minimum cybersecurity standards while providing more assistance to rural utilities.

      There are legitimate questions about federal authority, unfunded mandates, one-size-fits-all regulation and how a town with a tiny water budget is supposed to pay for another government requirement.

      There is also a legitimate national-security question:

      What happens when thousands of small public utilities operate equipment that adversaries can reach from halfway around the world?

      Those two concerns can both be true.

      Whatever one’s politics, the engineering problem doesn’t care which party wins the argument.

      And this brings us back home

      This is why I’ve been posting these water pieces.

      I’m not suggesting that everyone run out tomorrow and drill a $20,000 well, install a 5,000-gallon cistern and start preparing for the end of civilization.

      I am suggesting that water deserves a place fairly high on our personal and community preparedness lists.

      The previous WIRED war game showed what a massive attack could look like.

      The attacks we’re seeing now show what smaller real-world intrusions do look like.

      The scale is different, but the vulnerability is the same.

      For an individual household, that might justify some stored potable water, a good filtration method, knowledge of nearby alternative water sources, or a rain-catchment system that can provide non-potable water.

      None of those things makes us completely independent.

      They simply buy time.

      And in most emergencies, time is exactly what preparedness is supposed to buy.

      Where amateur radio fits

      There is another reason this subject belongs on a ham-radio club forum.

      We aren’t going to repair somebody’s SCADA system with a handheld radio.

      But if a utility disruption occurs at the same time that commercial communications are congested, damaged or unavailable, reliable local communications become enormously valuable.

      Questions start coming quickly:

      Is this neighborhood affected?
      Is water pressure gone everywhere or only in one area?
      Has a boil-water notice been issued?
      Where is bottled water being distributed?
      Does a shelter have water?
      Does a hospital, nursing home or other facility need assistance?
      Which information is official, and which is merely something somebody posted on Facebook?

      Those are exactly the kinds of situations where established nets, trained operators and relationships with local emergency-management organizations can provide useful situational awareness.

      The value isn’t the radio.

      The value is having people who already know how to communicate accurately when normal systems aren’t working normally.

      One final thought

      When I started this series, the first article involved a hypothetical Chinese cyberattack war game.

      Then we started seeing actual attacks against American municipal water systems.

      Now federal officials and the water industry are openly debating minimum cybersecurity requirements because attacks have reportedly spread across at least a dozen states.

      I’m not interested in scaring anybody.

      I am interested in recognizing trends before we are standing in the middle of one wondering why nobody thought about it beforehand.

      Water, electricity and communications are three systems most of us use every single day without thinking very much about how they get to us.

      Maybe the useful exercise isn’t asking:

      “Will somebody hack our water system?”

      A better preparedness question might be:

      “If our normal water service were unavailable for three days—for ANY reason—what would I wish I had done beforehand?”

      Cyberattack, tornado, ice storm, equipment failure or broken main—the household problem at the faucet looks remarkably similar.

      I’d be interested in hearing what others think, particularly anyone with municipal-water, industrial-control, networking, cybersecurity, emergency-management or public-works experience.

      And from the ham/EmComm side: Have any of you ever participated in an exercise where loss of municipal water was part of the scenario? If not, perhaps that is something worth thinking about for a future exercise.

      As I’ve said before, I’m not trying to promote fear or turn everybody into a full-time prepper. I’m trying to stimulate some thought.

      A little forethought today can make a very bad day considerably more manageable.

      73,

      Phillip Beall (W5EBC)

      August 11, 2026 at 8:12 am #49330
      Keith Mumaw (KI5VNL)
      Participant

        This is all excellent food for thought and water survival should be on everyone’s mind.  I am currently working on a Power Point Presentation for the club and will share it as soon as it is completed.  But until then, excellent points, both on the ham radio side and the preparedness side.

        73

        Keith

        ki5vnl

        August 11, 2026 at 12:08 pm #49331
        Cliff Leath (KI5OPP)
        Participant

          Thank you for taking the time to share this.  It’s definitely worth thinking about

           

           

        • Author
          Posts
        Viewing 3 posts - 1 through 3 (of 3 total)
        • You must be logged in to reply to this topic.
        Log In

        Footer

        Who We Are

        Red River Valley Amateur Radio Club (RRVARC) is a licensed FCC radio operator (WB5RDD) and an affiliate of the American Radio Relay League (ARRL) – The National Association for Amateur Radio®.

        Club members – hams – are persons interested in amateur radio operations and public service. The Club and its members participate in public service events such as the Tour de Paris, Field Day and educational activities, as well as during emergency preparedness activations.

        Non-Profit Organization

        The RRVARC is a 501(c)3 tax-exempt organization.

        Where We Meet

        The Red River Valley Amateur Radio Club meets at Paris Municipal Court (2910 Clarksville St, Paris, TX 75460) usually on the 4th Saturday of each month.

        Note: Special events like Field Day and some November and December meetings are excepted.  Check the events calendar for special location, dates and time.

        Website contents and logo Copyright Red River Valley Amateur Radio Club (RRVARC). Please email the webmaster (admin@rrvarc.org) with additional content or corrections.