The recent wave of cyberattacks targeting U.S. water utilities is not a series of isolated incidents but part of a broader campaign targeting vulnerable infrastructure. Federal agencies, including CISA, have warned that additional attacks are likely. Defense contractors should pay attention because these attacks offer a preview of how adversaries are likely to approach smaller and mid-sized defense contractors.
These incidents are a reminder of how our adversaries think, how they operate, and where they believe they can achieve the greatest return for the least amount of effort. While Iran-nexus cyber groups are not the most advanced threat actors, low skill does not mean low risk. If you’re part of the Defense Industrial Base (DIB), there are several important lessons to learn before similar campaigns reach the defense supply chain.
Attackers frequently target the organizations with the fewest resources. Many of the recent campaigns focused on smaller and mid-sized water utilities rather than the nation’s largest metropolitan systems. That shouldn’t surprise anyone. Smaller organizations often have fewer cybersecurity personnel, tighter budgets, and less mature security programs. The same reality exists throughout the DIB.
For years, many small and medium-sized defense contractors assumed they were simply too small to be targeted. Not only is this a misread of the threat environment, but in many cases, it is the exact opposite of reality. Foreign adversaries understand that a smaller subcontractor with weaker defenses can provide valuable intelligence, sensitive technical data, or a pathway into larger defense programs.
Many of the recent intrusions relied on familiar weaknesses, including vulnerable internet-facing devices, exposed remote access services, default or absent credentials, and end-of-life equipment no longer receiving security updates.
These were not sophisticated “zero-day” exploits. Attackers simply connected to internet-accessible controllers, then changed passwords and IP addresses to lock legitimate operators out of their own systems.
Defense contractors sometimes assume that sophisticated nation-state adversaries require equally sophisticated defenses. In practice, attackers often succeed because organizations fail to implement basic security controls consistently.
Earlier this year, we analyzed 130 real-world techniques used by prominent Iranian threat groups and mapped them against the security controls in NIST SP 800-171, the cybersecurity baseline that underpins the Department of War’s Cybersecurity Maturity Model Certification (CMMC). The highest-leverage controls including monitoring, configuration management, baseline hardening, and malicious code protection, address these same underlying failures. Secure configurations and hardened baselines help prevent devices from being exposed with default credentials in the first place, while monitoring and malicious code protection help determine whether an intrusion is detected before significant damage occurs.
The scale and speed of these campaigns should concern every executive, because automation is fundamentally changing the economics of cyberattacks.
Threat actors no longer need to handcraft attacks against every organization they wish to target. Automated reconnaissance, vulnerability scanning, credential harvesting, and increasingly AI-enabled capabilities allow adversaries to identify and exploit thousands of potential targets simultaneously. AI will only make this process faster, cheaper, and more scalable, lowering the barriers for less sophisticated actors while increasing the volume of attacks that defenders must confront.
To cause that disruption, attackers are increasingly targeting operational technology (OT), such as industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. While defense contractors may not operate water treatment plants, they do operate manufacturing equipment, robotics, testing environments, production lines, logistics infrastructure, and other operational technologies that support the warfighter.
Protecting operational resilience is just as important as protecting sensitive information. The Department of War’s Office of the Chief Information Officer has recently highlighted this same issue, underscoring the growing importance of securing operational technology across the defense ecosystem.