What can attacks on America’s water systems teach us about counter-UAS?

At a glance: Recent attacks on U.S. water utilities expose a risk counter-UAS programs should examine closely. Physical defenses can be degraded through the digital infrastructure used to connect, manage and control it, even when the sensors, applications and effectors themselves have not been physically damaged.

Rob Spalding, Founder and Chief Executive Officer, SEMPRE
Aug 17, 2026
Perspective

Counter-UAS programs are being asked to move quickly, integrate more capabilities and protect many locations. Speed matters but adding capable components does not eliminate the dependencies between them. Instead, it increases the importance of getting those dependencies right…A defense that depends on normal gives an adversary too many ways to disrupt.

By Rob Spalding, CEO, SEMPRE | Brigadier General, U.S. Air Force (Ret.)

In late July, water utilities across at least seven states began reporting a strange and consequential problem. Operators were losing the ability to see and control equipment they depended on to run their systems.

Malicious actors had remotely accessed internet-facing programmable logic controllers, changed IP addresses and passwords, and interfered with the digital control layer between operators and physical equipment. The FBI and EPA reported operational consequences that included loss of pressure and flooding.

There is one detail that deserves more attention. Across several victims, investigators found similarities in network setups provided by third parties. The FBI said those similarities may have given the attackers an opportunity to repeat their success wherever the same vulnerable hardware and network configurations existed.

That should sound familiar to anyone trying to field complex technology fast.

We standardize because we want systems that can be deployed, integrated and supported repeatedly. Done well, that gives us enormous leverage. Done poorly, we can reproduce the same weakness just as efficiently as we reproduce the capability.

Counter-UAS is a particularly important place to think about that problem.

A modern c-UAS solution is rarely one product. It may combine equipment and software from several companies, tied into existing installation infrastructure. The value comes from what the whole environment can do together.

And that creates a second problem to defend.

We spend a great deal of time asking whether a sensor can detect the threat, whether software can classify it, and whether an effector can defeat it. We should because those are fundamental measures of performance.

But the mission also depends on whether a detection can become trusted information, reach the applications and people that need it and remain available, even when someone is trying to interfere with the infrastructure it travels on.

That last piece is easy to overlook because management traffic isn't the thing the operator came to use.

Until an attacker gets hold of it.

The water attacks show how quickly a cyber intrusion can become an operational problem. In some cases, changing a PLC’s configuration was enough to leave operators without visibility into, or control over, connected equipment. The FBI responded by urging utilities to reduce direct internet exposure, tightly control remote access, restrict communications to authorized devices, watch for lateral movement and isolate critical functions where possible.

So we ask, how much of the infrastructure the defense depends on is exposed to an adversary?

Protect the system that manages the system.

There is a reason cybersecurity architects separate different kinds of traffic.

NIST's 2026 guidance for 5G infrastructure recommends isolating the data plane, the control plane, and operations-and-maintenance traffic. Each performs a different job and separating them reduces the opportunity for access or disruption in one part of the environment to spill into another.

SEMPRE applies the same principle to the infrastructure we build, including an out-of-band control path that separates administration and control from user traffic. The user-facing environment is electronically isolated from that control interface.

That architectural choice becomes much easier to understand when you stop looking at cybersecurity as a checklist of protections and start looking at what an attacker is trying to accomplish. An attacker does not have to damage a sensor or effector to disrupt the mission. Interfering with the infrastructure that carries data, runs applications or manages the system can be enough to break the chain between detection and response.

The defense is only as strong as the infrastructure underneath it.

Counter-UAS programs are being asked to move quickly, integrate more capabilities and protect many locations. Speed matters but adding capable components does not eliminate the dependencies between them. Instead, it increases the importance of getting those dependencies right.

The water attacks are a warning because the attackers did not need to defeat the physical system directly. They found a way through the infrastructure used to manage it.

Counter-UAS leaders should assume an adversary will look for the same kind of leverage.

Test the environment as a whole, not just the performance of each component. Disrupt communications. Compromise an administrative credential. Take an external service offline. Introduce a misbehaving connected system. Then see what still works, what fails safely and how quickly operators can recover.

A defense that depends on normal gives an adversary too many ways to disrupt.

Image Caption: SEMPRE T fielded at AFCENT Titan Hoplite 3 2025

Ready to try a 30-day pilot to see what changes? Connect with our team to learn more.

Related articles