<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Why are water utilities becoming attractive cyberattack targets?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Water utilities often rely on legacy operational technology, industrial control systems, exposed remote-access paths, and devices that cannot be patched quickly without disrupting operations. Coordinated attacks can also use scalable reconnaissance and attack techniques to target multiple utilities in a short period of time."
}
},
{
"@type": "Question",
"name": "Why is traditional patching becoming less effective for OT cybersecurity?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Patching remains important, but attackers can increasingly analyze newly released patches to understand the vulnerabilities they fix and rapidly develop working exploits. In OT environments, where maintenance windows are limited and some legacy systems cannot be patched without downtime, defenders may not be able to deploy fixes before attackers begin exploiting the underlying vulnerability."
}
},
{
"@type": "Question",
"name": "What is the patch race in cybersecurity?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The patch race is the competition between defenders trying to deploy security fixes and attackers trying to weaponize newly disclosed vulnerabilities. As AI accelerates vulnerability analysis and exploit development, relying primarily on faster patching becomes increasingly difficult, especially for operational technology."
}
},
{
"@type": "Question",
"name": "How does network cloaking protect OT systems?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Network cloaking makes protected OT assets undiscoverable to unauthorized users and devices. Network scanners, reconnaissance tools, malware, and attackers cannot see the PLCs, HMIs, controllers, or other protected systems they would normally attempt to identify and exploit."
}
},
{
"@type": "Question",
"name": "Can network cloaking protect unpatchable legacy OT equipment?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Yes. Network cloaking does not remove the underlying vulnerability, but it can reduce exposure by preventing unauthorized systems from discovering or communicating with the vulnerable device. This provides a protective layer for equipment that cannot immediately be patched or replaced."
}
},
{
"@type": "Question",
"name": "Why does preventing reconnaissance matter for OT cybersecurity?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Most attacks require attackers to first identify reachable systems, services, ports, and vulnerabilities. If an OT asset cannot be discovered through scanning or reconnaissance, attackers lose much of the information they need to select and deliver an exploit. This reduces dependence on winning an increasingly fast patch race."
}
}
]
},
{
"@type": "HowTo",
"name": "How to Reduce OT Exposure Without Relying on the Patch Race",
"description": "A six-step approach to reducing OT cyber risk by identifying exposed assets, prioritizing legacy systems, eliminating unnecessary visibility, deploying network cloaking, enforcing Zero Trust access, and using patching as one layer of defense.",
"step": [
{
"@type": "HowToStep",
"position": 1,
"name": "Identify your most exposed OT assets",
"text": "Inventory PLCs, HMIs, SCADA systems, controllers, engineering workstations, remote-access systems, and other critical infrastructure that could be discovered or reached from untrusted networks."
},
{
"@type": "HowToStep",
"position": 2,
"name": "Prioritize legacy and difficult-to-patch systems",
"text": "Identify devices that cannot be patched quickly because of operational requirements, vendor limitations, certification requirements, or the risk of production downtime."
},
{
"@type": "HowToStep",
"position": 3,
"name": "Eliminate unnecessary network visibility",
"text": "Remove unnecessary exposed services and prevent unauthorized users, devices, and scanners from discovering critical OT systems."
},
{
"@type": "HowToStep",
"position": 4,
"name": "Deploy network cloaking around critical OT assets",
"text": "Use a cloaked network architecture so protected systems do not respond to unauthorized reconnaissance or scanning. Only authenticated and authorized users or devices should be able to establish communication with protected OT resources."
},
{
"@type": "HowToStep",
"position": 5,
"name": "Restrict communication to explicitly authorized connections",
"text": "Apply Zero Trust principles so access is based on verified identity and defined policy rather than simply being connected to the network. Limit each user or device to the specific OT resources required for its role."
},
{
"@type": "HowToStep",
"position": 6,
"name": "Keep patching, but stop making it your only defense",
"text": "Continue testing and deploying appropriate security patches, but treat patching as one layer of defense rather than the primary barrier protecting OT systems. Reducing discoverability and reachability can help protect systems during the period between vulnerability disclosure and patch deployment."
}
]
}
]
}
</script>
When I was a kid, I read Mad Magazine cover to cover, but I always turned to the same page first. Spy vs. Spy. The black spy and the white spy, identical except for color, spend every wordless panel building elaborate traps for each other. One plants a bomb in a mailbox. The other rigs the mailbox to send the bomb back. Nobody ever wins. That was the whole joke, and I loved it.
I loved it enough that I went looking for that world when I grew up. I found it at the NSA while I was in the Air Force. Turns out the trap-and-countertrap game is real; it just does not come with dotted lines and TNT that goes "BOOM" in a little cloud.
Last week I watched the cartoon come to life in Minnesota, and it was not funny at all.
The strip was always right about one thing. It was wrong about the ending.
From July 26 to 27, someone ran a coordinated attack against more than thirty municipal water systems across Minnesota. Plymouth, South St. Paul, Maple Plain, Braham. Small towns, not marquee targets. One treatment plant went offline. Investigators lean toward Iran, tradecraft consistent with CyberAv3ngers and the IRGC crews that have been circling water utilities since 2023.
Thirty utilities in two days. That is not one spy sneaking up on one mailbox. That is a single actor hitting an entire state's worth of targets at once, because in the real version of this game, the attacker got something the cartoon spies never had. Scale.
One spy is a swarm. The other is a silo.
Here is the asymmetry that no one running a control room can afford to ignore. On offense, everyone shares. Exploit kits are open source. Offensive AI tools get forked and passed around like recipes. The people trying to break into your water plant operate as a decentralized R&D lab with thousands of contributors, and each one inherits the previous one's work for free.
On defense, we do the opposite. We lock our best threat intel behind vendor contracts. We hoard indicators. We sign NDAs about the very attacks we should be warning each other about. Braham, Minnesota, will not see what hit Plymouth until a report clears legal review months from now.
So the strip had the wrong picture. It was never one black spy against one white spy, evenly matched. It was one spy who was actually a swarm of thousands, sharing everything, against a spy who was really a thousand isolated defenders not allowed to talk to each other. That game does not end in a stalemate. It ends the way Minnesota ended.
The patch is the trap.
The part that should keep you up at night is what happens when a vendor does the responsible thing and ships a fix. J.P. Morgan's own security team called this year's version of the problem "Patchmageddon," and the number in it is the number I cannot stop thinking about. Median time from a patch being published to that patch being weaponized into a working exploit has collapsed from about a year in 2021 to a single day in 2026. The projection for 2027 is one minute.
Think about what that means in Spy vs. Spy terms. The patch is supposed to be your countertrap. But AI now reverse-engineers the fix into the weapon faster than you can deploy the fix itself. You disclose the vulnerability, you publish the remedy, and in doing so you hand the other spy the exact blueprint of the trap you just set. In OT, where a lot of the gear is legacy and half of it cannot be patched at all without taking a plant down, you are often holding the blueprint and have no way to act on it. You are the spy who built the mailbox bomb and then mailed the instructions to the other guy.
You do not win this game. You leave the board.
I spent enough years inside the trap-and-countertrap machine to tell you the honest thing about it. You cannot win it on speed. Neither cartoon spy ever wins, and they are evenly matched. When your opponent shares everything and weaponizes your defenses in a minute, "faster patching" is not a strategy. It is a treadmill you lose on slightly more slowly.
The way off the board is to stop being a target the trap can find. If your assets are invisible, if a scanner sweeping thirty Minnesota water systems cannot see the controller in the first place, there is no mailbox to rig. The whole game depends on the two spies being able to see each other. Take that away, and the exploit-in-a-minute number does not matter, because there is nothing for the exploit to reach.
I still have digital copies of some old Mad Magazines. I look at those two spies now, and I do not see a joke anymore. I see thirty towns in Minnesota, a water plant that went dark, and a race that gets one minute faster every year. The spies never figured out that the only winning move was to walk away from the mailbox. We still have time to.
Water utilities often rely on legacy OT and ICS equipment, exposed remote-access paths, and devices that cannot be patched quickly without disrupting operations. The Minnesota attacks described in the blog show how one threat actor can target many utilities at once using scalable reconnaissance and attack techniques.
Patching remains important, but attackers can increasingly analyze newly released patches to understand the vulnerabilities they fix and rapidly develop working exploits. In OT environments, where maintenance windows are limited and some legacy systems cannot be patched at all, defenders may not be able to deploy fixes before attackers begin exploiting the underlying vulnerability.
The patch race is the competition between defenders trying to deploy security fixes and attackers trying to weaponize newly disclosed vulnerabilities. As AI accelerates vulnerability analysis and exploit development, relying primarily on faster patching becomes increasingly difficult, especially for operational technology.
Network cloaking makes protected OT assets undiscoverable to unauthorized users and devices. Network scanners, reconnaissance tools, malware, and attackers cannot see the PLCs, HMIs, controllers, or other protected systems they would normally attempt to identify and exploit.
Yes. Cloaking does not remove the underlying vulnerability, but it can reduce exposure by preventing unauthorized systems from discovering or communicating with the vulnerable device. This provides a protective layer for equipment that cannot immediately be patched or replaced.
Most attacks require attackers to first identify reachable systems, services, ports, and vulnerabilities. If an OT asset cannot be discovered through scanning or reconnaissance, attackers lose much of the information they need to select and deliver an exploit. This changes the problem from continuously racing to patch every vulnerability to reducing whether vulnerable assets can be reached in the first place.
Inventory PLCs, HMIs, SCADA systems, controllers, engineering workstations, remote-access systems, and other critical infrastructure that could be discovered or reached from untrusted networks.
Identify devices that cannot be patched quickly because of operational requirements, vendor limitations, certification requirements, or the risk of production downtime.
Remove unnecessary exposed services and prevent unauthorized users, devices, and scanners from discovering critical OT systems.
Use a cloaked network architecture so protected systems do not respond to unauthorized reconnaissance or scanning. Only authenticated and authorized users or devices should be able to establish communication with protected OT resources.
Apply Zero Trust principles so access is based on verified identity and defined policy rather than simply being connected to the network. Limit each user or device to the specific OT resources required for its role.
Continue testing and deploying appropriate security patches, but treat patching as one layer of defense rather than the primary barrier protecting OT systems. Reducing discoverability and reachability can help protect systems during the increasingly short period between vulnerability disclosure and exploit development.
Russian hacktivists compromised a Polish hydropower plant through exposed ports. BlastWave cloaks OT networks, eliminating reconnaissance, exposed endpoints, credentials, and lateral movement entirely.
Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.