Pre-Positioned
Part III: Iran wants you to know it was there. China does not. One is a crime scene, the other a countdown, and for two years the government has been saying so in language nobody read closely.
Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science, Emerging Infectious Disease / Epidemiology. DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.
Bottom Line Up Front
Part II ended on a hopeful note, and I want to take it back. The utilities that came through Minnesota intact did so because a public works crew could run the plant by hand. That is true. It is also conditional, and this piece is about the condition.
Manual operation requires a person who can reach the plant, a way to coordinate with the people who are not at the plant, and a pump that turns. All three of those run on electricity, and two of them run on a telephone network that a foreign intelligence service has been living inside for years.
Seven judgments, each with my confidence on a 0 to 100 scale.
1. Chinese state-sponsored actors have maintained persistent access inside the IT networks of US critical infrastructure organizations, in some cases for years. This is not an allegation. It is the published finding of CISA, the NSA, the FBI, and their Five Eyes counterparts. High confidence, 92.
2. The purpose of that access is pre-positioning for disruption, not collection. This is the federal assessment rather than a fact on the ground, and it is the single most consequential judgment in this piece. Moderate to high confidence, 85.
3. Salt Typhoon is a different operation with a different mission. It is collection. Treating the two as one story is the central analytic error in the popular coverage, and it leads directly to the wrong policy response. High confidence, 88.
4. The lawful intercept systems that US law requires carriers to build were among the systems compromised. The access path was mandated by statute. High confidence, 85.
5. Electricity is the master dependency. Water, telecommunications, fuel distribution, and health care are all downstream of it, and the manual-operation defense that worked in Minnesota is downstream of it too. High confidence, 90.
6. The bulk electric system has binding, enforceable cybersecurity rules with real financial penalties. Drinking water has none. That asymmetry is a policy choice, and it is reversible. High confidence, 95.
7. Whether this pre-positioning will be activated, and when, is not knowable from open sources. Anyone telling you they know the timeline is telling you about their priors, not about the evidence. My confidence in any published claim of imminent activation: 20.
The discipline for this piece is a single distinction, and I will repeat it until it is boring. Confirmed access is not predicted timing. Espionage is not disruption. Presence is not intent.
I. Two Ways In
Everything in Parts I and II was about a loud adversary. Iran-affiliated actors reached exposed controllers, changed IP addresses, set passwords on devices that had none, and in the Aliquippa case in 2023 left a banner on the screen announcing themselves. CyberAv3ngers wants credit. The message is the product.
That is a specific operational model and it has a specific tell: the effect is visible immediately, and it is meant to be. An operator locked out of a screen knows within minutes. A defaced HMI is a self-reporting incident. Whatever else you can say about the July campaign, the utilities found out.
Now consider the opposite model. An intruder gets into the network of an electric utility and does nothing. No ransomware. No banner. No exfiltration large enough to trip a data loss alarm. They map the environment, learn which accounts have which privileges, identify the path from the business network to the operational one, and then they wait. Their entire objective is that you never notice.
You do not detect that with the tools built to catch the first model. And for a period measured in years, the United States did not.
II. What Volt Typhoon Actually Is
On 7 February 2024, CISA, the NSA and the FBI, joined by their counterparts in Australia, Canada, the United Kingdom and New Zealand, published joint advisory AA24-038A. The title is dry: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure. The content is not.
Three findings from that document matter, and I want to give them to you in the government’s framing rather than mine.
The dwell time. The authoring agencies stated that in some cases the actors had maintained access and footholds within victim IT environments for at least five years. Five years is not an incident. It is a tenancy. It means the intrusion predates most of the security tooling deployed to find it, and it means the adversary has watched several complete cycles of staff turnover, budget approval, and equipment replacement.
The sectors. Communications, Energy, Transportation Systems, and Water and Wastewater Systems, across the continental United States, its non-continental territories, and Guam. Note the fourth sector on that list. The water utilities in Part II were not a separate story. They were the same story, arriving loudly two years after a quieter version had already arrived.
The purpose. This is the sentence the whole piece turns on. The agencies assessed that the actors were pre-positioning themselves on IT networks to enable lateral movement to operational technology assets in order to disrupt functions, in the event of a major crisis or conflict with the United States. Not to steal. To be in place.
The tradecraft has a name that sounds almost gentle: living off the land. Rather than installing malware that a scanner can recognize, the intruder uses the administrative tools already present on the machine. PowerShell. Windows Management Instrumentation. Native remote access utilities. The commands they run are the same commands a system administrator runs. There is no malicious file to find because there is no file.
Understand what that does to detection. Conventional security asks whether anything foreign is present. Living off the land makes that question return the wrong answer, because nothing foreign is present. The right question is whether the legitimate tools are being used by the legitimate people at legitimate times for legitimate reasons, and answering it requires a baseline of normal behavior that most organizations have never established.
The record did not stop in 2024. CISA published further advisory material in April 2026 on China-nexus covert networks of compromised devices, describing infrastructure assembled from routers and appliances belonging to ordinary businesses and households, used to make hostile traffic look domestic. And the Office of the Director of National Intelligence carried the threat forward in its 2026 Annual Threat Assessment. This is a continuing federal finding, not a single alarming press cycle from two years ago.
III. What Salt Typhoon Actually Is
Now the other one, and it is a different animal entirely.
Beginning in 2024, a separate Chinese state-linked group compromised American telecommunications carriers. Not one. According to FBI figures, the operation touched more than 200 US organizations across some 80 countries. Among the systems reached at multiple carriers were the lawful intercept platforms.
Sit with that for a moment, because it is the most under-appreciated fact in American cybersecurity.
The Communications Assistance for Law Enforcement Act requires American carriers to build and maintain the capability to intercept communications on lawful order. The United States government mandated that a door exist. A foreign intelligence service found the door and walked through it.
This is not an argument about whether lawful intercept should exist. It is an observation about what happens when a capability is mandated across an entire industry, standardized for the convenience of the entity requesting it, and maintained by companies whose incentive is to satisfy an audit rather than to defend a system. The mandate created a common architecture. A common architecture is a common vulnerability.
The mission here is collection, and the reported targeting reflects it: call records, communications metadata, and the phones of senior political figures. That is classic signals intelligence performed through a commercial network rather than a satellite. It is enormously damaging, and it is a different thing from what Volt Typhoon is doing.
Two further facts belong in the record, both from Congress rather than from journalists.
In December 2025, the Senate Commerce Committee concluded that American networks remained vulnerable and that the major carriers had not convincingly demonstrated they had evicted the intruders. In February 2026, Senator Maria Cantwell reported that AT&T and Verizon had declined to release the network security assessments their own contractor had produced. Whatever the carriers know about the current state of their networks, Congress does not know it, and neither do you.
The public posture from the carriers in late 2024 was that activity had been contained. The joint advisory language describing persistent, long-term access is difficult to reconcile with that, and nobody has been made to reconcile it.
IV. The Distinction Everyone Collapses
Two Chinese operations, both real, both federally documented, running at the same time against overlapping targets. The coverage has fused them into a single sentence, usually some version of China is inside our infrastructure. That sentence is true and nearly useless, because the two operations imply completely different responses.
Here is the discipline, and it is the same instrument from Part I pointed at a harder problem.
Espionage is not disruption. Salt Typhoon is stealing. That is grave, it is a counterintelligence catastrophe, and the correct response involves architecture, encryption, and a serious conversation about mandated interception. But an adversary reading your call records does not turn off your water.
Presence is not intent. Volt Typhoon’s presence is documented. Its purpose is assessed. That is not a weaker claim made by cowards; it is an honest description of the evidentiary state. Access can be observed forensically. Intention must be inferred from what the access is positioned to do, which is why the agencies chose the word pre-positioning rather than something more definite.
Confirmed access is not predicted timing. This is where public commentary fails hardest. Knowing that someone is inside a system tells you nothing whatsoever about when, or whether, they will act. There is no public evidence supporting any specific timeline, and every confident prediction you have read about a date is an argument about geopolitics wearing the costume of an intelligence finding.
Why the distinctions matter practically. If the problem is collection, the answer is cryptographic and architectural, and it is largely a telecommunications policy question. If the problem is pre-positioned disruption, the answer is segmentation, isolation, and the ability to keep operating while compromised. Those are different budgets, different regulators, and different engineering. An organization that reads the fused headline and buys the wrong one has spent its money and increased its confidence without reducing its risk.
And a note on the failure mode in the other direction, because this series holds itself to symmetry. In April 2025 the Iberian Peninsula suffered a massive blackout, and within hours a substantial share of the internet had concluded it was a cyberattack. The official investigation found no evidence of one. It was a cascading failure in a power system, of the kind power systems have always been capable of producing on their own. If your model says every large outage is an attack, you will be wrong most of the time, and you will be wrong in the direction that gets budgets spent on the wrong thing.
V. Electricity Is the Master Dependency
Now the systems argument, which is the reason this part sits where it does in the series.
Critical infrastructure sectors are not a list. They are a directed graph, and almost every edge points back to one node. Water treatment is pumping, and pumping is motors, and motors are electricity. Telecommunications switching centers and cell sites run on power, with batteries and generators buying hours rather than weeks. Fuel distribution depends on pumps at terminals and card readers at stations, both electric. Hospitals have emergency generators sized for a defined endurance and a fuel contract that assumes the roads work and the supplier has power to pump.
Every one of those systems is engineered to survive losing power for a while. Almost none of them are engineered to survive losing power for a long while, at the same time as their neighbors, in a situation where the entities they would call for help are also down.
Trace it against the specific claim Part II ended on.
Manual operation needs a person at the plant. In a regional outage, that person is driving on roads with dark traffic signals, in a vehicle they may not be able to refuel, because gas station pumps are electric.
Manual operation needs coordination. A water system is not one building. It is wells, booster stations, towers and lift stations spread across a county. Running it by hand means people at multiple sites talking to each other. That is a phone call, on a network that has batteries measured in hours and, per the federal record, an uninvited long-term resident.
Manual operation still needs pumps to turn. Manual means a human making the decisions instead of the controller. It does not mean a human providing the horsepower. If the plant is on generator, the run time is bounded by the fuel in the tank and the ability of a truck to bring more.
So the honest version of Part II’s conclusion is this: the ability to run the plant by hand is the most effective control the water sector currently has, and it is a control against a cyber intrusion in an otherwise functioning world. It is not a control against the loss of the thing the plant runs on. Braham restored service in ninety minutes because Braham had power, phones, roads, and a supplier. Take those away and the same crew with the same skill produces a different outcome.
This is not a reason for despair. It is a reason to notice that resilience planning in this country is done sector by sector, by agencies that do not share a regulator, against scenarios in which only their own sector fails. The adversary is not planning that way, and the interdependency is where the actual risk lives.
VI. The Rule That Does Exist
Part II established that there is no binding federal cybersecurity requirement on American drinking water utilities. Here is the part that makes that finding sting: for the electric grid, there is.
The North American Electric Reliability Corporation’s Critical Infrastructure Protection standards are mandatory. They are approved by the Federal Energy Regulatory Commission, they apply to owners and operators of the bulk electric system, and they carry statutory civil penalties of up to one million dollars per violation per day, adjusted for inflation. They cover asset identification, security management controls, personnel and training, electronic security perimeters, physical security, system security management, incident reporting and response planning, recovery, configuration and vulnerability management, information protection, supply chain risk, and physical security of the most critical substations.
Compare the two sectors on the only measure that matters, which is whether anybody can make you do anything.
A generation and transmission operator that leaves a controller exposed faces an enforceable standard, an auditor, and a fine. A water utility that does the same thing faces a suggestion. The largest publicly disclosed CIP penalty settlement, against a single utility, was roughly ten million dollars. The entire federal grant program for water cybersecurity was authorized at less than eight times that per year and appropriated a fraction of it.
I am not arguing that NERC CIP is a triumph. Practitioners will tell you it can become a compliance exercise, that the paperwork can crowd out the engineering, and that an auditor’s checklist is not a threat model. All of that is fair. But note what the criticism concedes: there is something to criticize. The water sector does not have a compliance regime that has grown stale. It has nothing.
And notice the gap inside the grid regime too, because this series does not do triumphalism. CIP applies to the bulk electric system, the high-voltage backbone. Local distribution, the wires that actually reach your house and the pumps at your water plant, largely sits outside it. The rules protect the part of the system that a national planner cares about. The part a resident experiences is thinner.
VII. What CISA Asked For on 28 July
Three days after intruders reached thirty Minnesota water systems, and while attribution was still open, CISA issued guidance under an initiative it had launched in May 2026 called CI Fortify. The stated goal of the program is to help critical infrastructure operators achieve the ability to operate during and through cyberattacks. The 28 July guidance asked owners and operators for something specific: a pre-engineered, tested capability to isolate their operational systems from everything else.
Read that against the two adversary models and it clicks into place.
You cannot promise to keep every intruder out of an environment where the intruder uses your own administrative tools and has been resident for years. That is a losing formulation, and the agencies appear to have stopped making it. What you can do is guarantee that when you decide to sever the connection, the plant keeps running. Isolation is a capability, not a posture. It must be built, documented, and rehearsed before the day you need it, because on the day you need it you will not have time to discover which cable to pull.
This is the same insight Part II arrived at from the other direction. The Minnesota utilities that came through intact were the ones that could take the control system out of the loop and keep delivering water. CI Fortify is that capability, generalized and demanded in advance rather than improvised under fire. It is the correct ask. It is also, so far, an ask rather than a requirement, which returns us to Section VI.
One institutional observation, offered as a fact rather than a complaint. The agency issuing this guidance is doing so while its own proposed budget for infrastructure assessment work runs at a little over half of the current year’s, and while the information sharing statute that underpins the reporting relationship expires on 30 September. The mission is expanding and the resourcing is not. Whatever you think about the size of the federal government, an organization asked to do more with less will do less, and the part it stops doing will be the part nobody is counting.
VIII. Red Team
The strongest objections to what I have argued, and my answers.
“You are amplifying a China threat narrative that serves defense contractors and hawks.” The load-bearing claims here are quotations from joint advisories signed by five governments, from congressional committee findings, and from a senator complaining that companies would not hand over their own reports. If that constitutes a narrative, it is one the evidence built. I have also refused the part of the narrative that sells best, which is the timeline, and scored it at 20.
“Pre-positioning is an assessment, not a fact. You are treating it as one.” I am not, and I have scored it separately at 85 precisely so you can discount it independently of the 92 I gave to the access itself. If you believe the access is real but the purpose is ordinary espionage that happens to look like staging, the practical conclusion barely changes: an intruder resident in your network for five years is intolerable regardless of what they meant to do with it.
“Salt Typhoon proves lawful intercept is the problem, and you dodged that.” I raised it and then declined to litigate it, which is a fair thing to notice. My view is that the mandate created a standardized, industry-wide access path and that this is a structural finding independent of anyone’s position on encryption policy. The full argument is a piece of its own and I am not going to smuggle it in here.
“You undercut your own Part II conclusion.” Yes, deliberately. Part II said manual operation was the control that worked, and it was, against the threat Part II was describing. This part shows the boundary of that claim. A method that will not correct its own prior conclusions when the evidence widens is not a method.
“The Iberian blackout is a straw man. Nobody serious said it was an attack.” Serious people did not. Very large numbers of people did, within hours, and the correction never traveled as far as the claim. That asymmetry is the whole subject of Part I and it is why the example belongs here.
Next in Soft Targets
Part IV, “From the Fire to the Fork.” Back to Postville, and to the conspiracy theory that grew out of it. I am going to debunk the food plant fire narrative properly, with the numbers, and then show you the thing it has been crowding out: the JBS ransomware shutdown of 2021, precision agriculture, the cold chain, and a fungus in a smuggler’s luggage. The false story about American food is doing real damage, and the largest part of that damage is the attention it steals from the true one.
References
[1] Joint Cybersecurity Advisory AA24-038A, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure,” CISA, NSA, FBI and international partners, 7 February 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
[2] CISA, “People’s Republic of China Threat Overview and Advisories.” https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china
[3] CISA Advisory AA26-113A, China-nexus covert networks of compromised devices, April 2026. https://www.cisa.gov/news-events/cybersecurity-advisories
[4] CISA, CI Fortify initiative, launched May 2026; operational guidance on pre-engineered isolation capability, 28 July 2026. https://www.cisa.gov/
[5] Office of the Director of National Intelligence, Annual Threat Assessment of the U.S. Intelligence Community, 2026. https://www.dni.gov/index.php/newsroom/reports-publications
[6] FBI and partner reporting on Salt Typhoon scope, more than 200 US organizations across approximately 80 countries.
[7] U.S. Senate Committee on Commerce, Science, and Transportation, “Cantwell Demands AT&T, Verizon CEOs Come Clean on Salt Typhoon Hacks, Ongoing Network Security Risks,” February 2026. https://www.commerce.senate.gov/2026/2/cantwell-demands-at-t-verizon-ceos-come-clean-on-salt-typhoon-hacks-ongoing-network-security-risks
[8] Nextgov/FCW, “Senator says AT&T and Verizon blocked release of Salt Typhoon security reports,” February 2026. https://www.nextgov.com/cybersecurity/2026/02/senator-says-t-and-verizon-blocked-release-salt-typhoon-security-reports/411172/
[9] Lawfare, “Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon.” https://www.lawfaremedia.org/article/reconfiguring-u.s.-cyber-strategy-in-the-wake-of-salt-typhoon
[10] Communications Assistance for Law Enforcement Act, 47 U.S.C. 1001 et seq. https://www.law.cornell.edu/uscode/text/47/chapter-9
[11] North American Electric Reliability Corporation, CIP Reliability Standards. https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx
[12] Federal Power Act section 316A, civil penalty authority for violations of reliability standards, as adjusted for inflation. https://www.ferc.gov/enforcement-legal/enforcement
[13] FBI and EPA Public Service Announcement on water and wastewater sector PLC targeting, 30 July 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions
[14] CISA Alert, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” 30 July 2026. https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
[15] GAO-26-109159, testimony on cybersecurity threats to the water and wastewater sector, 21 May 2026. https://www.gao.gov/assets/gao-26-109159.pdf
[16] Red Eléctrica and Spanish government investigation into the 28 April 2025 Iberian Peninsula blackout. https://www.ree.es/en
[17] Congressional Research Service IF12959, “The Cybersecurity Information Sharing Act of 2015: Expiring Provisions.” https://www.congress.gov/crs-product/IF12959







Is there any way to move the needle on this issue other than for Federal regulatory enforcement? In my experience, FERC audits do drive some accountability, but the road to get there is frequently carved through intentional complexity and obfuscation that did not improve the security posture of the utility, but created enough complexity that the RF auditor does not understand what is going on.
For example, instead of having point to point secure encrypted tunnels with segmentation/isolation and tight ACLs with IDS/IPS/logging/layer7 inspection, corporate IT at a utility will route traffic back through a zone Z configuration so that it takes 6 people on the same web meeting to troubleshoot anything. This lack of intentional visibility makes items nearly impossible to audit. It causes RF auditors to fail to spot the security failure.
Excess complexity that results in a lack of ability to audit is a very serious vulnerability.
I would rather see an approach that couples or partners water utilities with certified information technology security experts such as network security architects that have decades of experience in the OT space. These people exist. But the municipalities are not looking for them. All it would take is one person per utility to function as the consultative network security architect. That person could audit, formulate an engineering plan, project manage and execute migrations and corrective actions, and produce the legal attestation documentation required.
My estimate is this would cost $36,000 per year for a continuous improvement approach that introduces change at a pace that matches not only what the utility can absorb in terms of budget for labor but also the pace of change that the environment can handle politically.
The approach would need to be assess, strategic plan, engineering plan, budget, procurement, remediation. All the while, improving operational maturity. Where asset inventory is lacking, rectify that. Where a GRC is missing, implement it. There are open source GRCs and open source asset inventory platforms. There are no excuses. They can be self-hosted in an isolated supply-chain risk managed approach.
It's all about the political will to solve the problem. The local municipalities need to get the political will to correct the issues. Municipal leaders are probably asking "are we good? are we fine?" The correct line of questioning should be show me the non-tamperable legal attestation of configurations that prove continuous configuration and state of the environment coupled with has that information been audited by someone qualified to do that work?