Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science, Emerging Infectious Disease and Epidemiology, DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.
Bottom Line Up Front
Five parts of this series described what is wrong with the systems that keep you alive. This one is about money and about ownership, and it is the only part where the finding is not technical.
Nothing across this series required a discovery. The vulnerability in the water sector was disclosed and patched in 2021. The adversary pre-positioned in American infrastructure was documented by five governments in 2024. The advisory describing this exact technique against these exact controllers was published on 7 April 2026. The attacks arrived on 26 July. Every material thing that happened this summer was known, written down, and circulated in advance. The systems did not fall to a superior enemy. They were sitting open, and the people who could have closed them were not asked to, could not be reached, or had just been cut.
Six judgments, each with my confidence on a 0 to 100 scale.
1. The warning existed, was specific, and was public more than three months before the campaign began. High confidence, 95.
2. The federal function responsible for carrying that warning to small operators was reduced by roughly three quarters over the same year. High confidence, 88. This is the finding of this piece.
3. The continuous risk-management process that is supposed to own this outcome is not being run, and is now being defunded so that it cannot be. Assessed, 85.
4. On 30 September 2026 the federal information-sharing statute and the water cybersecurity grant programs expire on the same day. High confidence, 92.
5. The obstacle is not money. The cost of closing these gaps is small against the cost of one bad week. The obstacle is that no institution owns the outcome. Moderate to high confidence, 82.
6. This is a governance failure, not a partisan one, and treating it as partisan is the most reliable way to guarantee it continues. High confidence, 98.
I have no interest in whether you think the federal government should be larger or smaller. I have an interest in whether the thing it was asked to do is being done, and in whether anyone can tell you who is responsible when it is not. Across six parts the answer has been the same, and here it is in one line: the failure is never that a defense was defeated. It is that no one owned the outcome.
I. The Warning
Fix the sequence in your mind, because the sequence is the argument.
On 7 April 2026, CISA, the FBI, the NSA, the EPA, the Department of Energy, and US Cyber Command’s national mission force jointly published advisory AA26-097A. It described Iranian-affiliated actors exploiting internet-exposed programmable logic controllers across US critical infrastructure. It named the equipment. It named the sectors, including water. It described the technique, which was not sophisticated: find the device on the public internet, and use the credentials that were never changed. On 22 July the advisory was updated, expanding the manufacturer scope and adding detection guidance.
On 26 and 27 July, intruders reached more than thirty Minnesota water systems and utilities in at least six other states, using that technique against that equipment. On 30 July, CISA published an alert urging operators to remove publicly exposed controllers from the internet, and the FBI and EPA issued a joint notice describing loss of pressure and flooding.
One hundred and ten days separate the warning from the attack. The warning was correct in every material respect. It was free. It was published by six federal agencies at once. And when the attacks came, thousands of the devices it described were still sitting on the open internet. So the question this part exists to answer is not why nobody knew. Everybody knew. The question is what stands between a correct federal warning and a person in a small town who could have acted on it, and why that thing has been getting thinner.
II. What Was Cut, and Where
Here are the numbers, plainly, and then the ones that actually matter, because the headline figure is not the important one.
CISA’s workforce was projected to fall from 3,292 positions to 2,324, a reduction of roughly a third. In practice the agency lost on the order of a thousand people through a combination of voluntary departures, early retirements, and terminations. Operational funding was set to fall from about 2.38 billion dollars to about 1.96 billion, a cut of more than 420 million, with total agency funding down by roughly 495 million.
Those are large numbers and they are not the finding. Agencies shrink, and a third is severe but survivable if the cuts are distributed against mission priority. Look instead at where the reductions landed.
Cybersecurity division: 1,267 to 1,063. A cut of about 16 percent to the largest technical division.
Infrastructure security division: 343 to 325. Almost untouched, about 5 percent.
Integrated operations: 827 to 500. A cut of about 40 percent.
Risk management operations: 179 to 58. A cut of about 68 percent.
Stakeholder engagement and requirements: 200 to 53. A cut of about 73 percent.
Read the last two again, because that is the whole piece. Risk management is the function that works out which assets matter most and where the national exposure actually sits. Stakeholder engagement is the function that carries a federal warning to an operator who is not on a classified distribution list, does not attend conferences, does not belong to an information-sharing organization, and has three employees. Those two divisions are how a document written in Arlington becomes an action taken in Braham, Minnesota. Between them they went from 379 people to 111.
Now recall the shape of the sector they were meant to reach. Roughly 680 water and wastewater systems belong to WaterISAC, out of something on the order of 170,000 systems. About one percent. The other ninety-nine percent have no threat-sharing membership, and the federal function designed to reach them was cut by nearly three quarters in the same year the warning had to travel. The agency did not fail to produce the warning. It produced an excellent warning, on time, with six agencies behind it. What was dismantled was the last mile.
III. The Framework, Starved
This is where the series closes its own loop, so hold the two facts together.
The United States runs critical infrastructure protection as a continuous risk-management cycle, not a filing cabinet. Under the National Infrastructure Protection Plan the framework is a loop: set goals, identify the critical assets, assess the risk to them with the best available science, prioritize, act, measure, and feed the result back into the next turn. It is meant to be evidence-driven and to run without stopping across the whole enterprise. A specific, credible warning about a live campaign against named equipment is exactly the input that loop exists to ingest and act on. It is the assess-and-notify-and-act step, handed to the process on a plate.
The loop did not turn. The warning was issued and then, for the ninety-nine percent of the sector that no federal hand can now reach, it went nowhere. And the two divisions whose job is precisely to turn that step of the loop, to assess where the exposure sits and to carry the notice to the operator, are the two that were gutted. That is the finding stated at the level of the machine rather than the incident. The process that is supposed to own this outcome was already running thin, and the budget removed the people who run it. A risk-management enterprise that cannot execute its own notify step on a warning its own agencies wrote is not a shield with a gap in it. It is a shield being quietly set down.
IV. What Expires on 30 September
Now the calendar, which is the part that makes this piece urgent rather than merely accurate.
The Cybersecurity Information Sharing Act of 2015. The statute that gives a company liability protection when it shares threat information with the government and with other companies. Without it, an in-house lawyer’s advice on whether to report an intrusion changes materially, and the honest version of that advice is often to say nothing. The law already lapsed once, at the end of September 2025, was briefly revived, extended into January 2026, and then extended again to 30 September 2026. It expires that day.
The water cybersecurity grant programs. The two EPA programs for water-system cyber resilience lapse after fiscal year 2026. They were authorized at a combined 75 million dollars a year and appropriated a fraction of that; the first 9.5 million for midsize systems was announced in late 2025. They end on the same day.
And the next request goes lower. The Government Accountability Office told Congress in May 2026 that the following year’s request for infrastructure-assessment work runs at about 58 percent of the current year, and that stakeholder-engagement work is requested at about 65 percent below the current year. The division already cut by three quarters is scheduled to be cut again.
So on 1 October, unless something changes: the law that makes information-sharing safe is gone, the money that was helping small systems is gone, and the office that reaches those systems is a third of the size it was two years ago, with a further reduction requested. I am not claiming any of these decisions caused the Minnesota attacks; that would be exactly the causal overreach this series has spent five parts refusing. What I am claiming is narrower and harder to answer. The warning was correct and it did not arrive, and the functions responsible for making it arrive were reduced by roughly three quarters in the same period. Whether or not that link is causal, it is the connection a serious after-action review would have to examine, and no such review has been announced.
V. Follow the Money
Some proportion, for scale, because absolute numbers in the federal budget mean nothing without something to hold them against.
The entire federal grant program for water-system cybersecurity was authorized at 75 million dollars a year across two programs, and appropriated far less, to protect a sector of roughly 50,000 community water systems serving essentially the whole population. Against that, hold one number this series already established. The Milwaukee Cryptosporidium outbreak of 1993, a single treatment failure in a single city, produced a cost of illness later estimated at 96.2 million dollars. One event, one city, thirty-three years ago, cost more than the annual national authorization for preventing the digital version of it. A single day of national water outage has been estimated in the tens of billions.
This is not a story about scarcity. Ten million dollars was authorized for the Water Risk and Resilience Organization proposed in H.R. 2594, a bill that would create actual enforceable standards for the sector, and that bill has sat in committee since April 2025 without a markup, a hearing, or a floor vote. The money is not the constraint. The constraint is that no institution owns the outcome.
The water sector has no regulator with authority. The grid has one. Health care has an outcome-measurement gap that no agency is required to close. Food and agriculture equipment has no cybersecurity oversight at all. And the theft of a critical infrastructure targeting product can be reported to eight agencies and investigated by none. In each case the failure is not that someone made a bad decision. It is that there is no one whose job it is to make the decision.
VI. The Part That Is Addressed to You
This is the only section in six parts that is not analysis, and I have earned the right to write it by spending the previous five refusing to.
If you run a water system. Everything the federal government asked for in July is free and takes days rather than months. Get the controllers off the public internet. Find the cellular modems, including the ones a vendor installed during a service call years ago and never wrote down. Set unique passwords and revoke access for people who have left. Put the key switch in RUN. Join WaterISAC, which costs 125 dollars for the smallest systems and nothing at all for many. And rehearse manual operation with the person who normally does it away, because that is the control that actually worked in Minnesota.
If you sit on a hospital board. Ask two questions at the next meeting. What is our downtime procedure for a fourteen-day loss of the electronic record, and when did we last rehearse it with clinical staff rather than IT staff? And which hospitals are within diversion distance of us, what is their security posture, and who is talking to them? The second question is the one nobody asks and it is the one that determines your exposure.
If you are a legislator or you employ one. Three specific things, none of which require agreeing about anything else. Reauthorize the information-sharing statute before 30 September rather than after. Move H.R. 2594 to a hearing so the water-sector question is argued in public instead of dying quietly. And require that cyber incident reporting be linked to clinical outcome data, so the country can measure the harm in health care using its own official statistics rather than waiting for academics.
If you are a citizen with no professional stake. Two things. Know how your household gets water and for how long it holds without power, because that single fact converts an abstract risk into a plan. And when the next incident happens, hold the line this series has been about: ask what is known, what is assessed, and what is not yet knowable, and notice who is skipping straight to certainty. The composure of the public is a real element of national defense. It is the only one you personally control.
VII. Red Team
The strongest objections to what I have argued, and my answers.
“This is a partisan attack on an administration’s budget.” The withdrawal of the water cybersecurity rule happened under one administration after litigation brought by states and industry associations. The workforce reductions happened under another. The information-sharing statute has now lapsed or nearly lapsed under both. The Water Risk and Resilience Organization bill was introduced by a Republican and has been ignored by two Congresses. If you can build a partisan story from that record, you are working harder than the facts require.
“You are arguing that a bigger agency would have prevented this.” No. I am arguing something more specific and more falsifiable: that a correct warning failed to reach the operators who needed it, and that the function responsible for that delivery was reduced by roughly three quarters in the same period. If someone can show me the last mile was covered by another mechanism that worked, I will withdraw the finding. Nobody has shown me that.
“Small utilities would not have acted on the warning anyway.” Some would not have. Braham, Minnesota acted after the fact in about ninety minutes, which suggests the technical lift was never the barrier. And the claim that recipients would have ignored the warning is not an argument against delivering it. It is an argument for finding out, which requires delivering it first.
“Your action list is thin for a six-part series.” It is short because the fixes are short. That is the actual scandal, and I would rather leave it looking thin than pad it. Nothing in the July campaign required a novel defense. It required a password and an inventory.
“You cannot show the cuts caused the attacks.” Agreed, and I said so explicitly rather than letting you infer it. The causal claim is unavailable and I am not making it. The correlation in time is documented, the mechanism is plausible, and the appropriate response is an after-action review that nobody has called for. Refusing to overclaim is not the same as having no claim.
Where This Series Ends
Six parts ago I said that most people cannot tell an attack from an accident, and that both errors get people killed. Everything since has been an attempt to demonstrate that carefully enough to be useful.
What the record actually shows is less dramatic than the headlines and considerably worse. There is no cunning adversary defeating excellent defenses. There is a warning nobody delivered, a controller nobody unplugged, a modem nobody wrote down, a regulator nobody empowered, a mortality effect nobody measures, a stolen target list nobody investigated, and a set of expiration dates nobody has moved. The systems that keep you alive are not falling to a superior enemy. They are sitting open, and the people who could close them have not been asked to.
That is a better problem to have than the one in the headlines, because it is fixable, cheaply, by identifiable people, this year. It is also a worse one, because there is no one to blame and therefore no one who has to answer. A risk-management enterprise that has quietly become a document does not announce itself. It just stops turning the loop, and waits for the next report to arrive and go nowhere.
Thank you for reading all six. The thing I most want you to keep is not a fact from any of them. It is the habit: what is known, what is assessed, what is not yet knowable. Hold that line and you will be right more often than the people who are certain, and you will be much harder to use.
References
[1] Joint Cybersecurity Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” CISA, FBI, NSA, EPA, DOE and CNMF, 7 April 2026, updated 22 July 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[2] CISA Alert, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” 30 July 2026. https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
[3] FBI and EPA Public Service Announcement on water and wastewater sector PLC targeting, 30 July 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions
[4] Government Executive, “CISA projected to lose a third of its workforce under Trump’s 2026 budget,” June 2025. https://www.govexec.com/workforce/2025/06/cisa-projected-lose-third-its-workforce-under-trumps-2026-budget/405817/
[5] Federal News Network, “DHS budget request would cut CISA staff by 1,000 positions,” May 2025. https://federalnewsnetwork.com/cybersecurity/2025/05/dhs-budget-request-would-cut-cisa-staff-by-1000-positions/
[6] Cybersecurity Dive, “CISA workforce cut by nearly one-third so far.” https://www.cybersecuritydive.com/news/cisa-departures-trump-workforce-purge/749796/
[7] GAO-26-109159, “Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector,” testimony, 21 May 2026. https://www.gao.gov/assets/gao-26-109159.pdf
[8] Department of Homeland Security, National Infrastructure Protection Plan and the CI/KR risk management framework. https://www.cisa.gov/resources-tools/resources/national-infrastructure-protection-plan
[9] Congressional Research Service IF12959, “The Cybersecurity Information Sharing Act of 2015: Expiring Provisions.” https://www.congress.gov/crs-product/IF12959
[10] H.R. 2594, Water Risk and Resilience Organization Establishment Act, 119th Congress, introduced 2 April 2025. https://www.congress.gov/bill/119th-congress/house-bill/2594/text/ih
[11] EPA, “Cybersecurity in Sanitary Surveys,” and the October 2023 withdrawal memorandum. https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys
[12] Corso PS et al., “Costs of Illness in the 1993 Waterborne Cryptosporidium Outbreak, Milwaukee, Wisconsin,” Emerging Infectious Diseases, April 2003. https://wwwnc.cdc.gov/eid/article/9/4/02-0417_article
[13] WaterISAC membership and dues. https://www.waterisac.org/









I completely agree that this is a governance failure issue. Also completely agree that the issue is ownership/accountability and not a funding issue. These types of problems require someone with the authority to enforce action to spend their political capital to achieve an outcome. I love it: "the failure is never that a defense was defeated. It is that no one owned the outcome."
Consistently you describe ownership of outcomes as being the differentiator. Of course, ownership also means accountability. This is no different than the BoD of an org owning risk therefore having accountability for risk in the organization. Yet we persistently see that without external enforcement either by customers driving “proof of state” transparency or perceived risk of non-compliance with insurance, that organizational leadership rarely moves to support initiatives to proactively close gaps. The security stewardship that occurs is being done by operations personnel that engage in the proactive due diligence and risk management on their own that has no additional cost to the entity so there is nothing to deny. When they have not asked for more resources, and they just do it along with everything else they are doing, it just gets done.
I can understand the cutting of CISA personnel from the perspective that the agency was politicized and used as a weapon against the American public while choosing to be completely ineffective where it could have made a difference. In a direct example I know of, CISA was provided hundreds of public facing vulnerability proofs that were all tied to a software provider servicing critical infrastructure. They were handed this issue on a silver platter with copious evidence. All they needed to do was to send letters to the software company telling them to get their act together. But instead, CISA literally closed the case. Closed the ticket without action. That is the epitome of uselessness. At one point, the head of CISA went public claiming that there was no election tampering. It was such a bald-faced lie that all credibility was removed from that individual. As the agency head, that reflected very poorly on the agency as a whole.
As with most things, the Federal government is a poor substitute for local control, local demand, local enforcement.
I took action talking to the local people who should own the accountability verification. Those people are the city, town, village administrators or executives who represent the populace. If they rely on a water utility to service their population, they should care to ask for proof of a regular vulnerability assessment and management program. If they don’t think they have the skill to do that, they should ask for residents who would be willing to volunteer to help out. But instead, I got smirks and disrespectful disregards with statements such as “the water utility is responsible for those items.”
The water utility is never going to make their attestation documentation public. If the representatives of the stakeholders do not step in and ensure accountability on those who are paid to own the problems, I'm seriously doubtful it will ever occur. The populace is equally complicit in the abdication of responsibility to demand accountability.