This summer, somebody went after the water.
By the FBI's count, intruders took control of industrial computers at water systems in at least seven states — some later reporting puts the number higher. These were not defense contractors or power grids with 24-hour security operations. They were small water systems: the kind with a handful of employees, a part-time board, and a treatment plant most residents drive past without noticing. In at least one Minnesota town, operators lost their controls entirely and ran the plant by hand.
The attackers did not need a software flaw. According to the FBI and EPA, they found programmable logic controllers — the small industrial computers that run pumps, valves and treatment cycles — sitting directly on the public internet, and changed the devices' IP addresses and passwords. Operators lost monitoring and control. Some reverted to running their plants by hand; CISA's alert records boil-water notices and sustained manual operations, at water entities of all sizes. Security researchers at Forescout, scanning on August 3, counted 4,407 of these devices reachable from the open internet worldwide — about two-thirds of them in the United States, and half of the global total the same controller model named in the federal advisory.
Researchers who examined the campaign found no confirmed exploitation of any software vulnerability. There was nothing to patch. The controllers were reachable, and they answered. The advisory on the water-system intrusions names no attacker. But a joint federal advisory first published in April had already tied a broader campaign against internet-connected industrial controllers — including in the water sector — to an Iranian-affiliated group active since at least March. Who was on the other end matters less than it seems: the fix is the same either way.
That changes the question for Vermont. It is not whether our water systems are running unpatched software. It is whether anyone at those systems is responsible for asking.
Vermont knows the answer to that, because Vermont asked.
In 2024 the state's Cybersecurity Advisory Council — created by the legislature in 2023 to advise on protecting critical infrastructure — surveyed critical-infrastructure operators across the state. The survey was deliberately built to expose nothing: anonymous, no technical detail, no way to identify a single organization or weakness. One hundred nineteen organizations started it. Seventy-seven finished.
The results sorted into three roughly equal groups. One had an established cybersecurity program. One had started but had nothing dedicated. One had not started at all.
Roughly a third of the Vermont critical-infrastructure organizations that completed the state's own survey reported no cybersecurity program of any kind. That figure deserves a caveat, and the caveat cuts against comfort rather than toward it: these were self-selected respondents. Organizations that sit down and finish a 39-question cybersecurity survey are, as a group, the ones already paying attention. The operators who never opened it are unlikely to be in better shape.
The plan
In January 2025 the Council published a strategic plan built on that finding. Three tiers of help, matched to the three levels of maturity: training and planning at the bottom, risk assessment in the middle, threat-sharing at the top. A pilot — Phase 1 — was to begin in calendar year 2025, focused on organizations supporting Vermont's hospitals.
In September 2025, presenting to a legislative oversight committee, the Council listed all three tiers under "Next Steps." Delivery was still described as planned.
In January 2026 the Council filed its next annual report. It records a productive year of a certain kind: presentations and outreach, engagement with federal partners, testimony in Washington, a letter backing federal grant matching funds, sector working groups formed, and — concretely useful for small towns — state IT retainer contracts extended so municipalities can hire vetted vendors quickly after an incident.
What it does not record is the pilot. Neither the September 2025 update nor the January 2026 annual report describes any organization receiving entry-level training or a risk assessment.
It also does not record any money. The plan flagged its own dependency in 2025: realizing its goals "will be dependent on available funding." No appropriation for the tiers appears in either report, and neither contains a dollar figure. The Council's one recorded budget action in three years is a letter — endorsing the state's matching-funds request for a federal cybersecurity grant program that is now in its final year.
The 2026 report then reprints the 2025 strategic plan essentially word for word — including the sentence saying Phase 1 is "planned to be start [sic] in calendar year 2025." Its own executive summary, eight pages earlier, explains that the Council has moved away from that approach, because each sector has different needs and continuing with "one size fits all" "will likely help none." The report says the plan will not work, and reprints the plan.
For 2026, the Council also cut its own meeting schedule from every other month to quarterly.
What it asked for. What it got.
The Council has also told the legislature, in writing and twice, what it needs in order to reach the systems most at risk.
In its 2025 report it asked for one added seat: a representative of the telecommunications and internet service industries. It did not get it.
In January 2026 it asked again, and added a second request — a seat for local government. Its reasoning was explicit: "Many of the small, rural, critical infrastructure operators are owned by municipalities (water, wastewater, electric, emergency services, and transportation systems) and having representation will help to ensure efforts of the Council meet their needs."
In the final week of the 2026 session, the legislature did amend the Council. Not through a cybersecurity bill. The standalone measure, H.560, had been introduced in January by three House members — including the chair and ranking member of the very committee it was referred to — and never received a recorded action after it arrived there. The change came instead as an addition to a data broker bill, in language the House committee handling that bill had never taken up before it came back from the Senate. It passed on a voice vote as part of the package. The governor signed it June 16; the change took effect July 1.
It added three members: the chairs of the House and Senate committees that handle information technology, and a representative of the judiciary. It also extended the Council's expiration date from 2028 to 2033.
Two legislators and a judge. Neither seat the Council asked for. Among the seats it did create: one for the chair of the committee where the standalone bill sat.
H.560 was not the only water-security measure parked at that committee. S.213, passed by the Senate in March, would have made cybersecurity a condition of running a public water system on smart meters — and directed the Secretary of Natural Resources to develop cybersecurity measures for every public water system in the state. It was the only bill of the session that would have actually required Vermont water systems to protect themselves. In written testimony to the committee that April, the general manager of the Champlain Water District — who noted he also holds the Council's water seat — told lawmakers the bill's cybersecurity language "is not necessary," because "the CAC legislation already incorporates what is in this bill."
The committee took the testimony. Neither bill moved again before adjournment. The only mandate of the session was set aside on the assurance that the Council already had it covered — the same Council whose own report, filed three months earlier, reprinted a plan it said will likely help none.
The timeline deserves one more date. The joint federal advisory on the controller campaign was first published April 7 — one week before the committee took that testimony. The session adjourned in June. The mass attacks on water systems began six weeks after that.
Water does hold a chair, and has since the Council was created — one representative of a state municipal water system, appointed by the Secretary of Natural Resources. The seat is held by the general manager of the Champlain Water District, among the largest and best-resourced water utilities in the state. The Council's own position is that the small rural systems are still not in the room.
What can't be known
This story names no Vermont town and identifies no vulnerable system, and that is partly by law. The 2023 act that created the Council gave it an exemption from the public records act covering cybersecurity standards, protocols and incident responses where disclosure would jeopardize public safety, along with expanded authority to meet in executive session. Whether any specific Vermont utility is exposed is not a question the public record can answer.
It is also not the important question. The state surveyed its own critical infrastructure, found roughly a third of respondents at zero, wrote a plan, and eighteen months later has no delivered pilot to show for it — while the seats it says it needs to reach the smallest systems sit empty.
The fix for what actually happened this summer, meanwhile, costs almost nothing. What a small Vermont water system can do this week — most of it free, most of it an afternoon.

Comments