Can we avert catastrophe?

 

(Ars Electronica)

For decades, Americans have thought of cyberattacks as an annoyance.

If we thought of them at all.

Someone steals credit card numbers. A hospital pays ransomware. A social media account gets hacked. These incidents can be expensive and disruptive, but they usually remain confined to the digital world.

That assumption is becoming dangerously outdated.

The next generation of cyberattacks may not be aimed at your computer. They may be aimed at your water.

Recent attacks on water utilities across multiple states offered an unsettling glimpse of the future. According to federal authorities, hackers altered passwords and network settings on industrial control systems that help operate water infrastructure. Some utilities temporarily lost the ability to control their own equipment, forcing operators to switch to manual operations and issue precautionary boil-water notices.

Fortunately, the systems continued functioning, and no widespread public health disaster occurred.

Not yet, anyway. But the warning light persists.

America’s critical infrastructure — including water systems, electric utilities, pipelines, transportation networks and hospitals — is largely connected to the internet, dependent on computer systems protected by outdated software. That connectivity makes these systems more efficient and easier to monitor. It also creates opportunities for foreign adversaries to interfere with physical infrastructure from thousands of miles away.

This represents a profound shift in national security.

The countries most often associated with these operations are familiar names: China, Russia, Iran and North Korea. Their objectives differ. China tends to focus on long-term espionage and positioning itself inside critical networks. Russia has used cyber operations as an instrument of political warfare and disruption. Iran has demonstrated a willingness to target symbolic civilian infrastructure. North Korea frequently uses cybercrime to generate revenue for the regime.

Artificial intelligence doesn’t change who America’s adversaries are.

It changes what they can accomplish.

Large language models and other AI tools can write convincing phishing emails in flawless English, analyze software for vulnerabilities, summarize technical manuals, automate reconnaissance and help less experienced hackers perform tasks that once required years of training. AI has not created cyberwarfare — but it is making cyberattacks faster, cheaper and easier to scale.

That is a dangerous combination because America’s critical infrastructure remains remarkably uneven in its defenses.

The United States has roughly 170,000 drinking water and wastewater systems alone. Many are operated by small municipalities with limited budgets, aging equipment and only a handful of IT personnel. Some industrial control systems still rely on outdated software or basic security practices that would not meet modern standards. In too many cases, foreign intelligence services are probing networks defended by organizations that struggle simply to maintain their pipes and pumps.

The result is an alarming imbalance.

America’s adversaries can organize cyber operations at the national level. America’s defenses often remain local.

So what can be done?

There is no one silver bullet.

There are many.

The first priority is making critical infrastructure much harder to penetrate. Many successful cyberattacks still exploit surprisingly ordinary weaknesses: default passwords, outdated software, poorly secured remote access or industrial equipment unnecessarily connected to the public internet. Basic cyber hygiene — multifactor authentication, network segmentation, regular software updates and offline backups — would dramatically reduce the number of successful intrusions.

Infrastructure should also be redesigned with the assumption that attackers will eventually get inside.

Instead of trusting software alone, engineers can build physical safeguards into critical systems. Chemical treatment equipment should have hardware limits that prevent dangerous overdoses. Pumps should not be able to shut down entire regions without multiple human approvals. Water plants should retain the ability to operate manually if automated systems fail.

The goal is not merely preventing cyberattacks.

It is preventing cyberattacks from becoming physical disasters.

Artificial intelligence also has an important defensive role to play.

Just as AI can help attackers identify vulnerabilities, it can help defenders monitor millions of network events simultaneously, detect unusual behavior and flag suspicious commands before they affect real-world equipment. Future AI systems may function as digital sentries, continuously watching for anomalies while human operators retain authority over critical decisions.

But technology alone cannot solve what is ultimately a geopolitical problem.

The United States also needs stronger deterrence.

Today’s cyber responses often consist of sanctions, criminal indictments or diplomatic protests issued long after an attack has occurred. Those measures rarely alter the strategic calculations of governments that view cyber operations as relatively inexpensive, difficult to attribute and unlikely to provoke serious retaliation.

Future trade agreements could begin changing that equation.

Imagine if countries receiving preferential access to American markets agreed not to target civilian infrastructure such as water systems, hospitals or electrical grids. Violations could automatically trigger tariff increases, export restrictions, financial sanctions or suspension of technology licenses. Rather than threatening vague consequences after an attack, the penalties would already be written into the agreement.

Likewise, America’s allies could agree that significant attacks on civilian infrastructure would trigger coordinated economic responses rather than isolated national protests. A hostile government might ignore one country’s sanctions. It would find it much harder to dismiss simultaneous action by the United States, Europe, Japan, Australia and other major economies.

The objective is not to eliminate cyber conflict entirely.

Espionage between nations will continue, just as it always has.

The objective is to establish clear norms that place hospitals, water systems and other essential civilian infrastructure beyond the acceptable boundaries of state competition.

None of these measures is sufficient on its own. Better software will not stop determined foreign intelligence services. Sanctions alone will not prevent cyberattacks. AI will not permanently outsmart other AI. International agreements will not persuade every authoritarian regime to abandon cyber operations.

But together they can change the underlying economics of cyber conflict.

If America’s critical infrastructure becomes significantly harder to penetrate, if attacks are detected more quickly, if physical safeguards prevent catastrophic consequences, and if hostile governments know that successful operations will trigger immediate and meaningful economic costs, the strategic calculation begins to change.

Cyberattacks become less attractive.

That is the real objective.

No single measure would eliminate the threat. But together they could change the attacker’s calculation from cheap, deniable and potentially disruptive to difficult, likely to fail and economically costly.

That is how catastrophe is most likely to be averted — not by building an impenetrable digital fortress, but by ensuring that America’s enemies conclude it simply is not worth trying.

(Contributing writer, Brooke Bell)