Defending US Water Systems: A PacketViper Perspective
A response to the CyberScoop op-ed “The US needs a real plan to defend its water systems,” mapping each element of its five-part plan to agentless, preemptive protection that can be deployed today.
7 pages • Published October 2026
Download the PDF Book a demo →The short version
The op-ed names the real obstacle to defending water systems: the cost and complexity of adopting stronger technical defenses across a highly fragmented sector. PacketViper’s Automated Moving Target Defense (AMTD) architecture removes the assumptions that make most OT security hard for utilities: no agents on controllers, no staffed SOC, no multi-year integration project. The phase-ins in any federal plan will take years. A preemptive, agentless layer can protect the control equipment utilities already run today.
A note on how to read this
This paper is commentary and analysis of a published op-ed, read against PacketViper’s stated architecture and field experience. Customer references are anonymized. Where PacketViper complements a recommendation rather than fulfilling it, the paper says so.
What prompted this paper
On October 5, 2026, CyberScoop published an op-ed by Franklin D. Kramer, Robert J. Butler and Melanie J. Teplinsky arguing that the United States needs a real plan to defend its water systems. The trigger was this summer’s campaign by Iranian actors against water systems in 12 states. CISA has reported that more than 100 internet-exposed water systems were targeted in July alone, most often through programmable logic controllers (PLCs) connected directly to cellular modems.
The authors propose a five-part federal program. The paper summarizes each element on its own, then looks at how PacketViper’s architecture, already deployed in water and wastewater environments, is positioned to deliver it affordably, at AI speed, and at every scale from a single unmanned lift station to a utility with hundreds of sites.
The plan, element by element
The paper covers six items. For each, it sets out what the op-ed calls for and how PacketViper addresses it:
1. Zero trust architecture
Zero trust enforced at the network layer, because PLCs, RTUs and HMIs cannot run an agent and speak protocols such as Modbus and DNP3 that have no authentication. PacketViper sits inline as a transparent Layer 2 bridge with no readdressing, and allows only the device-to-device conversations a utility defines. Enforcement is scoped to the device, never the subnet, and deployment follows a “start open, narrow in” sequence.
2. Formal methods and code mending
A compensating control for software that cannot yet be replaced or patched. Command-level Modbus protection inspects unit ID, function code, register address and the value being written, so a historian can read tank levels while writes to a chemical-dosing register from an untrusted source are stopped at the wire.
3. Support for large water systems
Federated, centrally managed enforcement across many sites, with a block detected at one unit propagated to every other unit in milliseconds, and Automated Moving Target Defense (AMTD) that keeps changing what an adversary doing long-dwell reconnaissance can map.
4. Assistance for midsize water systems
A light-touch platform for utilities with an IT team but no 24/7 security operations center: most installations complete in hours, not weeks, and one platform consolidates functions that would otherwise take several separate tools.
5. A safe operations posture for small water systems
The Remote Security Unit (RSU): a ruggedized, DIN-rail appliance installed inline in an existing cabinet. Reads for remote monitoring stay open, while writes from untrusted sources, logins from unapproved geographies and sessions outside approved windows are blocked. It keeps enforcing if the link to the central office drops.
6. An AI-capable cybersecurity cohort
AI readiness in both directions: AMTD and enforcement against AI-speed attacks, and an on-premises AI advisory so no operational data leaves the utility.
One architecture, every tier
The paper’s common thread is that every element of the plan runs into the same constraint, cost and complexity multiplied across nearly 50,000 systems of very different sizes. A defense that reaches the sector has to work the same way at the smallest site and the largest: agentless inline enforcement, protocol-native control down to individual commands, AMTD, an autonomous edge that keeps enforcing without a live connection, and deployments measured in hours.
PacketViper offers a proof of concept against a real environment as a standard option. Learn about the proof of concept.
Talk to us about your water or wastewater environment
If you run, regulate or advise a water or wastewater system, we would welcome the conversation.
Book a Demo Download the PDF ↓