The war with Iran has come for U.S. infrastructure. A cyberattack last month affected more than 30 Minnesota water systems and 11 other states, according to a government report. There are no reports of water contamination or human harm, but some utilities have reported pressure loss and flooding. It was sufficiently severe that several municipal utilities disabled digital controls and switched to manual operations. Intelligence agencies and federal authorities believe that Iran-backed hackers are behind the attack, and a hacking group closely tied to Iran has claimed responsibility.There is broad agreement that U.S. water utility security controls are outdated and cannot keep pace with rapidly evolving cyber threats. A recent inspection by the Environmental Protection Agency revealed that roughly 70% of U.S. water systems failed to meet basic cybersecurity standards. Specific identified problems include unchanged default passwords, reliance on factory-set credentials that hackers can quickly find online, single shared logins, former employee accounts that remain active, and failure to immediately cut off network access upon threat detection, among others.Local water utilities struggle to address such threats alone, given their small scale and limited resources. The Bureau of Labor Statistics estimates there are about 51,700 water and wastewater treatment plant and system operators in the United States. More than half have only one or two employees, while roughly 85% have three or fewer staff members, who of necessity must perform a variety of tasks. Many are also rural, rely on a single part-time certified operator, and are small enough to be viewed as “micro-systems.”