Recent weeks saw a surge in cyberattacks targeting water utilities and a sharp increase in AI-driven threats against small businesses. With federal support receding and attackers exploiting both legacy technology and new AI tools, business leaders must adapt strategies to protect their revenue, reputation, and operational continuity.


Water Utilities Targeted: Operational Disruption and Trust at Stake
Last week, the FBI and EPA issued a joint warning: cybercriminals are actively targeting water and wastewater utilities by exploiting weaknesses in internet-facing control systems, particularly Programmable Logic Controllers (PLCs). Since late July, incidents across at least seven states have caused operational disruptions ranging from service slowdowns to partial shutdowns. Many affected utilities serve mid-sized or rural communities—precisely the segments with limited cybersecurity resources.
Supporting this, a Cybersecurity and Infrastructure Security Agency (CISA) investigation found that core water system controls in at least a dozen states were left exposed online, either with default or no password protection. The impact: direct operational risks, the potential for regulatory scrutiny, and lasting damage to public trust. Utility operators face systemic vulnerabilities that, if exploited, can halt essential services for businesses and residents—an outcome that undermines confidence not just in utilities, but in local economies reliant on them.
The issue extends beyond technical missteps. Many utilities, like other small enterprises, lack the funding and expertise to overhaul aging systems or maintain enterprise-grade network hygiene. The result is a widening gap between attackers’ capabilities and the defensive posture of organizations managing critical infrastructure, with attackers capitalizing on both complacency and budget constraints.


AI Changes the Game—and Federal Support Shrinks
While infrastructure attacks raise alarm, there is another dimension: AI is supercharging cybercrime against small and mid-sized businesses overall. TechRadar Pro’s latest report illustrates this sharp evolution: 82.6% of phishing emails now leverage AI, a year-on-year jump of over 50%. These attacks scan for neglected digital assets—like outdated domains or weak email authentication—and craft credible messages designed for speed and scale. Many small businesses, relying on in-house or ad hoc cybersecurity, struggle to keep pace as AI removes barriers for attackers.
This increased risk arrives as CISA, the key federal cyber support agency, is scaling back outreach to businesses and utilities most in need. Budget-driven staff reductions are leaving smaller organizations to fend for themselves, signaling a shift in how cybersecurity support must be sourced and prioritized. Meanwhile, security leaders are urgently discussing AI governance and adversarial risks—topics covered at the recent SecurityWeek AI Risk Summit. Strategic questions about AI adoption, secure deployment, and risk management are moving from theory to boardroom priorities.
Patterns: Rising Threats, Shrinking Safety Nets
The pattern is clear. Attackers are blending old and new—targeting neglected industrial controls as well as exploiting the opportunities created by AI. They move quickly when federal or industry resources stretch thin, especially as oversight shifts away from smaller entities. Business continuity, not just IT security, is at risk.
Security conversations are migrating away from technical teams and toward executive leadership. CEOs and business owners must weigh the reputational and operational costs of inaction, especially in sectors where trust and service delivery are inseparable from business value. The expectation is no longer perfection, but visible, deliberate investment in resilience and governance—even for organizations with limited resources.
What Business Leaders Should Consider
- Audit all internet-facing systems and ensure default or weak passwords are eliminated—prioritize essential infrastructure and customer-facing platforms.
- Develop a communications plan for customers and stakeholders in the event of operational disruptions or data incidents to preserve trust and avoid reputational fallout.
- Upgrade email and domain security by adopting industry standards (e.g., SPF, DKIM, DMARC) to reduce AI-driven phishing success rates.
- Budget for cybersecurity skill-building, whether by training existing staff or engaging external partners, as federal outreach services contract.
- Monitor the AI landscape and participate in peer or industry networks to gain timely intelligence on evolving cyber risks and defense strategies.
