Loading...
Loading...
The world is increasingly awash with cybersecurity incidents. In 2025, Americans alone lost over $20 billion in cybercrimes.1 Globally, cybersecurity incidents are becoming more common by the year, and attacks targeting civilian infrastructure have become a regular facet of warfare. Since the Maidan Revolution of 2014, Ukraine has been targeted by Russian hackers attempting to cripple their infrastructure, while Iranian hackers have infiltrated critical infrastructure across the United States amid the recent war.2
Often, the specific target of these hacks is a niche part in a factory that, for example, controls circuit breakers. But why are these niche parts targeted, and what makes them uniquely vulnerable to cyberattacks? In short, the world’s physical infrastructure is built on technology that—while excellent for industrial automation, the tasks it solves—was not built for a world in which every device is connected to the internet.
Operational Technology (OT) is hardware and software that interacts with physical systems. A classic example of OT hardware is a programmable logic controller (PLC), a type of computer designed to automate industrial processes. PLCs were invented in the 1960s to replace more cumbersome forms of industrial automation that many automotive companies possessed at the time.3 They are a key component of any modern factory and make mass production possible.
A whole layer of digital OT facilitates the security and functionality of the physical OT. Network segmentation software ensures that machines are only accessed by authorized users and protocols. Asset management software helps firms audit and track all the OT that they control. Finally, if a hack happens, backup and disaster recovery software enables companies and governments to get their systems back up and running rapidly.
Infrastructure that the world depends on runs through these machines and the digital safety net behind them. Food processors use PLCs to automate ingredient mixing. Water treatment plants use sensors to monitor water tanks and ensure the right chemical mix enters the water to make it clean. Power plants use control systems to regulate how generators and turbines run to produce electricity. It’s easy to imagine how the failure of these systems can produce horrific results. Food processors become unable to make food. Water treatment plants suddenly produce toxic water. Power plants break down, and thousands to millions are affected. Our critical infrastructure could be crippled in countless other ways, owing to the diversity of industries that use OT.
If the consequences of the failure of these machines are so dire, why are they vulnerable? Unfortunately, in industry and government, funds are not available to help construct the digital architecture required to protect our physical infrastructure, which was constructed in a bygone threat landscape. Threat actors are becoming ever more sophisticated in how they hack these systems. Simultaneously, the threat of frontier AI models such as Mythos looms over the horizon, foreshadowing a future in which threat actors have access to frontier models that can easily overwhelm companies and countries without equivalent access. We must rapidly and resolutely prepare for these urgent threats against our critical infrastructure.
No Money for Security
Even the United States, home to some of the world’s most successful cybersecurity companies, struggles with implementing cybersecurity infrastructure. Firms and government agencies, particularly at the state and local level, unfortunately do not spend money to secure their IT/OT infrastructure because of disincentives and/or a lack of funds for infrastructure upgrades.
Firms are disincentivized to spend on cybersecurity broadly because it’s an operating expense, not a capital expense. While more flexible than capex spending, cyber opex strikes executives as a cost-center, which does not motivate them to spend on it. As for OT security spending, the status quo is even worse because OT budgets are split between multiple professionals with different spending priorities.4
Equally, one of the most common challenges that state-level chief information security officers (CISOs) face is lack of budget.5 A plurality of CISOs reported that their budgets for cybersecurity either stayed the same as last year or was reduced.6 Funding is even worse at the local level. For example, the Center for Internet Security (CIS), in its 2024 report, found that of the thousands of local agencies that reported their cyber capabilities, 32 percent were not performing any cybersecurity activities at all or doing them on an ad hoc basis.7
Unsurprisingly, underfunding allows for hacks that cripple organizations. In 2024, Russian hackers breached the water system for a small town in Texas, causing water tanks to flood for nearly an hour.8 Understandably, the local government did not have the budget to protect against this. The city did not even learn about the hack from a city employee but from a software vendor notification. The town’s entire revenue in 2023 was $3.37 million, with no dedicated line item for cybersecurity.9 Overflowing water tanks may seem like a minor threat, but they hint at the access rival powers have to our basic utilities and the catastrophic damage they can inflict. As we have seen in Ukraine, the cost of major OT hacks can be deadly.
Operational Technology as a Target in Warfare
Discussions of large-scale hacks into civilian infrastructure are not idle speculation; they are a major facet of contemporary warfare. Ukraine is the poster child victim of these attacks as the country has dealt with hacks to civilian OT infrastructure for over ten years. After the failure of Russian interests in the Maidan Revolution and the cessation of the Donbas war, Russia continually attacked Ukrainian infrastructure. One of the most infamous state-sponsored hacker groups, Sandworm, has been at the forefront of these attacks on Ukrainian critical infrastructure.10 In 2015, the group used the BlackEnergy malware to hack into SCADA systems in western Ukraine. With access to the substations, they were able to open the station circuit breakers and break the power grid for hundreds of thousands of Ukrainians. Such attacks were repeated at the start of the Russia-Ukraine war. In April 2022, with the Industroyer2 virus, Sandworm crippled the Ukrainian power grid by shutting off multiple electrical substations, leading to the loss of power for over two million Ukrainians.11
Beyond being a terror tactic, Russia hacking Ukrainian power grids is a way to cripple the Ukrainian war effort. There are specific reasons why the Ukrainian power grid is so vulnerable. Poor cybersecurity is the simplest example. Russian hackers were able to shut down power for Ukrainians in the dead of winter with the FrostyGoop malware because the power system was connected to a router directly connected to the internet. With no internal IT security, the hackers could easily wreak havoc by accessing the connected systems.12
Worse, many pieces of OT infrastructure were never even built with security in mind. These systems were not intended for a world of seamless interconnectivity. Modbus, an industrial communication protocol from the 1970s, is a good example: it was built for reliability in isolated factory environments, not for a world in which critical infrastructure is connected to the internet and laid bare by state-backed hackers. When Sandworm deployed FrostyGoop malware against a Ukrainian district’s heating provider, they exploited exactly that flaw. They sent Modbus commands to shut down the power generation systems, cutting off heat for civilians in the dead of winter.13
Outdated OT can also make infrastructure more vulnerable. In 2015, for example, Ukrainian power companies experienced major outages after Russian hackers corrupted the firmware on serial-to-Ethernet converters at electrical substations. These cables exist to enable communication between old and new devices.14 Unfortunately, the serial equipment is often insecure, and the actual converters tend to have a variety of vulnerabilities. In the case of the 2015 hack, the vulnerability is one that the Department of Homeland Security flagged back in 2008. It’s easy to know that an issue exists, but remediating a legacy OT environment issue can take years, if the will is even mustered to undertake such a project at all.
A different kind of vulnerability occurs when outdated OT is forced to work in ways for which it was never intended. With the 2024 FrostyGoop hack, once the Russians infiltrated the Ukrainian IT system, they successfully manipulated the OT. Once they hacked into the PLCs, they prevented users from monitoring how those PLCs were operating.15
After years of attacks, Ukraine today represents an optimistic case. Through experience, Ukrainians have been well-trained and are now highly motivated to fix all cybersecurity issues within their infrastructure. The threat is existential. Much less can be said of companies and countries elsewhere who remain lax in their security; their folly could be catastrophic.
The United States is now getting a taste of these Russia-style OT attacks due to the war with Iran. Already, American OT has been directly targeted by Iranian-backed hacker groups.16 Specifically, they are targeting Rockwell Automation/Allen-Bradley PLCs, which has directly led to PLC disruptions across multiple sites.
This is not the first time Iranian hackers have decided to hack into American critical infrastructure. Back in 2023, a water treatment plant in Pennsylvania was hacked by CyberAv3ngers, an Iranian-backed hacker group.17
At the start of the U.S.-Iran war, the Iranians hacked the medical company Stryker. The hack deleted hundreds of thousands of accounts and disrupted internal communication systems.18 The cause of the hack? A single compromised admin account for Microsoft Intune which allowed hackers to shut down all devices managed on that system.19 If a Fortune 500 company has these vulnerabilities, imagine the ineptitude of most American firms, possessing even less money, resources, and training, in dealing with sophisticated hacks from state-backed actors. Now imagine every anti-American actor having access to tools that enable them to commit crippling attacks at scale.
The Frontier Model Threat
Back in April, Anthropic launched Mythos, a specialized model for cybersecurity work. What they publicly reported has dark implications for everyone’s security. Anthropic’s Red Team, in their preview of the model, found that it successfully located and exploited zero-day vulnerabilities in every major operating system and was capable of writing sophisticated exploits.20 OpenAI has also launched a similar model.21 While the two leading frontier labs are trying to ensure these models do not break the internet through Glasswing and Daybreak respectively, OT systems will still face a variety of challenges because of these models.
To start, security by obscurity is officially over. AI models can rapidly find and exploit bugs in the wild.22 While the diversity of OT equipment used to be something that deterred hackers, this is no longer a barrier. A Mythos-tier model can easily discover and exploit vulnerabilities in these oft-neglected systems.23 And it is unlikely that, say, a municipal water plant will have access to the technology and training needed to patch these issues.
Barring safeguards, models with these types of capabilities will be accessible to everyone. Open-source AI models such as DeepSeek and Kimi are roughly four months behind the state-of-the-art models.24 Unlike American AI companies, Chinese AI model companies such as DeepSeek, Kimi, MiniMax, and Z have not launched equivalent cyber programs.
Already, however, we can see that open-source models are nearly as effective at cyber compared to their closed-source counterparts. An independent safety evaluation of Kimi2.5 revealed that the model had cyber capabilities on par with closed-source models.25 A similar evaluation found the same with DeepSeek v4.26 That level of performance is only a baseline; presumably, the open-source models will keep improving. Now imagine an improved version of one of these models, with its guardrails removed, deployed against American industry and business. If Stryker can be crippled with a single hacked admin account, what disasters could a hacker create with a model that lets one rapidly develop and deploy new exploits?
Cyber Solutions
Thankfully, there are steps the government can take today to defend against these risks and ensure the security of American industry. To start, the Trump administration can ensure its own OT systems are ready for adversarial advanced AI. The administration recently released an executive order on artificial intelligence, one section of which focused on improving the cyber defense of our national security systems.27 The administration must ensure that OT security in these systems, such as industrial control systems on military bases for water and power, is upgraded.
Equally lucky for CISOs and firms looking to secure their operations, there is an existing policy lever that is useful: the tax code. Rather than trying to set formal requirements for cybersecurity spending or formalize existing guidance, a better path forward is to lean into existing financial incentives to make investing in IT/OT easier. This approach is a win-win: firms will be empowered to invest in improving their operations and embrace a flexible, iterative approach to governing connected systems without creating additional regulatory burdens across the economy.
To enable this step-change in preparedness, industry and government should look to existing incentives. The distinction between capex and opex is relevant because cybersecurity has traditionally been viewed as the latter, which dissuades firms from investing in this area. Taking a creative approach to the tax code offers an opportunity to solve this problem with private dollars rather than creating a cumbersome government grant program or expanding regulatory authority.
The biggest opportunity for this “creative reading” was created by updates in President Trump’s One Big Beautiful Bill Act (obbba). Starting with hardware and physical systems, the law enables 100 percent bonus depreciation for eligible macrs property with a recovery period of twenty years or less. This covers a broad swath of components, systems, sensors, and other kinds of equipment. Another opportunity is the 100 percent allowance for qualified production property, which is narrower, but still useful for physical system investments and upgrading. Finally, there is Section 179, which provides elective immediate expensing for tangible property, such as machinery and equipment. The full deduction is capped at $2.5 million per purchase, with reduced dollar-for-dollar expensing up to $4 million, before phasing out after $6.5 million. To secure critical infrastructure and take advantage of software-enabled systems, which have been billed as key for reindustrialization and advanced manufacturing, firms must invest and iteratively improve their plant. obbba lays the foundation to do so.
Moving to firmware and software development, there are three notable sections of the IRC that come into play. First is Section 174A, which allows for full expensing and deduction for software development spending. Firms looking to develop new connected systems with cyber-relevant software and firmware should be eligible for full expensing. Development is key, which creates a mutually beneficial opportunity of exchange: firms providing IT/OT services have a ready market and chance to develop solutions tailored to customer needs while the purchaser is incentivized to invest in needed capacity consistently over time.
Together, these several lines of the tax code can be the key to unlocking necessary investment in IT/OT capabilities. Ensuring that these investments can be made now and sustained over the long term is critical for securing American industrial operations moving forward. Guidance from the White House, in the form of an executive order, in tandem with guidance from Treasury and the Office of Management and Budget, can set a standard for the duration of this administration, and hopefully, into the future. Providing this clarity is necessary as cyber threats evolve, IT/OT systems become increasingly vulnerable, and the opportunity cost of inaction thereby grows. Done right, these investments can simultaneously stimulate and secure the techno-industrial platforms of the future.
1 2025 Internet Crime Report (Washington D.C., Federal Bureau of Investigation, 2025).
2 Significant Cyber Incidents,” Center for Strategic and International Studies, March, 2026; “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” Cybersecurity & Infrastructure Security Agency, April 7, 2026.
3 Ken Ball, “How Programmable Logic Controllers Emerged from Industry Needs,” Control Engineering, September 1, 2008.
4 Dean Parsons,“2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future,” SANS Institute, March 2025.
5 Meredith Ward, Mike Wyatt, “2026 NASCIO-Deloitte Cybersecurity Study,” Deloitte Center for Government Insights, April 27, 2026.
6 Ward and Wyatt, “2026 NASCIO-Deloitte Cybersecurity Study.”
7 Ward and Wyatt, “2026 NASCIO-Deloitte Cybersecurity Study.”
8 Ken Miller, “Rural Texas Towns Report Cyberattacks That Caused One Water System to Overflow,” Texas Tribune, April 19, 2024.
9 Colt Ellis et al., 2022–2023 Approved Budget, City of Muleshoe, October 1, 2022.
10 “Sandworm Team, Group G0034,” MITRE ATT&CK, December 4, 2024.
11 Andy Greenberg, “Russia’s Sandworm Hackers Attempted a Third Blackout in Ukraine,” Wired, April 12, 2022.
12 Eduard Kovacs, “FrostyGoop ICS Malware Left Ukrainian City’s Residents Without Heating,” SecurityWeek, July 23, 2024.
13 Greenberg, “Russia’s Sandworm Hackers Attempted a Third Blackout in Ukraine.”
14 “Cyber-Attack Against Ukrainian Critical Infrastructure,” Cybersecurity & Infrastructure Security Agency, February 25, 2016.
15 Pierluigi Paganini, “FrostyGoop ICS Malware Targets Ukraine,” Security Affairs, July 23, 2024.
16 “Cyber-Attack Against Ukrainian Critical Infrastructure,” Cybersecurity & Infrastructure Security Agency.
17 Erika Stanish, “Municipal Water Authority of Aliquippa hacked by Iranian-backed cyber group,” CBS News, November 26, 2023.
18 Lynsey Chutel, “Cyberattack Adds to Fears of New Front in Iran War,” New York Times, March 12, 2026.
19 Andrej Safundzic, “The Stryker Hack: How One Compromised Admin Account Led to 200,000 Wiped Devices,” Lumos, March 15, 2026.
20 Nicholas Carlini et al., “Assessing Claude Mythos Preview’s Cybersecurity Capabilities,” Anthropic, April 7, 2026.
21 “Introducing Trusted Access for Cyber,” OpenAI, February 5, 2026.
22 Larry O’Brien, “Should Industrial Cyber Teams Be Concerned About Claude Mythos and Project Glasswing?” ARC Advisory Group, April 20 2026.
23 Jordyn Alger, “What Are Security Experts Saying About Claude Mythos and Project Glasswing?” Security Magazine, April 10, 2026.
24 Jack Edwards, Luke Emberson, “Open Models Lag State-of-the-Art Closed Models by 4 Months,” Epoch AI, May 29, 2026.
25 Zhen-Xin Yong et al., “An Independent Safety Evaluation of Kimi K2.5,” arXiv, April 3, 2026.
26 “Evaluating DeepSeek v4 Pro for Frontier Risks,” Neo Research, May 29, 2026.
27 Donald J. Trump, “Promoting Advanced Artificial Intelligence Innovation and Security,” White House, June 2, 2026.
点击"双栏对照"切换左右对照视图
全球网络安全事件日益泛滥。2025年,仅美国人就在网络犯罪中损失超过200亿美元¹。放眼全球,网络安全事件逐年递增,针对民用基础设施的攻击已成为战争的常规组成部分。自2014年乌克兰亲欧盟革命以来,乌克兰一直是俄罗斯黑客试图瘫痪其基础设施的目标;而在近期战争期间,伊朗黑客也已渗透美国各地关键基础设施²。
这些黑客攻击的特定目标,往往是工厂中控制断路器之类的专用部件。但为何这些专用部件会成为攻击目标?是什么让它们特别容易受到网络攻击?简而言之,世界的物理基础设施所依赖的技术,虽然擅长解决工业自动化问题,但其设计初衷并非面对一个每台设备都连接互联网的世界。
操作技术(OT)是与物理系统交互的硬件和软件。OT硬件的一个经典例子是可编程逻辑控制器(PLC),一种专为工业过程自动化设计的计算机。PLC发明于20世纪60年代,用于取代当时许多汽车公司使用的更繁琐的工业自动化形式³。它们是任何现代工厂的关键组成部分,并使大规模生产成为可能。
… 点击上方按钮查看完整翻译