Fortresses Built on Sand: The Persistent DDoS Vulnerabilities Threatening America's Critical Infrastructure
In the spring of 2021, a threat actor briefly gained access to the water treatment system serving Oldsmar, Florida, attempting to raise sodium hydroxide levels to dangerous concentrations. The intrusion was caught—narrowly—by an attentive operator. That incident triggered congressional hearings, urgent advisories from the Cybersecurity and Infrastructure Security Agency (CISA), and pledges of modernization from utility operators across the country. Three years later, security professionals who work directly with critical infrastructure operators describe a landscape that has changed far less than the policy announcements suggest.
The specific vulnerability at the center of this concern is not a zero-day exploit or a nation-state backdoor. It is something more mundane and, in many ways, more dangerous: the chronic failure to defend industrial control networks against distributed denial-of-service attacks sophisticated enough to serve as both a disruptive weapon and a diversionary screen.
Why Legacy Frameworks Cannot Keep Pace
Most critical infrastructure operators in the United States—from regional electric cooperatives to municipal water authorities to community hospital systems—built their cybersecurity postures around frameworks established in the early 2010s. NERC CIP standards for the electric sector, for instance, were authored before volumetric DDoS attacks routinely exceeded 1 terabit per second. The NIST Cybersecurity Framework, while regularly updated, offers guidance at a level of abstraction that leaves significant interpretation to individual operators.
The result is a patchwork of defenses. Some larger utilities have invested in purpose-built scrubbing centers and upstream traffic filtering partnerships with their internet service providers. Many others—particularly the roughly 3,200 rural electric cooperatives that collectively serve millions of Americans—rely on configurations that security engineers describe, with some understatement, as "not fit for the current environment."
"The challenge is that SCADA systems and industrial control networks were originally engineered for availability, not security," explains one infrastructure security consultant who has conducted assessments for multiple regional grid operators. "When you start layering modern DDoS mitigation onto those environments, you run into real conflicts. Latency introduced by traffic scrubbing can interfere with the millisecond-level response times that some control systems require. Operators face a genuine dilemma, and many resolve it by doing less mitigation than they should."
The SCADA Exposure Problem
Supervisory Control and Data Acquisition systems sit at the operational heart of American infrastructure. They monitor and control everything from transformer switching in electrical substations to chemical dosing in water treatment plants. Historically, these systems were air-gapped—physically isolated from public networks. That isolation has eroded substantially over the past decade as operators connected control networks to corporate IT environments for efficiency and remote management.
That connectivity, while operationally convenient, opens SCADA interfaces to network-layer attacks that their designers never anticipated. A sustained DDoS campaign against the human-machine interface layer of a water treatment plant does not need to breach the control system directly to cause harm. It needs only to deny operators visibility at a critical moment—during a chemical feed adjustment, a pump failure, or a pressure event—to create conditions where human error becomes likely.
CISA's 2023 advisory on threats to water and wastewater systems specifically cited DDoS attacks as an underappreciated vector, noting that several utilities had experienced service disruptions to their operational technology networks without fully recognizing the connection to network-layer flooding. The advisory recommended network segmentation, rate limiting at the perimeter, and coordination with upstream providers—recommendations that remain unimplemented at a significant share of the facilities the agency identified as at risk.
Hospital networks present a related but distinct challenge. Clinical environments have seen a dramatic increase in connected medical devices over the past decade, many of which communicate over the same network segments that handle patient records and administrative traffic. A volumetric attack capable of saturating a hospital's internet uplink does not merely slow down email. It can interrupt the telemetry feeds that intensive care physicians rely on, delay imaging transfers that inform surgical decisions, and knock out the remote monitoring platforms that have become central to post-acute care.
The Modernization Pathway
Security professionals working in this space are not without solutions. They are, however, frustrated by the pace at which those solutions are being adopted.
The most frequently cited modernization priority is network segmentation that genuinely isolates operational technology environments from enterprise IT and internet-facing systems. This is not a novel recommendation—it appears in virtually every federal advisory on the subject—but its implementation requires capital investment and operational disruption that many facility managers are reluctant to authorize without a more immediate forcing function.
Beyond segmentation, infrastructure operators are increasingly advised to establish formal relationships with upstream DDoS mitigation providers before an incident occurs, not during one. Cloud-based scrubbing services can absorb volumetric attacks that would overwhelm on-premises hardware, but the routing changes required to redirect traffic through those services take time to implement and test. Operators who have never performed that process under controlled conditions are unlikely to execute it effectively under attack.
Another concrete step involves deploying out-of-band management networks for critical control systems. If the primary network path to a SCADA interface is flooded, operators need an alternative communications channel that remains functional. Cellular-based backup connectivity, properly secured and regularly tested, provides exactly that capability.
Finally, tabletop exercises that specifically simulate DDoS scenarios against operational technology environments remain rare in critical infrastructure planning. Most facilities conduct incident response drills focused on ransomware or physical security events. Rehearsing the specific decision points that arise when control network visibility is degraded by a network flood would substantially improve response outcomes.
The Policy Gap and What Fills It
CISA has made critical infrastructure cybersecurity a stated priority, and the Biden-era executive orders on improving national cybersecurity produced meaningful structural changes in how federal agencies coordinate with private sector operators. Yet the fundamental challenge is jurisdictional and financial. The federal government cannot compel most private infrastructure operators to meet specific DDoS mitigation standards, and the grant programs designed to help smaller utilities modernize are oversubscribed relative to available funding.
That gap is unlikely to close through policy alone. The security professionals who assess these environments most frequently argue that the more realistic path runs through insurance markets and liability frameworks—that as cyber insurers become more sophisticated in underwriting infrastructure risk, the financial incentives for adequate DDoS protection will align more directly with operational decisions.
In the interim, the vulnerabilities remain. The frameworks remain outdated. And the attacks continue to grow in sophistication. America's critical infrastructure is not defenseless—but it is, in many places, defended by walls that were built for a different era of threats, by adversaries who have long since adapted.