Everything Is A Computer Now
And that leaves us vulnerable...
In Bruce Schneier’s seminal work, Click Here To Kill Everybody, he talks about how everything has become a computer: a modern car is just a computer with wheels; a fridge is just a computer that keeps things cold; a water plant is a computer that, funnily enough, moves water from place to place. He uses the term “Internet+” to describe this fusion of the internet, the system that connects us all (well most of us), with the physical world.
This changes things quite substantially; when talking about just personal or business data, a hack costs you money, a hack leads to your secrets being out in the open. Now, with a level of online-ness that those at the dawn of the internet would never have been able to predict, the same kinds of flaws and vulnerabilities could open a dam valve, or stop a pump, creating fatal consequences for real people. Failures are no longer just creating problems online. Those things have come right up to your front door.
The exact same to properties that have made computing both cheap and universal, interconnection and shared code, also make it insecure at scale. This piece explores those two concepts, relating them to stories that I’ve encountered in the past few days…
Story One: The Water Plant
At DEFCON, the ex-NSA chief Paul Nakasone said that programmable logic controllers that run water systems should not be things which are exposed to the internet at all. This came in the wake of a run of suspected attacks by foreign actors. The sheer scale of this makes it deeply concerning: the US relies on roughly 50,000 water municipalities, with most of its supply flowing through them. As you might expect they are historically underfunded, with little or no dedicated security staff. At least twelve states’ water systems have been hit according to reporting.
The controllers in question were built decades ago, in an era of closed and isolated networks. That was the context within which these systems were designed. Later on, however, they were quietly wired to our information superhighway so that they were more convenient, and could be managed from afar. No-one involved took the time to re-architect this system so that it was ready for now, where hostile actors abound. We connected all of this vital infrastructure and left security as an afterthought. And let’s just underline here that, by and large, the system doesn’t care if a command to stop a pump comes from a legitimate engineer, or a hacker. The physical world is now taking instructions from whoever and reach a port and breach a system.
Story Two: Poland
The second story come courtesy of TechCrunch, where two researchers scanned the Polish public web. They discovered that more than 10,000 public entities and 250,000 websites had security flaws… with airports, hospitals, and government offices being in those numbers. One single flaw in a widely-used content management system (CMS) called Pad CMS allowed the into over 300 public sites without a password. Another bug opened up ~245 courts, 2/3 of Poland’s judiciary. All it took here was one component to fail in one instance for a very large portion of a nation state to be vulnerable.
The problem here, as Schneier would put it, is one of a monoculture; much like planting just one crop in a field causes problems down the line, everyone running the same handful of libraries, CMSs, and chipsets, means that a single bug can lay bare a whole interconnected web of systems. The master key to million of doors can suddenly be left on the ground. Efficiency gains come from everyone using the same thing, no doubt, but they also turn into horrendous flaws in situations like these.
In this particular instance, the vendor for Pad CMS would not patch the issue because it was “end of life,” a fact that was likely not very widely known or understood by these many vital government agencies. As often is the case, the incentives to fix are weaker than the incentives to ship something else.
Why This Keeps Happening
The attack surface of a software environment is the sum of the different points (for "attack vectors") where an unauthorized user (the "attacker") can try to enter data to, extract data from, or control a device or critical software in an environment.
Every device added creates new connections to every other, the complexity and the attack surface grow faster than the number of devices. Crucially, security is only as strong as the weakest link… and we keep on creating more and more links.
The market rewards those who deliver features, fast, and at a low price. This is not a set of conditions that is primed for creating secure systems; in fact, it kind of rewards insecurity and displaces the cost of breaches onto the public, not the vendor. Insecurity, much like pollution, is a negative externality. Someone pays the cost, but it isn’t accounted for in the price of the product itself.
The people building water controllers, medical devices, and CMS platforms are experts, but they are experts in water, medicine, and publishing respectively. What they don’t hold expertise in is securing these systems from attacks against rogue actors. We’re putting the responsibility for defending against a nation-state onto the shoulders of a person who believes their role is all about making the water system work.
And this is not to say that there aren’t benefits to this interconnectivity such as remote monitoring, operations being cheaper, services being better… and also making these systems fully offline would not be a practical or a free process. Unplug everything is not at all what I, or Bruce, would be pitching here; we’re saying “can you please think of the consequences more?”
What Actually Helps
The fixes for this problem are mostly structural; Nakasone’s own offering is that critical controllers should be taken off of the public internet and defended through partnerships. It should be obvious that the individuals tasked with keeping the water systems going are not going to be able to patch things so, why act as if they will? Operational technology should be segmented, isolated, and air-gapped so that the open web is not a highway to messing around with vital resources.
Schneier also argues that liability would help reduce these externalities. Make it so that vendors carry the cost of any insecurity that ends up in products that they sell, making security suddenly a non-optional cost of doing business. Bug bounties and real disclosure channels, the exact things that the researchers in story 2 found missing, are cheap - and they work.
And if this has you worrying about yourself, and wanting to lower your attack surface, there are some simple steps.
Does it need to be on the internet? If no, don’t allow it to be.
Do you use smart technologies in some way? How about putting them on a separate network so that you isolate the damage they can have on things.
Could you use non-smart technologies instead? Local media (DVDs, a server), a dumb fridge, a washing machine that isn’t texting you when a load of clothes is done.
Individual lessons here are the same as national and supranational ones… do not connect a thing to the internet just because you can.
The Bigger Picture
The book I started this piece off with is called Click Here To Kill Everybody, a title which is a touch hyperbolic, but is becoming a more and more resonant warning as we go further down this pathway of merging digital and physical worlds (without taking into account the security implications). The water plant and the Polish public services are the same story at different scales.
Systems built for a trusting world are now exposed to a hostile one, held together by shared parts with nobody’s clear responsibility, and no real financial incentive to fix the inherent problems of modern ultra-connected-ness.
Interconnection is a debt that we haven’t paid down, yet; but if we want to continue down this pathway of hooking everything up to the information superhighway, it’s time to put money into security and thinking into processes.
Oh, and if you’re wanting to dig further, the book that is much-cited in this piece sits in sources below… and it’s truly a great read.
Sources
Jessica Lyons, Water system controllers don’t belong on the internet, says ex-NSA chief after suspected Iran attacks (The Register) — https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070
Zack Whittaker, Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks (TechCrunch) — https://techcrunch.com/2026/08/07/security-researchers-scanned-the-polish-web-and-found-courts-hospitals-and-airports-at-risk-of-hacks/
Bruce Schneier, Click Here to Kill Everybody: Security and Survival in a Hyper-connected World (W. W. Norton, 2018) — https://www.schneier.com/books/click-here/
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems (The Register) — https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/5280357
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat (TechCrunch) — https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/
CVE-2025-7063: critical vulnerability in Pad CMS (CERT Polska) — https://cert.pl/posts/2025/09/CVE-2025-7063/
DEF CON Franklin project enlists hackers to harden critical infrastructure (The Register) — https://www.theregister.com/special-features/2024/08/12/def-con-launches-public-policy-report-volunteer-program/408600
Bruce Schneier, The Internet of Things Will Be the World’s Biggest Robot / essays on IoT security and liability (Schneier on Security) — https://www.schneier.com/blog/archives/2017/02/security_and_th.html

Brilliant explanation of our exposures and the remedies.
Seems common sense that not everything should be connected to the internet. A former boss once said,”common sense is a misnomer. There is nothing ‘common’ about it.” English was his second language. Thanks for a useful article.