Tue, 18 Aug 2026

Human factors and vendor dependence: The hidden vulnerabilities in Asia’s critical infrastructure

Recent cyberattacks on water systems across several US states have reignited concerns over the security of essential services that underpin daily life.

Yet, contrary to popular belief, the onus of protecting critical infrastructure does not rest primarily with federal or state governments.

“The primary responsibility for securing these systems usually falls to the local government or contract organization running the utility or service, with only support from state and federal agencies,” says Daniel Votipka, assistant professor of computer science at Tufts University and co-director of the Tufts Security and Privacy Lab.

In many cases, especially among smaller jurisdictions and public utilities, dedicated cybersecurity teams are a luxury few can afford. Instead, IT or engineering staff—already stretched ensuring uninterrupted service delivery—must juggle cybersecurity alongside operational demands.

“Complex machines fail all the time, and keeping essential services running usually takes priority over longer-term cybersecurity work,” Votipka notes.

Compounding the challenge is reliance on third-party vendors for technology and vulnerability mitigation. Should a vendor cease operations or discontinue support for legacy devices, utilities are left exposed with no ready patch to address discovered flaws.

Attackers, meanwhile, need not deploy sophisticated exploits; unpatched software, misconfigured systems, or a single clicked link often suffice. These human errors proliferate where employees are overworked, undertrained, or burdened with competing responsibilities.

Water systems and similar critical infrastructure present unique security hurdles. Unlike financial institutions or tech giants, many utilities operate with constrained budgets and staffing, hindering robust system design, threat monitoring, and timely equipment upgrades.

Moreover, patching computer systems that control physical equipment entails complex testing in realistic or simulated environments—processes that may still fail to capture every real-world scenario.

Related:  HKCERT warns AI, supply chain and staffing gaps are reshaping HK cyber risk

Human emotions further complicate patch adoption. Operators, wary of updates that might disrupt essential services, often defer installations—mirroring everyday users who postpone software updates. “The goal isn’t to eliminate every risk; it’s to prevent a breach from becoming a public safety emergency,” Votipka asserts.

Resilience, therefore, means designing systems that assume some attacks will succeed but limit their impact. For instance, allowing remote monitoring of a water treatment plant poses far less risk than permitting remote changes to treatment settings.

Requiring in-person verification or multi-factor authentication for critical changes ensures that even compromised access cannot easily alter public safety parameters.

Looking ahead, AI is poised to amplify existing challenges. It can craft convincing phishing messages, accelerate vulnerability discovery, and generate false data that evades traditional safety checks.

“If AI enables attackers to create false data that looks medically plausible and fits with other information, those safeguards could become much less effective,” warns Votipka, citing recent healthcare-focused research.

To meaningfully reduce cyber risk, utilities require increased resources for technology modernisation and cybersecurity expertise. Yet funding alone is insufficient.

Secure-by-default technologies, sustained government support, and systems embedding security into daily operations—not as an afterthought—are essential. Investing now will prove far more effective than reacting after the next major attack.

Related Stories

MORE STORIES