The coordinated cyberattack that hit water utilities across more than thirty Minnesota communities last week is a reminder that critical infrastructure protection isn’t an abstract policy problem — it’s a leadership gap we haven’t closed. The state’s technology bureau confirmed the disruptions but hasn’t attributed them, which means we’re still in the fog-of-war phase. What’s clear already is that municipal water systems remain soft targets, and the talent pipeline to harden them is too thin.
Most of these utilities operate on shoestring IT budgets with skeleton crews. They’re running legacy SCADA systems that were never designed to be internet-facing, managed by operators whose expertise is water chemistry, not network segmentation. When I map the market for cleared cybersecurity leaders, I see plenty of demand at the federal level and among primes — but state and local infrastructure sits several rungs down the compensation ladder, and the talent follows the money. That’s not a criticism. It’s the market.
The challenge isn’t just hiring a CISO or two. It’s that effective defense of distributed infrastructure requires coordination across dozens of independent municipalities, each with its own governance, budget cycle, and risk tolerance. You need someone who can speak both technical and political dialects, who understands how to build a shared services model that doesn’t trip over procurement rules, and who has the operational credibility to get buy-in from elected officials who’d rather fund visible projects. That’s a narrow candidate profile, and there aren’t many of them sitting idle.
The federal response will likely include more grant funding and framework guidance — helpful, but not sufficient. Money without the people to execute it well just creates compliance theater. I’ve watched organizations hire into newly funded roles and then struggle for months to find someone who can actually do the work, not just check boxes. The passive candidates who could step in and run point on a statewide critical infrastructure program are already employed, often in roles that pay better and come with fewer political headaches.
What might move the needle is treating these roles less like government IT positions and more like the strategic leadership assignments they actually are. That means competitive compensation, clear authority, and top-cover from the governor’s office or state legislature. It also means being willing to pull talent from the private sector or federal space with offers that reflect the mission’s urgency. Minnesota and states in similar positions have a narrow window to build resilience before the next incident — and the next one may not stop at disruption.