The Silent Siege: How Insurance Executives are Confronting a Hypothetical Catastrophic Cyberattack on US Water Infrastructure
7 mins read

The Silent Siege: How Insurance Executives are Confronting a Hypothetical Catastrophic Cyberattack on US Water Infrastructure

Seventy minutes into an intense tabletop simulation held in a high-rise conference room overlooking Times Square, the atmosphere shifts from intellectual exercise to existential dread. The participants, a cohort of senior insurance executives, are grappling with a synthetic scenario: a synchronized, nationwide cyberattack on 5,000 American water utilities. Orchestrated by Joshua Corman, a former strategist for the Cybersecurity and Infrastructure Security Agency (CISA), the simulation—convened by the cybersecurity organization CyberAcuView—seeks to pressure-test the industry’s capacity to respond to a crisis that moves beyond mere digital disruption into the realm of kinetic, societal collapse.

The scenario, set in the summer of 2027, posits a reality where the "second-order effects" of a digital strike have crippled the physical underpinnings of the United States. As Corman narrates, the virtual clock ticks forward. Within 24 hours, the failure of water control systems has cascaded into widespread outages. Cold storage warehouses are losing power, triggering mass food spoilage. Pharmaceutical manufacturing, heavily dependent on purified water, faces severe production bottlenecks, leading to acute insulin shortages. Data centers, lacking the water required for their cooling systems, are shutting down, taking critical cloud infrastructure offline. Most alarmingly, 2,000 hospitals are reporting complete water loss, forcing the evacuation of patients during a sweltering July heatwave.

The Anatomy of the Threat: Volt Typhoon and Beyond

The simulation is not a product of pure fiction; it is grounded in the evolving threat profile of state-sponsored cyber operations, most notably the group identified as Volt Typhoon. First publicly disclosed in May 2023 by Microsoft, the National Security Agency (NSA), and CISA, Volt Typhoon represents a paradigm shift in Chinese state-sponsored cyber capabilities. Unlike traditional espionage units that focus on the theft of intellectual property, Volt Typhoon has demonstrated a persistent intent to "pre-position" itself within the critical infrastructure of the United States and its territories, such as Guam.

The technical signature of these actors is "living off the land"—a strategy that leverages legitimate network administration tools to execute malicious commands. By avoiding the installation of custom malware, the hackers remain invisible to many traditional security monitoring systems. This tradecraft has allowed them to gain a foothold in telecommunications, energy grids, and water systems. As former CISA executive director Brandon Wales noted in 2025, the strategic objective appears to be the capacity to induce "societal chaos" during a geopolitical crisis, such as a kinetic conflict in the Taiwan Strait. By disabling civilian infrastructure, the attackers seek to degrade the American public’s will to support a protracted military engagement.

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

Chronology of a Simulated Collapse

The war game was designed to force insurance executives to confront the limitations of the current risk-transfer model. The progression of the simulation followed a harrowing timeline:

  • July 1, 2027 (Day One): The simulation opens amidst reports of rising geopolitical tensions in the Pacific. Cybersecurity incident response firms are already stretched thin, managing a separate, massive ransomware campaign. The "starting gun" sounds when a classified advisory confirms that thousands of water utilities have lost control of their operational technology (OT).
  • The Immediate Response: Participants are tasked with the initial triage: Should they notify all clients of the impending threat, or maintain silence to prevent market panic? The table dynamics reveal a deep divide between traditional client-reporting models and the exigencies of an emergency.
  • The Escalation: Corman introduces a 20-sided die roll, which determines that major incident response firms—Dragos, CrowdStrike, and Mandiant—are fully booked, forcing teams to scramble for secondary or tertiary resources.
  • July 2, 2027 (Day Two): The crisis enters a kinetic phase. Real-world physical damage—burst water mains and destroyed hardware—renders many systems irreparable without significant manual intervention. A fictional military official appears on screen, requesting that insurers prioritize the restoration of "dual-use" infrastructure critical to military mobility.

The Financial and Ethical Dilemma

The central tension of the simulation lies in the role of the insurer. In the event of a national emergency, insurance companies act as the "gatekeepers" of incident response; they hold the keys to the funds required to hire specialized cybersecurity firms and legal teams. However, the simulation forces these executives to decide whose needs take precedence: the largest, most profitable clients, or the regions where human lives are at the highest risk.

"If the Treasury Department is calling and asking for numbers, and we’re telling them we’re focused on human life, I don’t know if that’s the actual talk track," one participant remarked during the breakout session. This highlights the fundamental friction between fiduciary duty, contractual obligations, and national security requirements.

Furthermore, the threat of bankruptcy looms over the exercise. Insurers are left to consider the "act of war" exclusion—a standard clause in many policies that absolves providers of liability during active military conflict. Invoking this clause could protect the solvency of the insurance industry but would inevitably label the carriers as the "villains" of the crisis, potentially leading to long-term litigation similar to the disputes that followed the 2017 NotPetya attack.

Implications for National Resilience

The simulation underscores a significant vulnerability in American infrastructure: the fragmentation of security standards. According to Corman, a mere 0.3 percent of the nation’s 151,000 water utilities are currently active members of cybersecurity information-sharing organizations. This lack of collective defense, combined with limited municipal security budgets, creates a target-rich environment for sophisticated state actors.

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

Industry experts, including former CISA director Jen Easterly, argue that the integration of artificial intelligence into offensive cyber operations will only accelerate these risks. As AI-driven hacking tools become more capable of identifying and exploiting zero-day vulnerabilities at scale, the time available for human defenders to respond will continue to shrink.

Mark Camillo, CEO of CyberAcuView, posits that the scale of such a cataclysmic attack might be "uninsurable" without federal intervention. He suggests that a model similar to the Terrorism Risk Insurance Act (TRIA)—which provides a federal backstop for losses resulting from certified acts of terrorism—might be necessary. However, relying on a government bailout creates its own set of moral hazards, potentially disincentivizing the private sector from making the necessary investments in preventative hardening.

Moving Toward Prevention

The ultimate conclusion drawn by the participants—and encouraged by Corman—is that the insurance industry possesses the unique power to mandate change. Rather than focusing on how to respond to a catastrophe, the industry could leverage its underwriting power to force meaningful cybersecurity adoption. By requiring clients to patch vulnerable network edge devices, join information-sharing collectives, and conduct regular penetration testing as a condition of coverage, insurers could systematically raise the cost of entry for hackers.

As the simulation concluded, the message was clear: the current trajectory of cyber-preparedness is insufficient. The "winning move" is not to become more efficient at responding to an inevitable collapse, but to dismantle the vulnerabilities that make such an event possible in the first place. The simulation proved that when the backbone of society—water, power, and communications—is exposed, the traditional mechanisms of corporate risk management are simply not designed to hold the weight of the consequences. For the insurance industry, the challenge of the next decade will be deciding whether they will remain passive payers of claims or become active agents of national resilience.

Leave a Reply

Your email address will not be published. Required fields are marked *