Over the summer, a coordinated cyberattack targeted operational technology at more than 30 community water systems in Minnesota. The FBI later reported similar incidents in at least seven states. The ramifications were significant enough for Congress to get involved, prompting the introduction of the “Water Cyber Shield Act” last week, which would increase cybersecurity funding and empower the EPA to help prevent future attacks on water infrastructure.
These incidents should serve as a wake-up call. Protecting critical infrastructure is fundamentally a homeland security mission, but much of the infrastructure at risk, like our water utilities, hospitals, transit systems, and school districts, is operated by state and local institutions. In Minnesota, operators knew how to run their plants by hand when the screens went dark. The technology failed. The people did not. But that kind of readiness is not always guaranteed.
That is why technical talent should be considered part of America's critical infrastructure. Without the people who can secure, modernize, and manage essential systems, even the best technology falls short. Experienced operators are indispensable during an emergency, but local institutions also need technical staff who can reduce exposure before an incident, maintain inventories and access controls, and connect operational expertise with modern cybersecurity practice.
Essential services today also increasingly depend on connected systems, spread across institutions of very different sizes and capacities. Federal warnings and state responses are helpful, but every organization’s cybersecurity capability depends on whether it can hire people with the necessary expertise to defend against threats. Some estimates suggest we’re not there yet. GAO has found wide differences in cybersecurity capabilities across the water sector, along with workforce skills gaps that make those vulnerabilities harder to address.
Building that local capability is difficult in a labor market where cyber expertise is already in high demand. CyberSeek recorded more than 514,000 cybersecurity job listings from May 2024 through April 2025. Local utilities and agencies compete with large private employers that recruit continuously, can generally pay more, and are already recognized as places to build a technical career.
Smaller public institutions often enter that competition with less visibility and limited recruiting reach, even though they are responsible for systems on which entire communities depend.
Candidate supply is only part of the challenge. Many early-career technologists do not encounter a municipal government or utility as an obvious place to begin a career, even when the work is technically demanding and personally rewarding, as it is directly connected to public service.
Supporting fellowship and apprenticeship models can help smaller public employers compete for talent. The NobleReach Scholars is a program where public institutions select and supervise the work. NobleReach recruits and screens candidates nationally, then supports a peer cohort of Scholars through preparation, mentoring, and professional development. This arrangement gives state and local employers access to candidates they may not reach on their own and gives participants a supported route into public institutions they may not otherwise have considered. Our newest cohort includes over 40 Scholars serving across 11 states, including roles in cybersecurity and public infrastructure.
The goal should be to make that capacity easier to build everywhere. Congress created the State and Local Cybersecurity Grant Program (SLCGP)in 2021 to help state and local governments protect their systems. The program's planning framework requires states to identify cybersecurity workforce gaps, improve recruitment and retention, and strengthen the skills of cyber personnel. That’s exactly the kind of capacity local institutions need. But the current authorization sunsets on September 30, 2026.
Fortunately, last year, the House passed a multi-year reauthorization, known as the PILLAR Act, that would strengthen the SLCGP and explicitly include operational technology, while the Senate introduced bipartisan legislation that would extend the program and authorize $300 million for fiscal year 2026. Both proposals point in the right direction: helping states and local governments turn cybersecurity funding into durable local capability. The question now is whether Congress will act in time.
The Minnesota attacks demonstrate why workforce development is essential for a robust cybersecurity strategy. Digital systems are in communities of every size, and the institutions responsible for them cannot build cyber capability without access to skilled people. Talent-pipeline models such as NobleReach Scholars, along with extension and expansion of grant programs like the SLCGP, can provide one practical way for public institutions to reach and support early-career technical talent. That kind of capacity-building can help more communities develop the talent required to secure the systems that keep the water running.
Rebeca Lamadrid is Chief Programs Officer at NobleReach Foundation and former Executive Director of the Presidential Innovation Fellows (PIF) program.