Summary
What do the "Rocky" movies and water utilities have in common? More than you might think. In part one of this two-part series, we start laying out the 5 questions that can help your utility keep its eye (of the tiger) on cybersecurity.
Part 1: Eye (of the Tiger) on Cybersecurity—5 Questions Utilities Need to Ask Now
Utilities are at risk from cyber threats. But you aren’t defenseless.
Recent attacks targeting dozens of water systems across multiple states are a wakeup call: major changes are needed to protect critical infrastructure—changes like legislation, technology, and funding.
I discussed this in my most recent blog on cybersecurity and utilities. You can read it here.
It takes time to pass legislation.
It takes time to better connect utilities with resources and technology.
It takes time to secure funding for infrastructure improvements.
(If you work in utilities, I’m not telling you anything you aren’t already painfully aware of.)
But this raises an important question for utilities: if an attacker targeted our system tomorrow, are we prepared?
Utilities need the eye of the tiger
Indulge me for a moment as I connect this issue to one of my favorite movie series.
When Rocky faces Clubber Lang in the third installment of the “Rocky” franchise, he loses. Badly. That’s despite demolishing boxers like Apollo Creed to earn the designation of champion—and as the clear underdog! (It’s a fantastic feat that, in my opinion, still pales in comparison to those our utility workers accomplish daily, with limited staffing and resources.)
But Rocky got complacent. And comfortable.
He lost the eye of the tiger.
In my short seven months of working in this utilities-adjacent career, I’ve learned that the “if it ain’t broke, don’t fix it” mindset is relatively common in public utilities. The reasons, of course, are very real (budget constraints, anyone?).
But that slow rate of change nearly earned many communities a knockout punch from cyber-attackers.
At the very least, the recent cyber incident is a stark warning that utilities, like Rocky, better train hard before their next match with Clubber.
That’s where United Systems’ Chief Information Security Officer, Darren Duncan, comes in. Think of him as the “Mickey” to your “Rocky”: your coach for all things cybersecurity. He says there’s a lot that can be done to bolster your utility’s cyber defenses, but staff must lead the way.
A simple place to start? Ask questions, such as these first two (of five) that utilities need to focus on now, before the next attack.
1. Is our cybersecurity posture just meeting the baseline, or are we being as proactive as possible?
Foundational protections—like firewalls, antivirus software, password policies, and backups—are no longer enough to win a fight against cyber-attackers.
“Your security strategy must be proactive. The goal has to be to find weaknesses before someone else does,” Darren says.
One of those is what cyber-attackers targeted recently: operational technology (OT) that’s insecurely connected to the internet.
“We never want any machine, regardless of its use, to be connected to a public IP address,” Darren told local NBC affiliate WPSD-TV during a recent interview. “That’s just cause for concern, from a security perspective, across the board.”
CAPTION (Above): Chief Information Security Officer, Darren Duncan, presents during our 2026 User
2026 User Conference in Bowling Green, KY.
Like Clubber Lang, cyber-attackers are quick on their feet. And they’re constantly sparring.
A utility needs boxing gloves and a mouth guard to help take those punches, but those alone aren’t enough to stay standing.
“The tools and measures in place need to focus on keeping up with swiftly and constantly evolving threats,” says Darren.
2. Have we conducted a formal risk assessment to identify weaknesses in our network?
Rocky heard rumblings of Clubber. He knew other fighters were losing to him, and Mickey and others warned Rocky that he’d lose if he faced Clubber. But he didn’t take the threat seriously. He didn’t keep up.
He had no clue how vulnerable he was. Rocky didn’t even realize he had vulnerabilities.
The same is true for utilities: you can’t protect what you don’t know exists.
A formal cybersecurity risk assessment can help utilities identify weaknesses across your IT and OT environments and prioritize which issues need attention first. That’s particularly important as utilities increasingly connect operational systems to networks for remote monitoring, control, and maintenance.
Darren says a risk assessment can help answer questions like:
- Which devices are connected to the internet?
- Does every internet-connected device actually need that connection?
- Who has remote access to critical systems?
- Are default or weak credentials still being used?
- Are any systems running outdated or unsupported software?
- Are IT and OT networks properly segmented?
- What third-party vendors have access to the network?
- What happens if a critical system becomes unavailable?
To be continued…
Like any great movie in a series, let’s end this blog on a cliffhanger (didn’t mean to throw in another Sylvester Stallone reference, but it works!).
Rocky fought Clubber and lost. But he learned some valuable things in the process, and it changed his approach to the next fight.
He didn’t lose again.
Utilities can arm themselves with the knowledge to win their next match with cyber-attackers. So, stay tuned… I’ll have the last three questions utilities should be asking right now in our next blog installment!
Ready to reduce friction across operations?
Coordinate billing, payments, customer service, metering, work orders, and operational workflows through utility-focused technology and support services. Talk with our team to learn how United Systems supports utilities through technology, operational services, metering, customer service, and workflow management.


