One County, Multiple Points of Failure: When Crumbling Infrastructure Meets Cyber Exposure

August 11, 2026 | Author: Jeff Gray, Cyborama | Source: ControlSystemsSecurity.com
OT Security Infrastructure Risk Dam Safety ICS Exposure Converging Threats Alabama
The Hidden Risk: The National Inventory of Dams tracks ~92,000 structures — but a vast category of water-control infrastructure (retention gates, spillway valves, small locks, stormwater systems) is neither classified as a dam nor tracked by any unified framework. We can't quantify how many exist. Many of them have internet-facing control systems that anyone can find with a search engine.
The Pattern: In a single geographic area, aging physical infrastructure with known safety concerns intersects with internet-exposed industrial control systems. Neither problem alone is unusual. Together, they create a risk profile that neither the dam safety community nor the cybersecurity community is equipped to see.
Aged dam spillway with rusted control box and dry riverbed
Aging infrastructure: rusted spillway controls overlook a dry riverbed. No active reconnaissance required to see what's exposed.

The Spark

A retention lake in a Birmingham-area community drained suddenly. The city's statement noted that the overflow system was "compromised" and the property owner engaged a contractor to evaluate the situation. The structure was on private property, outside municipal maintenance.

We don't know what happened at that lake. In the end, it is of little consequence — a lake was drained, a repair will be affected. But that incident sparked a question: "Hmmm?"

A moment of extrapolation. If a single private retention structure can fail quietly, untracked and unregulated, what does the broader landscape look like? That question led to a passive survey of Alabama's dam safety data, its industrial control system exposure, and the intersection between the two. The big picture that emerged is what matters — not the individual incident that sparked the curiosity.

The Physical Layer: Crumbling Dams

Alabama has approximately 2,260 dams in the National Inventory of Dams. Of those, 227 are classified as high hazard — meaning failure would likely cause loss of life. Six are in poor or unsatisfactory condition. Two are both high-hazard and in poor condition.

The NID assigns each dam an Impact Level based on potential consequences of failure:

Alabama Dam Impact Levels donut chart
Alabama Dam Impact Levels — 2,262 dams in the National Inventory of Dams
Impact Level Definition Alabama Count % of Total
High Hazard Failure would likely cause loss of life 227 10.0%
Significant Hazard Failure would cause significant property damage 443 19.6%
Low Hazard Failure would cause minimal property damage 1,592 70.3%

The 227 high-hazard dams are the ones that keep dam safety officials awake at night. Combine a high-hazard rating with a poor condition assessment, and you have a recipe for disaster. Logan Martin Dam in St. Clair County is exactly that: high-hazard, 142 feet tall, hydroelectric, completed in 1964, and rated in Poor condition. It sits in a region where downstream communities depend on its integrity every day.

In one urban Alabama county, the state's third-tallest dam stands 158 feet tall. Its condition is listed as "Not Rated."

These are structures that hold back millions of gallons of water. They have emergency spillway systems, gate controls, monitoring equipment, and automated valves. They were built in the mid-20th century and are now reaching the age where maintenance becomes not just costly, but critical.

Alabama only recently established a formal state dam safety program (2026). For decades, there was no statewide program to coordinate inspections, track condition assessments, or ensure compliance with federal guidelines. This history helps explain why many dams — even high-hazard ones — carry "Not Rated" condition status in public records.

The Digital Layer: Exposed Control Systems

In the same state, a passive survey using the Shodan search engine revealed:

Alabama data: passive Shodan search results as of August 11, 2026. These devices are internet-reachable; ownership and function cannot be confirmed without active reconnaissance, which was not performed. Alabama counts validated across multiple scans from May through August 2026.

National context: Third-party research (Forescout/Vedere Labs, Censys, 2026) has reported between 4,100 and 5,200 internet-facing Rockwell/Allen-Bradley controllers globally, with approximately 75% located in the United States. Modbus exposure estimates vary widely by platform and methodology.

Internet-Facing OT Devices in Alabama bar chart
Internet-Facing OT Devices — Alabama (Passive Shodan Search, August 2026)

Exposed does not mean vulnerable.

A device visible to a search engine is not necessarily exploitable. Authentication may be enabled. Access controls may be properly configured. But exposure is the prerequisite — a device cannot be attacked remotely if it cannot be found. And these devices were found without sending a single packet.

These aren't hypothetical vulnerabilities. The Rockwell MicroLogix 1100 and 1400 PLCs — the exact devices we found exposed — are the same controllers that the FBI, EPA, and CISA reported being actively exploited in water utility attacks across multiple states in 2026. Attackers accessed these devices remotely, modified ladder logic, changed IP configurations, and locked out legitimate operators.

Dozens of internet-facing control systems were identified across the state. No active scanning required to find them.

The Invisible Infrastructure

Here's what most people don't realize: the National Inventory of Dams is not a census. It's a filtered list. A dam only appears in the NID if it meets specific criteria:

Anything below those thresholds doesn't appear in the NID. No federal tracking. No required inspections. No Emergency Action Plans. No oversight.

But the deeper problem is that not every water-retaining structure is classified as a "dam" at all.

A retention lake outlet gate, a stormwater culvert valve, a small irrigation lock — these aren't "dams" in any regulatory sense. They're infrastructure components. They hold back water. They can fail catastrophically. And they increasingly have programmable logic controllers managing them.

These structures are subject to some regulation — stormwater systems fall under Clean Water Act NPDES requirements, state stormwater management rules, and local permitting. But none of these frameworks maintain a centralized inventory comparable to the NID, nor do they track the control systems that operate these structures. Low-head dams, a related category, were historically excluded from national inventory and only recently received separate tracking.

Water Infrastructure Oversight Gaps matrix
Water Infrastructure Oversight Gaps — Which structures are tracked, and by whom?
The gap is not absence of all regulation, but absence of unified oversight: Stormwater systems face NPDES and state-level requirements, but no framework maintains a centralized inventory of these structures or tracks the control systems that operate them. We can't quantify how many exist, because the data lives across disparate permitting systems, property records, and construction documents — if it exists at all. And an increasing number of them use the same internet-facing PLCs that are being actively exploited in water utility attacks.

The Convergence

The blind spot: Dam safety programs assess structural integrity, spillway capacity, and emergency action plans. Cybersecurity teams scan for exposed ICS devices and unauthenticated protocols. Neither group looks at both. And neither group is tracking the unclassified water-control structures that operate outside all regulatory frameworks.

The gap isn't technical. It's institutional.

A dam with a compromised spillway control system doesn't fail because the concrete is weak. It fails because the gate that controls water release was manipulated — whether by a cyber actor, a maintenance error, or a simple mechanical failure that went undetected because the monitoring system itself was compromised.

The Perfect Storm Scenario

Consider what happens when these layers converge in a single geographic area:

  1. Aging dam infrastructure with deferred maintenance and poor condition ratings
  2. Internet-exposed control systems managing spillway gates, pump stations, and water level monitoring
  3. Active exploitation campaigns already targeting the same controller models used in water infrastructure
  4. Private and municipal structures that fall below regulatory reporting thresholds
  5. Minimal coordination between dam safety officials and OT security professionals

This isn't speculation. It's a pattern that already exists in public data. We mapped it passively, without sending a single packet to any target, using only publicly available information.

What We Can See — and What We Cannot

Here is what we can verify from public data in a single county:

In one urban Alabama county, there are 20 high-hazard dams — structures whose failure would likely cause loss of life. The large majority are listed as "Not Rated" for condition in the National Inventory of Dams. A "Poor" rating means someone inspected the dam and found problems. "Not Rated" means the inspection data does not exist in any publicly accessible system.

In the same state, we identified 37 Rockwell PLCs and 91 Modbus devices exposed to the internet. We cannot determine what these devices control, which facilities they serve, or whether any of them are connected to water-retaining infrastructure. To do so would require active scanning, banner fingerprinting beyond passive enumeration, or direct probing of industrial control systems. That type of reconnaissance violates the Computer Fraud and Abuse Act, the terms of service of the equipment manufacturers, and our own ethical boundaries. We will not break the law to prove a point that is already visible in aggregate.

The question is not whether the convergence exists. The question is whether anyone responsible for public safety is looking at both halves of the picture.

The Uncounted Infrastructure

One conclusion from this analysis: there is a category of water-retaining structures — retention gates, spillway valves, small locks, stormwater control systems — that are neither classified as dams nor tracked by any centralized inventory comparable to the NID. They are subject to some regulation (NPDES permits, state stormwater rules), but no framework unifies oversight of these structures or their control systems. We cannot confirm how many exist or where they are located. This absence of consolidated data is itself a risk signal.

Some of these structures are the ones that drain suddenly, prompt city statements, and require contractors to show up. They exist in the gap between what is tracked and what is real.

What Defenders Should Do

The solution isn't more scanning. It's better coordination and architecture:

Methodology

This analysis was conducted using publicly available data sources only:

No specific organizations, facilities, or targets are identified. No active scanning or exploitation was performed. All data represents publicly available information that any internet user could access through standard search interfaces. City-level and carrier-level patterns are reported only at the aggregate level.

Queries conducted: approximately 150. API usage is tracked and remains within our 10,000 query/month Developer tier limit.

Note: This article was drafted on August 11, 2026. It has not been published pending final review.

Analysis based solely on publicly available sources (passive Shodan search results). No active scanning, probing, or unauthorized access was performed. No specific private facilities or control systems are identified. The views expressed are the author's alone and do not represent the positions, strategies, or opinions of any government agency, department, or employer.