Cyberwarfare has one characteristic that distinguishes it from conventional military conflict: the attack may be invisible, but the consequences are very real. A missile leaves a crater. A successful cyberattack may leave nothing more dramatic than silent pumps, disabled treatment plants, empty supermarket shelves, or contaminated water. Modern civilisation increasingly depends upon digital systems that most citizens never notice until they fail.

That is why the recent attacks on American water systems deserve attention regardless of the political debate surrounding their origin. President Donald Trump dismissed suggestions that Iran was responsible for the attacks on Minnesota's water infrastructure, instead blaming incompetence by Minnesota's state government. His remarks contrasted with preliminary assessments from cybersecurity officials who were investigating whether Iranian-linked hackers were involved, while also acknowledging that the investigation remained incomplete.

Politics aside, one obvious point remains. If these systems were indeed subjected to coordinated cyber intrusions, then someone carried them out.

Perhaps it was Iran. Perhaps it was another nation seeking to disguise its identity. Perhaps it was an independent criminal group exploiting geopolitical tensions. Perhaps it was a sophisticated false-flag operation intended to inflame international conflict. At this stage, investigators have not publicly reached a definitive conclusion.

But dismissing one suspect does not eliminate the existence of an attacker.

This is an important logical distinction that is too often lost in political argument. Refuting one explanation does not prove there was no attack. If evidence eventually demonstrates Iran was not responsible, the question immediately becomes: who was?

Cyber attribution is notoriously difficult. Unlike tanks crossing a border, malicious computer code can pass through dozens of countries before reaching its target. Attackers routinely hijack innocent computers, lease servers under false identities, recycle previously stolen malware, or deliberately imitate the techniques of rival intelligence agencies. Even experienced investigators often speak in probabilities rather than certainties. Yet uncertainty about identity should not produce complacency.

The more worrying lesson concerns the vulnerability itself. Reports indicate that multiple water and wastewater facilities experienced attempts to manipulate programmable logic controllers: the industrial computers that regulate pumps, valves and treatment systems. Even where water quality remained safe, investigators warned that operational technology had become the target.

Water is not merely another utility. It underpins hospitals, firefighting, food production, sanitation and every aspect of daily life. A prolonged disruption would rapidly become a humanitarian crisis without a single shot being fired.

What makes this especially troubling is that cybersecurity experts have warned for years that many municipal water systems operate with ageing equipment, limited budgets and minimal specialist staff. Numerous facilities remain connected to the internet despite controlling essential infrastructure. Federal agencies have repeatedly warned that Iranian-affiliated actors have shown interest in precisely these kinds of systems, although each individual incident still requires its own investigation.

The broader lesson extends beyond the United States. Every advanced nation is becoming increasingly dependent upon networked infrastructure. Electricity, banking, telecommunications, transport, fuel distribution, hospitals and water systems all rely upon interconnected digital control systems. The more efficient these systems become, the more attractive they become as targets.

History teaches that every new technology eventually becomes weaponised. Railways transformed military logistics. Aircraft transformed warfare. Satellites transformed intelligence gathering. Artificial intelligence and industrial cyber capabilities are now transforming strategic competition.

Governments therefore need to prepare for two challenges simultaneously. First, they must improve the resilience of critical infrastructure through better cybersecurity, redundant manual controls and rapid recovery capabilities. Second, they must resist the temptation to leap prematurely to conclusions about attribution before forensic evidence has been fully assessed. The public deserves accuracy rather than speculation.

Whether the culprit ultimately proves to be Iran, another hostile state, a criminal syndicate or an entirely different actor, one uncomfortable reality remains. Someone demonstrated that critical infrastructure can be reached through cyberspace. That should concern every democracy.

When politics fades from the headlines, the underlying vulnerability will still exist. And the next attacker, whoever it may be, will almost certainly already be searching for the next weak point.

This is another lesson for Australia.