

Water systems are foundational to daily life—and to many other critical services. Hospitals, public-safety agencies, businesses, schools, and residents all depend on water utilities for safe, reliable service.
Cyberattacks suspected to be linked to Iran have included unauthorized access to drinking-water systems, disruptions to programmable logic controllers (PLCs)—industrial computers that help operate pumps, valves, and other equipment—and incidents that forced operators to work manually. While service disruption is the immediate concern, the broader risk is how an attack on one water system can ripple across the communities and institutions that depend on it.
A vulnerable PLC can provide attackers with an entry point, but initial access is only the beginning. From account recovery to privileged access, each interaction calls for identity assurance that confirms the person behind the request. States can’t address every risk overnight, but they can strengthen protection around the systems already in place.
Security starts with identity
Not every water attack begins with an identity compromise, but every critical system relies on people to create accounts, enroll in MFA, support users, approve access, manage vendors, and respond under pressure. Identity matters at each one of these touchpoints—and they all deserve the same level of security as the systems themselves.
Once an attacker gains a foothold into a system, access can be extended through compromised credentials, socially engineered password resets, help-desk exceptions, and unverified privileged-access requests. That’s where identity matters: a valid password, token, or familiar device may authenticate a request, but no single signal verifies the person behind the interaction.
Verify the person beyond the device
At high-risk moments, security teams need confidence that the person requesting access is real, that identity details align with authoritative and credible sources, and that the request comes from the user linked to the account or workflow. That level of identity assurance requires more than a single credential or device signal.
CLEAR1 takes a multi-layered approach to identity that combines four layers: biometric verification confirms a live person and matches them to an ID photo; document authenticity checks help detect forgery or alteration; source validation compares identity details against authoritative and credible sources; and device assurance confirms physical possession and surfaces device-related security signals. Together, these layers build a more complete, accurate understanding of identity and create a reusable identity layer that works alongside existing IAM and ITSM environments—including Microsoft Entra, Okta, and ServiceNow.
With CLEAR1, security teams can verify the person behind a high-impact request before granting, restoring, or expanding access.
From utility security to statewide services
State leaders are securing legacy systems across fragmented agencies and technology environments, often on long procurement timelines. Rather than wait for every system to be replaced or modernized, states and utilities can strengthen protection incrementally—starting with high-value workflows such as employee access, account recovery, and privileged access.
That same reusable identity layer can then extend beyond utility workflows to Medicaid, SNAP, benefits, licensing, digital wallets, and other services, helping maximize security and minimize friction for residents, providers, employees, and contractors.
Join the conversation
The recent attacks on water systems call for a broader conversation about how states can verify the person beyond the device at the moments when access matters most—and extend that identity layer across the critical services residents rely on every day.
To explore this and more, join our upcoming webinar. Security leaders will discuss:
- Why identity matters at account recovery and privileged-access points in water-utility security
- How CLEAR1’s multi-layered identity approach can add identity assurance to existing systems without adding unnecessary complexity
- How states can extend that identity layer from utility employees and privileged access to Medicaid, SNAP, benefits, licensing, digital wallets, and other digital government services
Join us Tuesday, September 29, from 11:00 a.m. to 12:00 p.m. ET.
Water systems are foundational to daily life—and to many other critical services. Hospitals, public-safety agencies, businesses, schools, and residents all depend on water utilities for safe, reliable service.
Cyberattacks suspected to be linked to Iran have included unauthorized access to drinking-water systems, disruptions to programmable logic controllers (PLCs)—industrial computers that help operate pumps, valves, and other equipment—and incidents that forced operators to work manually. While service disruption is the immediate concern, the broader risk is how an attack on one water system can ripple across the communities and institutions that depend on it.
A vulnerable PLC can provide attackers with an entry point, but initial access is only the beginning. From account recovery to privileged access, each interaction calls for identity assurance that confirms the person behind the request. States can’t address every risk overnight, but they can strengthen protection around the systems already in place.
Security starts with identity
Not every water attack begins with an identity compromise, but every critical system relies on people to create accounts, enroll in MFA, support users, approve access, manage vendors, and respond under pressure. Identity matters at each one of these touchpoints—and they all deserve the same level of security as the systems themselves.
Once an attacker gains a foothold into a system, access can be extended through compromised credentials, socially engineered password resets, help-desk exceptions, and unverified privileged-access requests. That’s where identity matters: a valid password, token, or familiar device may authenticate a request, but no single signal verifies the person behind the interaction.
Verify the person beyond the device
At high-risk moments, security teams need confidence that the person requesting access is real, that identity details align with authoritative and credible sources, and that the request comes from the user linked to the account or workflow. That level of identity assurance requires more than a single credential or device signal.
CLEAR1 takes a multi-layered approach to identity that combines four layers: biometric verification confirms a live person and matches them to an ID photo; document authenticity checks help detect forgery or alteration; source validation compares identity details against authoritative and credible sources; and device assurance confirms physical possession and surfaces device-related security signals. Together, these layers build a more complete, accurate understanding of identity and create a reusable identity layer that works alongside existing IAM and ITSM environments—including Microsoft Entra, Okta, and ServiceNow.
With CLEAR1, security teams can verify the person behind a high-impact request before granting, restoring, or expanding access.
From utility security to statewide services
State leaders are securing legacy systems across fragmented agencies and technology environments, often on long procurement timelines. Rather than wait for every system to be replaced or modernized, states and utilities can strengthen protection incrementally—starting with high-value workflows such as employee access, account recovery, and privileged access.
That same reusable identity layer can then extend beyond utility workflows to Medicaid, SNAP, benefits, licensing, digital wallets, and other services, helping maximize security and minimize friction for residents, providers, employees, and contractors.
Join the conversation
The recent attacks on water systems call for a broader conversation about how states can verify the person beyond the device at the moments when access matters most—and extend that identity layer across the critical services residents rely on every day.
To explore this and more, join our upcoming webinar. Security leaders will discuss:
- Why identity matters at account recovery and privileged-access points in water-utility security
- How CLEAR1’s multi-layered identity approach can add identity assurance to existing systems without adding unnecessary complexity
- How states can extend that identity layer from utility employees and privileged access to Medicaid, SNAP, benefits, licensing, digital wallets, and other digital government services
Join us Tuesday, September 29, from 11:00 a.m. to 12:00 p.m. ET.








