The Partner Masters logo

Back

Microsoft Partners Growing Cybersecurity Practices Focus on Operational Excellence

Microsoft Technical

Microsoft Partners Growing Cybersecurity Practices Focus on Operational Excellence

 |  11 min read

Kevin Martins
Kevin MartinsExecutive Vice President

The recent attacks on municipal water systems should cause major concern with What the recent attacks on municipal water systems should teach every Microsoft partner about assessment, automation, and audit readiness.

What Happened, and Why It Should Concern All of Us

Over the past several weeks, I have been following the reporting on the cyberattacks against municipal water systems across the United States, and the more that comes out, the more concerning the picture becomes. What started in late July 2026 as an attack on roughly thirty water systems in Minnesota has grown into something much larger. NBC Chicago reported on August 26, 2026, that the Cybersecurity and Infrastructure Security Agency (CISA) had acknowledged malicious activity targeting more than one hundred internet exposed systems in the Water and Wastewater Systems Sector across twelve states, commonly through programmable logic controllers connected directly to cellular modems.

One of the things that stood out to me as I read through the coverage was how ordinary the targets were. These were not sophisticated, heavily funded enterprises with mature security operations. In many cases, attackers were reaching operational technology that regulates valves, water flow, and chemical treatment, equipment that was never designed to sit on the public internet and face a nation state adversary. Water districts, small municipalities, and rural utilities frequently operate with tight budgets, aging equipment, and one or two people covering everything technical. That combination is exactly what makes them attractive targets.

The Opportunity is to Protect, Not to Profit from Fear

I want to be direct about something, because I think our industry sometimes gets this wrong. Incidents like these are not a sales opportunity in the way that phrase is usually meant. Nobody in our community should be sending fear-based campaigns to water districts this month. What these incidents represent is a call for the Microsoft Partner ecosystem to step forward and do the work that these organizations cannot do alone.

Organizations across the country are searching right now for partners who can help them understand where their risk lives, implement Microsoft Defender properly, tighten identity and remote access controls, establish real security monitoring, and prepare for the audit and compliance requirements coming their way. Whether the customer is a county government, a school district, a regional healthcare provider, a manufacturer, or a defense contractor, the underlying question is the same. They want to know what is exposed, what it would take to fix it, and how long it will take. Microsoft Partners who can answer those three questions credibly are going to be very busy over the next several years.

Building Security Operations That Actually Scale

The single fastest growing need we see right now is for modern Security Operations Centers.

No organization can rely on a security review conducted once a year anymore. They need continuous monitoring, meaningful threat detection, an incident response process that people have actually practiced, and disciplined vulnerability management. The recent water sector incidents illustrate the point painfully well. A cybersecurity expert quoted in the NBC Chicago reporting observed that the ability of small water utilities to detect a cyber incident is often out of reach because of funding cuts and limited budgets, and that many of them did not know for a long time that they had been affected. That gap between compromise and detection is where the real damage happens.

The Partner Masters helps Microsoft Partners design, build, staff, and operationalize Security Operations Center offerings around Microsoft Sentinel, the Microsoft Defender suite, Microsoft Entra, Microsoft Purview, and Microsoft Security Copilot. That work includes defining the service itself, implementing the technology, writing the operational runbooks, establishing escalation paths, building the customer reporting, and preparing the partner's own staff to run it day after day. Done well, it becomes a recurring revenue stream for the partner and continuous protection for the customer.

You Can’t Afford Waiting Weeks for Cybersecurity Assessments

A traditional cybersecurity assessment takes weeks. Information gathering is slow. Configuration review depends on screenshots, spreadsheets, interviews, and a dozen different administrative portals. Then everything must be documented, prioritized, and translated into a remediation plan that an engineer must execute by hand.

We have invested heavily in this area using a different approach. The Partner Masters relies on Infrastructure as Code, Declarative State Configuration, and Policy as Code because these methodologies turn security and compliance work into something repeatable, scalable, auditable, and that can be executed quickly.

Combined with PowerShell automation, Microsoft Graph integration, and purpose-built assessment tooling, these approaches allow us to pull tenant configurations, Conditional Access policies, multifactor authentication coverage, endpoint settings, email protection settings, data protection policies, and logging configurations in a fraction of the time a manual review would require.

More importantly, once the findings are agreed upon and the changes are authorized, much of that same automation can push the corrections back into the environment consistently across every affected system. Work that would traditionally consume weeks can frequently be completed in days.

Speed alone is not the goal, and I want to be clear about that. Changes still need to be tested, approved, and introduced through a proper change management process. What automation gives us is the ability to spend our time on judgment and risk decisions rather than on data collection.

Configuration Drift is Natural

Here is what I have seen repeatedly over the years. An organization completes an assessment, implements a strong set of controls, and feels genuinely secure. Eighteen months later, the environment looks nothing like what was signed off on.

Administrators make changes. New services are enabled. A vendor receives temporary access that quietly becomes permanent. An emergency exception is granted on a Friday afternoon and never revisited. People change roles. Over time, the environment drifts away from the secure baseline without anyone making a conscious decision to weaken it.

This is precisely where Infrastructure as Code, Declarative State Configuration, and Policy as Code earn their keep. When the intended state is expressed as code, the current state can be compared against it continuously. Deviations become visible instead of invisible. The organization can determine what changed, whether it was authorized, and whether it introduced risk, and then restore the approved configuration when remediation is authorized. Security stops being an event and starts being an operating discipline.

Cybersecurity panel with digital readouts for CMMC compliance topics

Audits, Evidence, and CMMC Audits

The other benefit of this approach is one that most people overlook until an auditor is sitting across the table.

Many of our partners serve customers who face recurring audit obligations. Government contractors, members of the defense industrial base, and organizations in regulated industries must demonstrate not only that a control was implemented once, but that it has been operated continuously. They must show how the environment was configured, what changed, who approved it, how findings were remediated, and whether the control remains effective today.

The same scripts used to assess and secure an environment can capture configuration baselines, record changes over time, document implemented controls, track remediation activity, and produce time stamped evidence. Instead of reconstructing twelve months of history in a panic before an assessment, the organization already has a documented record. Automation does not guarantee an audit outcome, and the final determination always rests with the authorized assessor, but it dramatically improves the quality, consistency, and traceability of the evidence being presented.

For organizations working toward Cybersecurity Maturity Model Certification requirements, and particularly for those operating in Microsoft GCC and GCC High environments, this discipline matters enormously. CMMC is not a configuration exercise that gets completed and forgotten. Scope, governance, documented processes, personnel responsibilities, and evidence all have to hold up over time. We help partners build service offerings that address readiness, security control documentation, remediation planning, tenant security, and ongoing compliance monitoring so that CMMC support becomes a repeatable practice rather than a one time project.

Technology Alone Does Not Secure Anyone

Every engagement we run includes a component that has nothing to do with technology, and in my experience, it is often the difference between success and frustration.

Security changes affect people. If users do not understand what is changing, why it is changing, and what they need to do differently, even a technically flawless implementation will generate help desk volume, resistance, and workarounds that undermine the entire effort. Before we make significant changes, we help partners communicate clearly to the customer's user community about what is coming, when it will happen, how it may affect daily work, and where to get help. Administrators receive deeper training on monitoring, response, approved change procedures, and evidence preservation.

That preparation is what allows an organization to move into a substantially more secure posture with little to no business disruption. It is unglamorous work, and it is essential.

What These Attacks Should Teach Us

If I had to distill the lessons from the water sector incidents into something every organization can act on, it would come down to this. Organizations providing essential services are being targeted deliberately, not incidentally. Operational technology exposed to the internet represents risk that most organizations have never fully inventoried, and CISA has urged critical infrastructure owners, operators, and integrators to remove publicly exposed controllers and other operational technology from the internet as quickly as possible. Smaller organizations frequently lack the resources to detect sophisticated activity on their own, which is exactly why managed services and partner delivered security operations matter so much. And resilience deserves as much attention as prevention, because every organization should know how it will continue operating safely when automated systems become unavailable.

None of this is solved by purchasing a product. It is solved by people who know what they are doing through years of real-world experience, working through a disciplined process, supported by automation that makes the work repeatable and auditable.

Frequently Asked Questions

Why are municipal water systems being targeted by cyber threat actors?

Water and wastewater organizations provide essential services, and operational disruption creates immediate public and economic consequences. Recent reporting identified internet exposed programmable logic controllers and other operational technology as a common point of entry, often on systems connected directly to cellular modems.

Were the recent attacks formally attributed to the Iranian government?

As of August 18, 2026, the Center for Strategic and International Studies reported that the United States government had not publicly attributed the attacks, although CyberAv3ngers, a group associated with Iran's Islamic Revolutionary Guard Corps, claimed responsibility. The accurate description at this point is Iranian linked activity.

What is the difference between Infrastructure as Code, Declarative State Configuration, and Policy as Code?

Infrastructure as Code defines and deploys infrastructure through version controlled code rather than manual administration. Declarative State Configuration describes how a system should be configured so that the actual state can be continuously compared against the intended state. Policy as Code expresses governance and compliance requirements in machine readable form so that they can be evaluated consistently rather than interpreted manually.

How does automation help during a compliance audit?

Automation captures baselines, records configuration changes, tracks remediation activity, and produces consistent, time stamped evidence. It does not determine the audit outcome, which remains with the authorized assessor, but it substantially improves readiness and traceability.

The Partner Masters Runs on Trust

I have saved this for last, because everything above only matters if the partner delivering it can be trusted completely.

At The Partner Masters, we do not compete with Microsoft partners. We never take the customer relationship, go around the partner, or position ourselves as an alternative. We work behind the scenes as an extension of the partner’s team, and our success is measured by their success.

Whether a partner is building a security practice or needs additional expertise and capacity, our goal is the same: transfer knowledge, build capability, and leave the partner stronger than we found them.

Cyberattacks will continue, and Microsoft partners are on the front lines of protecting the organizations that keep our communities running. The Partner Masters is committed to helping partners become more capable, efficient, and prepared through expertise, automation, knowledge transfer, and trust.

References

  1. Chuck Goudie, Lisa Capitanini, and Nathan Halder, Government Admits Water System Cyberattacks Were Worse Than First Reported, NBC Chicago, August 26, 2026. Available at https://www.nbcchicago.com/investigations/government-admits-water-system-cyberattacks-were-worse-than-first-reported/3980961/
  2. Lorenzo Franceschi-Bicchierai, What We Know About the Alleged Iranian Hacks on U.S. Water Utilities, TechCrunch, August 14, 2026. Available at https://techcrunch.com/2026/08/14/what-we-know-about-the-alleged-iranian-hacks-on-u-s-water-utilities/
  3. Rithula Nisha, Iran Linked Cyberattack on US Water Systems Explained, Cyber Magazine, August 3, 2026. Available at https://cybermagazine.com/news/iran-linked-cyberattack-on-us-water-systems-explained

Related articles

Let’s achieve more together!

Ready to experience greater productivity and profitability with your Microsoft partnership? Reach out to us today!

  • Receive comprehensive Microsoft partner program support
  • Advance your technical, sales, marketing & operations capabilities
  • Increase efficiency so you have more time to do what you love

Your data is in safe hands. Check out our Privacy policy for more info.