For many, last week’s cyberattacks on water systems throughout the U.S. was a wake-up call. Many municipal water systems are sitting ducks for hackers. But experts say there’s plenty that operators can do to protect city water.
“The systems are unprotected because they are misconfigured,” Annie Fixler, director of the Center on Cyber and Technology Innovation Foundation for Defense of Democracies, told Smart Cities Dive. “They are configured for ease of access without security in mind.”
When water systems were digitized in the 1990s and 2000s, manual operators were replaced with programmable logic controllers, internet-facing computers that monitor input signals from sensors to control output devices like motors and valves, Fixler explained. But the systems were configured to make it easy for operators “without thinking that some malicious actor might want to use that same access to sabotage systems,” she said.
”While they could and should be behind layers of firewalls, authentication pathways and access controls, they are not set up that way because they were set up quickly or by someone who was not familiar with cybersecurity concerns or by a third party who similarly wasn't thinking about the security aspect and said, ‘Here you go. Here's your remote access. You're all good to go. Bye.’ We are now paying for the lack of investment.”
Many municipal water systems, especially in smaller cities, lack the staff to focus on things like firewalls and cybersecurity because “keeping the water on is their main goal,” Lessie Skiba, deputy managing director for the Cyber Readiness Institute, told Smart Cities Dive. More than 97% of the nation’s 156,000 public water systems serve fewer than 10,000 customers; many of those have aging systems and operate with minimal IT or cybersecurity personnel, a Cyber Readiness Institute report found. “Their capacity to respond to a cyber incident is limited,” the report states.
In small municipalities, the person managing the water utility is often also a county commissioner or even the mayor, Skiba said. “This cybersecurity conversation, they know it’s important, but they’re not even really sure where to start.”
In an Aug. 5 letter, the American Water Works Association urged congressional leaders to provide utilities with federal funding to address critical cybersecurity needs, including cybersecurity training for utilities of all sizes, because “threat actors will continue to adapt and seek out vulnerabilities.”
Smart Cities Dive talked with water and cybersecurity experts, who laid out five steps water system operators can take to protect against the next cyberattack. Protection is imperative, said Cyber Guardian Consulting Group CEO Nick Martin, a member of the U.S. Secret Service Cyber Fraud Task Force, because “these bad actors are doing things at light speed.”
1. Enforce basic account hygiene.
Operational systems designed to facilitate remote operations are inherently vulnerable to cyberattacks, “especially if utilities do not take basic security steps like changing default passwords,” Dan Hartnett, interim chief executive officer of the Association of Metropolitan Water Agencies, told Smart Cities Dive in an email. For that reason, they should prioritize “fundamental cyber hygiene measures, including multifactor authentication, timely patch management, network segmentation, and tested backup and recovery capabilities,” Bhavesh Vadhani, partner and global leader of CohnReznick Advisory’s Cybersecurity & Digital Trust, said in an email.
All water system operators, large and small, should ensure that passwords are unique, software is updated, and storage and file transfers are secure, Skiba said. Everyone within a utility — not just the IT manager – should be aware of these fundamental steps, she said, because they can protect against “a significant number of the types of attacks that are targeting them.”
This includes getting a full technical assessment of all the utility’s laptop and desktop computers, servers, cloud environments and other network points to determine where firewalls are misconfigured, outdated or simply missing, Martin said. “They all play a role,” he said.
2. Build an incident response plan before an attack happens.
Utilities need to know “who to call, how to react, how to respond and how to recover” as soon as an incident occurs, Skiba said.
In its Cyber Readiness Program’s Water Utility Addendum, the Cyber Readiness Institute offers a free downloadable incident response plan that it developed with water experts, she said.
3. Take non-essential operational technology systems offline and preserve manual override capability.
The utilities that got hit in last week’s attacks mitigated damage, for the most part, by switching to manual operations, which was disruptive to the utility but mitigated public health and safety concerns, Fixler said.
Smaller municipalities that lack in-house technical expertise should disconnect control systems from the internet until a proper security assessment can be done, Martin said.
4. Join a threat-intelligence sharing network.
The Association of Metropolitan Water Agencies recommends that all water and wastewater systems subscribe to the Water Information Sharing and Analysis Center, or WaterISAC, a resource that provides member water systems with information on the latest threats and steps to respond to them, Hartnett said.
A provision in the Water Resources Development Act, which was recently approved by the Senate Environment and Public Works Committee, would direct the U.S. Environmental Protection Agency to help more water systems become WaterISAC members, he said.
5. Build relationships with federal and state agencies before an incident occurs.
“The adage of emergency responders is you never want to be trading business cards on the back of a truck,” Fixler said. “You want those relationships established ahead of time. … Build that network now.”
Local Federal Bureau of Investigation offices have agents responsible for coordinating with critical infrastructure, and the Cybersecurity and Infrastructure Security Agency’s regional offices have cybersecurity advisors, she said.
State agencies are also there to help, said Anthony Festa, managing director and national practice leader, machinery and equipment valuation, at Marshall & Stevens, which provides valuation and advisory services for water-related assets. ”I would implore operators or mayors that have questions to work with their state public utility commissioners,” he said. “They meet with industry experts constantly, and they’re there as a resource. They’re there to connect the dots. No one should feel that they’re on an island.”