What should IT take away from cyberattacks on water infrastructure?
It starts with understanding the constraints around OT, experts say.
• 3 min read
Recent cyberattacks on municipal water systems in at least 12 states highlight the need to harden critical infrastructure—and resolve the tension between IT and operational technologies (OT).
States with water facilities impacted by the attacks include Michigan, Minnesota, New Jersey, South Dakota, and more, according to CBS reporting. While the identity of the attackers remains unconfirmed, investigators suspect Iran-based hackers; the tactics used in this instance resemble that of a 2023 campaign from CyberAv3ngers, which targeted Israeli-made programmable logic controllers (PLC) and other equipment in water and wastewater systems.
On July 30, the Cybersecurity and Infrastructure Security Agency (CISA) released a statement urging the owners and operators of critical infrastructure to remove any publicly exposed PLCs and other operational technologies (OT) from the internet.
IT, meet OT. Rafe Pilling, director of threat intelligence for the Sophos Counter Threat Unit, told IT Brew that the vast majority of OT incidents stem from the accidental exposure of a system to the internet with default or weak credentials. Alternatively, OT systems may have an old vulnerability never patched.
Pilling said that there needs to be more connectivity between IT and OT, adding that IT professionals who understand the OT environment can better defend against infrastructure attacks.
While IT routinely tries to utilize the latest and most secure technologies, OT ecosystems may still rely on an older piece of software or hardware that acts as a controller for downstream devices. In the case of public sector organizations, this could be due to resource constraints on OT; with the public sector, it might stem from the potential downtime faced if a patch or upgraded tooling stops a system from communicating.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
“A lot of people get upset because people aren’t getting their water, or the cars have stopped getting made, and it’s been that kind of culture clash that has created a lot of friction over the years,” Pilling said.
Kevin Kirkwood, CISO at Exabeam, a global cybersecurity company, told IT Brew that in many cases, OT professionals may worry about damaging legacy tech that could disrupt a critical infrastructure’s operations, or the cost surrounding overhauling a system.
“It’s about how much do we pay just to keep the system operational and without replacing fundamental components that do probably need to be updated,” Kirkwood said.
Guided approach. For IT professionals who are looking to help OT workers secure their environment, Pilling said that the first step is to understand the environment on a granular level, along with potential attack surfaces. For example, IT might want to review where human machine interfaces (HMIs) sit on the network, and whether they are accessible via the internet.
Once an IT professional has understood the environment, then they should resist the urge to immediately enact change, as IT updates can take systems offline. Instead, Pilling recommended that IT ask OT staff if they can talk to a vendor about an upgrade pathway to a more current configuration.
“If not, what are the kind of compensation controls or mitigations that we can put in place, and often it’s things like isolation,” Pilling said. “There are some strengths to OT environments, and some basic monitoring can go a long way.”
About the author
Caroline Nihill
Caroline Nihill is a reporter for IT Brew who primarily covers cybersecurity and the way that IT teams operate within market trends and challenges.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.