A cyberattack on a municipal water authority in Pennsylvania has raised concerns about the vulnerability of water utilities to hacking. The attack was attributed to Iranian-backed hackers who targeted a piece of Israeli-made equipment. Security officials warn that hackers gaining control of automated equipment could shut down pumps supplying drinking water or contaminate water by reprogramming automated chemical treatments. Several states have introduced legislation to address cybersecurity in water utilities, but water authority advocates argue that lacking funds and expertise are the main obstacles. The upkeep of water infrastructure is already underfunded, and some cybersecurity measures have been seen as attempts to privatize the sector. Efforts to improve cybersecurity in the water sector have taken on new urgency after five attacks on water authorities were reported by the federal government’s leading cybersecurity agency over two years. Some states have passed legislation to enhance scrutiny of cybersecurity, while others have opposed bills backed by private water companies. The American Water Works Association and the National Rural Water Association, representing public water authorities, support bills in Congress to address cybersecurity concerns. The groups propose a tiered approach to regulation, with more requirements for larger or more complex utilities, and the deployment of federal employees called “circuit riders” to help smaller water systems detect and address cybersecurity weaknesses. If Congress does not act, the existing Safe Drinking Water Act standards, which are largely voluntary, will remain in place. Water utilities can apply for grants from a $1 billion federal cybersecurity program, but they will face competition from other utilities and organizations. Cybersecurity firm Dragos Inc. has started offering free access to its online support and software to help water and electric utilities detect vulnerabilities and threats. CEO Robert M. Lee said that most utilities lack cybersecurity help and that the feedback from those who received assistance has been positive.
States and Congress grapple with water utilities’ cybersecurity amidst federal alerts
Latest from Blog
Learn board security buy-in strategy from the NCSC for CISOs
TLDR: The NCSC provides guidelines for CISOs to communicate with the board effectively Key points include using non-technical language, making risks tangible, and connecting with what is important to the board In
DoD perfecting zero trust concepts during assessment process
“`html TLDR: The Pentagon is rigorously evaluating its zero trust use cases, including working with major cloud providers like Microsoft and Google. The goal is to achieve a target level of zero
EU push for unified incident report rules
TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and
Comcast reveals customer data stolen in ransomware attack on debt agency
TLDR: Comcast has reported a data breach affecting over 230,000 customers due to a ransomware attack on a third-party debt collection agency. The stolen data includes sensitive information such as names, addresses,
Maritime vessels face exponential cyber threats
TLDR: Cyber threats to maritime vessels are increasing rapidly Marlink will soon release a report detailing the growing problem Cyber threats to maritime vessels are on the rise, with a new report
San Diego Business Journal shines light on cyber risk, resilience
TLDR: October is National Cybersecurity Awareness Month and San Diego is a target-rich community for cybercrime. CCOE suggests four key areas to eliminate 98% of cybercrime: Recognize and Report Phishing, Use Strong
Educause Horizon Report: Sustainability driving Cybersecurity Risks on Campus Technology
TLDR: Educause released the 2024 Cybersecurity and Privacy Edition of its Horizon Report series Key trends include sustainability pressures leading to increased cybersecurity risks The 2024 Cybersecurity and Privacy Edition of the
PwC leads cyber resilience: organisations follow suit
TLDR: Despite cyber security concerns and the average data breach exceeding $3 million, only 2% of businesses have implemented cyber resilience. However, 77% of organizations expect their cyber budget to increase. The
Keep Security Week 2 Cybersecurity Action: Phishing Awareness Importance
TLDR: Keeper Security emphasizes the importance of phishing awareness during Cybersecurity Action Month. Individuals and organizations are urged to adopt and enforce practices to protect against evolving threats. With Cybersecurity Awareness Action
CT medical providers threatened by ransomware gangs, data and health at risk
TLDR: Key Points: Ransomware gangs are targeting CT medical providers, putting health data and care at risk Cyberattacks on healthcare have increased dramatically, impacting patient care and privacy Your health and personal