18706_Authority_Oct
municipalauthorities.org | 15 s ECuriNg thE f low : C ybEr aNd ot r EsiliENCE iN thE a gE of E mErgiNg t EChNology By Keon McEwen, Head of Solutions Development – Industrial Cybersecurity, Black and Veatch, and Matt Crow, PE, Project Manager, Black and Veatch Cybersecurity in the water sector is no longer a theoretical concern—it’s a daily operational reality. From ransomware attacks that disrupt billing systems to nation-state actors targeting programmable logic controllers (PLCs), the threat landscape has evolved rapidly. As water utilities embrace digital transformation through smart sensors, cloud-based supervisory control, and data acquisition (SCADA) systems and artificial intelligence (AI), the need to secure operational technology (OT) environments has never been more urgent. Recent incidents have underscored the vulnerability of water systems. In a Kansas municipality, a ransomware attack in 2024 disrupted billing and metering services, doubling water bills overnight. In Pennsylvania, the City of Aliquippa’s water system was partially compromised by the Iranian-linked group CyberAv3ngers. These attacks weren’t just about data theft—they targeted the physical systems that deliver water to communities. Unlike traditional information technology (IT) systems, OT environments control pumps, valves, chemical dosing and filtration processes. They are the heartbeat of water treatment and distribution. However, many utilities still operate with legacy systems that lack modern security features. These systems were designed for reliability and uptime—not for resilience against cyber threats. The convergence of IT and OT has introduced new risks. While IT networks handle business communications, OT networks manage the operational infrastructure. The two are increasingly interconnected, often through remote access points or shared data platforms. This connectivity, while beneficial for efficiency, creates pathways for attackers to move laterally across systems. A breach in IT can quickly cascade into OT, threatening water quality, service continuity, public safety and community public trust. Water utilities, a vulnerable target Several factors can contribute to the sector’s exposure: • Legacy infrastructure: many utilities rely on aging industrial control systems (ICS) and SCADA systems that were never designed with cybersecurity in mind. These systems often use default passwords, lack encryption and are difficult to patch. The infamous password on a sticky note resonates with the technicians we speak to in this domain. The focus was on keeping it running rather than cybersecurity. • Resource constraints: smaller utilities, in particular, face budgetary limitations. Cybersecurity competes with visible infrastructure needs — such as repairing water mains or upgrading treatment facilities. • Lack of policy and oversight: many utilities lack formal policies governing the devices that connect to critical operational systems. As a result, vendors often introduce unvetted equipment—such as laptops, tablets or even personal cell phones used as hotspots—without undergoing proper security screening. In some cases,
Made with FlippingBook
RkJQdWJsaXNoZXIy MjY5OTU3