18706_Authority_Oct

20 The Authority | October 2025 H ave Y ou T HougHT a bouT C YberseCuriTY T odaY ? As you are reading this article you will notice links to resources to assist drinking water and wastewater utility management with enhancing cybersecurity resilience. You should be thinking about clicking on links, or not clicking on links, whenever you are on your computer, phone or tablet. That is a basic tenet of cybersecurity. The links in this article are safe to follow, but that may not always be the case in emails from unknown persons or on webpages. It is wise to hover over links to see the details of where the link will take you or to copy and paste into your browser. These days there is much more going on in the background than any of us knows. Those that wish to do water utilities harm (see text box) have reached high levels of sophistication meaning we all need be much more aware, seek to learn more about how to protect ourselves and how to react if we are suspicious or suspect someone has penetrated our network or devices. You can stay on top of threats by signing up for alerts and notifications of new webinars and other resources from EPA at [subscribe EPA]. This is an ever-evolving landscape; therefore, cybersecurity needs to be thought about every day. Your actions to protect your utility is not a once and done process. Prompt responses to cyber incidents may lessen the impacts meaning less down-time of treatment plants, less impacts to water quality or quantity, and fewer concerns for impacts to public health. You do not need to become an IT expert to act to protect your utility. Let’s start with some simple steps that will go a long way to enhancing your cybersecurity. Much of this starts at the top with management establishing a culture that fosters awareness of the concerns, offering staff training opportunities, taking steps to evaluate Internet exposed devices and then taking the necessary steps to remove or protect these devices. See the text box for eight proactive steps identified by EPA as a good place to start. For more sophisticated operations, you may need to hire an IT expert or depend on your vendors. Those that want to harm water utilities • Nation States for Geopolitical Reasons; • Hacktivists for Ideological Reasons; • Terrorist Groups for Ideological Violence; • Insider Threats due to Discontentment; • Cyber Criminals for Profits; • Also be aware of mis-information (incorrect information intentionally provided); and • Dis-information (intentionally provided to mislead, disrupt and create fear) Proactive Steps 1. Reduce Exposure to the Public Facing Internet 2. Conduct Regular Cybersecurity Assessments 3. Change Default Passwords Immediately 4. Conduct an Inventory of OT/IT Assets 5. Develop/Exercise Incident Response/Recovery Plans 6. Backup OT/IT Systems 7. Reduce Exposure to Vulnerabilities 8. Conduct Cybersecurity Awareness Training

RkJQdWJsaXNoZXIy MjY5OTU3