Aging US water systems under attack by ransomware

Share post:

Recent cyberattacks on U.S. water systems, including an incident involving an Iran-linked hacker group targeting a water authority in western Pennsylvania, have heightened federal focus on the cybersecurity vulnerabilities of water utilities. These attacks, which also affected a North Texas water utility with ransomware, did not disrupt water supplies but underscored the urgent need for improved cyber defenses.

Anne Neuberger, Deputy National Security Adviser for Cyber and Emerging Tech, emphasized the importance of these events as a wake-up call for utilities to enhance their cyber hygiene. The U.S. water system consists of about 150,000 individual systems, most of which are small, municipality-run entities with limited resources for cybersecurity staff and training. Many of these systems rely on older infrastructure, complicating upgrades and cloud integration.

Prior to these attacks, the Biden administration faced challenges in regulating cybersecurity in the water sector. An attempt by the Environmental Protection Agency to integrate basic cyber questions into sanitation inspections was withdrawn due to legal challenges.

However, a recent report by Microsoft and the Cyberspace Solarium Commission 2.0 (CSC 2.0) suggests ways forward. It recommends that water sector operators conduct risk assessments, implement multifactor authentication, and utilize available state funds for cybersecurity improvements. Over the next year, initiatives by Microsoft, the Cyber Readiness Institute, and the Foundation for Defense of Democracies will focus on coaching small water utilities in cybersecurity and employee training.

Tom Fanning, Executive Chairman of Southern Company, highlighted the urgency of the situation, urging water utilities to proactively utilize available cyber resources without waiting for new regulations.

Source: Axios

SUBSCRIBE NOW

Related articles

Resignations at OpenAI. Hashtag Trending for Friday, May 17, 2024

The question changes from “where’s Ilya” to what took so long?  Did Musk’s Neuralink team know there might...

Google does the unthinkable – reportedly erasing a 125 billion dollar pension fund

It's reported that Google inadvertently erased the Google Cloud account of UniSuper, an Australian pension fund valued at...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

iOS update brings back photos users thought were permanently deleted

After a recent iOS update, a number of iPhone users have found themselves facing unexpected blasts from the...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways