For many, last week’s cyberattacks on water systems throughout the U.S. was a wake-up call. Many municipal water systems are sitting ducks for hackers. But experts say there’s plenty that operators can do to protect city water. “The systems are unprotected because they are misconfigured,” Annie Fixler, director of the Center on Cyber and Technology Innovation Foundation for Defense of Democracies, told Smart Cities Dive. “They are configured for ease of access without security in mind.” When water systems were digitized in the 1990s and 2000s, manual operators were replaced with programmable logic controllers, internet-facing computers that monitor input signals from sensors to control output devices like motors and valves, Fixler explained. But the systems were configured to make it easy for operators “without thinking that some malicious actor might want to use that same access to sabotage systems,” she said. ”While they could and should be behind layers of firewalls, authentication pathways and access controls, they are not set up that way because they were set up quickly or by someone who was not familiar with cybersecurity concerns or by a third party who similarly wasn't thinking about the security aspect and said, ‘Here you go. Here's your remote access. You're all good to go. Bye.’ We are now paying for the lack of investment.” Many municipal water systems, especially in smaller cities, lack the staff to focus on things like firewalls and cybersecurity because “keeping the water on is their main goal,” Lessie Skiba, deputy managing director for the Cyber Readiness Institute, told Smart Cities Dive. More than 97% of the nation’s 156,000 public water systems serve fewer than 10,000 customers; many of those have aging systems and operate with minimal IT or cybersecurity personnel, a Cyber Readiness Institute report found. “Their capacity to respond to a cyber
Protecting water systems from cyberattacks: 5 steps <b>cities</b> can take now
Read the original article
smartcitiesdive.com →