Water utilities are a cybersecurity challenge that’s national in scope but local in responsibility | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Terry Gerton We’re going to talk about cyber attacks against water utilities. They continue to make headlines and generate concern in communities across the country. From your perspective, what makes water systems such attractive targets for this in the first place?

Ozgur Ozmen Yes, so water systems are critical for everyday use. They are used for like for our everyday needs. We drink it, we like use it for cleaning. And in addition to this, our industry is reliable, right? Like our data centers now cool with waters. And water is such a critical commodity to our lives. So any attacks, any disruptions to these water treatment plants, water systems, they cause disruptions in our lives. And this is what hackers, these malicious entities are trying to achieve basically. They are trying cause chaos, they are trying to cause disturbances in our daily lives. And water is a great target to achieve that.

Terry Gerton Many sectors operate critical infrastructure. We have the electrical grid. We have all kinds of things. Why do water systems appear to be so difficult to secure at a national level?

Ozgur Ozmen So, the main reason is because they are distributed. They are extremely distributed. Of course, like this has some benefits as well, right? Because if there is a single attack to a single municipality, it doesn’t spread that much outside of that municipality. But on the other hand, trying to secure all these distributed water treatment systems across the United States is a very, very difficult task. As far as I see, there are over 150,000 individual water treatment systems. So the attackers only need one or ten vulnerable systems. On the other hand, as defenders, as the government, we have to make sure that we secure each and every of these systems. And achieving that is definitely difficult because of the scale, basically.

Terry Gerton So really every water treatment facility stands on its own.

Ozgur Ozmen Yes, basically. Yes.

Terry Gerton You describe these systems as cyber-physical systems involving pumps and valves and pressure systems. How does defending a cyber- physical system differ from defending a traditional IT network?

Ozgur Ozmen Yes, that’s a great question. So, cyber physical system is, as the name also implies, there are two sides of every attack. One, like the cyber component, the other is the physical component. First, the attackers can enter these systems through both cyber and physical components. They can conduct cyber attacks to a cyber physical system, but they can also conduct some physical attacks. The attacks we observed so far, they were generally cyber attacks, but a cyber-physical system also exposes, enables physical attacks where attackers can disrupt sensors, actuators directly to influence, to impact these cyber physical systems and the other aspect is the consequence in a cyber attack Traditionally the attacker can steal your information, can like put some malware into your laptop, into your computer, put some ransomware to extract some money from you. In a cyber-physical system, these attacks can also cause physical consequences. And these can be much more severe than actually cyber consequences. In a water treatment plant, this can cause poisoning the water. It can cause water to be unavailable to… Like people in some other cyber-physical systems, again, these would have different physical consequences the attacker can achieve. And that’s what makes these CPS, we call them, unique and more attractive to the attackers as well.

Terry Gerton It seems like in the attacks that we’ve seen so far, the actual quality of the drinking water wasn’t compromised, but other aspects of the water distribution system were the focus of the attacks. What does that tell you about how well we’re securing different parts of the system? Or does it just tell you that that’s where the attackers went first?

Ozgur Ozmen I would say, so then, securing, we can understand it in different perspectives, right? One is securing in terms of, like, resilience, how resilient these systems are, how well they are designed to detect and recover from attacks. I think the fact that we didn’t see very serious consequences showed that we have resilience in general water treatment infrastructure. But… On the other hand, robustness, how well we designed the system so that the attackers are not even able to get into our systems. I think we are still not there in terms of keeping the attackers away from our critical infrastructure. So they are able to get into these systems but the impact they cause is limited because our personnel they are able to detect and respond to these attacks in a timely manner. But this also creates another vulnerability. If these people are not available if the attack happens at the wrong time and humans they can make some errors when they are trying to detect and respond to these attacks if this happens then the consequences could be much, much higher. So definitely we need to still improve how we can prevent these attacks even from happening at the first place

Terry Gerton Ozgur Ozmen is assistant professor at the School of Computing and Augmented Intelligence at Arizona State University. Let’s talk about the prevention. You are a college professor teaching this now. What’s at the top of your list in terms of reforms or things we could do differently that would actually help us secure our water systems?

Ozgur Ozmen Yes, that’s a great question. So as a college professor, definitely education is extremely important. We have a lot of cybersecurity professionals, we have a lots of people working in the operational technology side, learning how cyber-physical systems operate, but the intersection of these, like experts or cyber physical system security is what we need for securing these water treatment plants, electrical infrastructure, these cyber physical systems. And at ASU we have courses, we have programs trying to make sure that we are educating the next generation of these cyber system security professionals. And besides the educational side we also need some tools, automated tools that these water treatment plants can deploy and use to understand the vulnerabilities and how to prevent those vulnerabilities in their systems. Why I am saying this is because FBI, CISA, they release a lot of advisories which are extremely detailed and extremely useful. But like how to make sure that these water treatment systems actually follow these advisories is a very difficult question to answer and since considering the scale of them making sure that all these individual water treatment system follow these advisories we need to make steps towards that actually and how that happens is a really big question, but it starts from some regulations and regulations that can be actually checked and enforced. And this should definitely happen in collaboration with these water treatment systems, water plants and understanding what can be checked and what can enforced and actually regulating them.

Terry Gerton One of the challenges that we hear is, of course, back to the number of these plants that stand alone, 150,000 in communities of all sizes across the country. Some communities can afford to update their equipment and some communities can’t. And those small communities may not have a cybersecurity expert on board. So, again, back to your points about how do we build resilience into this system. Is it the regulations and trying to bring people up to speed on those or is it some form of technology investment perhaps funded through federal grants or something like that that really brings all of the systems up to a common standard?

Ozgur Ozmen Yeah, that’s a great question. To be honest with you, I think we need both. Definitely we need the both of these aspects. One without the other may remain limited. If we have the technology but we don’t have the personnel, the people to actually use the technology correctly, then the technology itself is not that impactful. We cannot get the most out of the technology that we have. And for instance, these attacks that already happened, they were all preventable. We have the technology to prevent all of these attacks. Not connecting your controllers to the internet, changing your passwords to things that cannot be easily guessed. If all the plants did this, these attacks, most of them would not happen at all. So, in some cases, we have already the technology but don’t have the people to use them. But with the AI and the complexity of these attacks changing, we also need, of course, new technology to detect and respond to these new types of threats that are targeting our cyber-physical systems.

Terry Gerton And Ozgur, since we don’t have a national water system, whose responsibility is it to write those regulations that would enforce compliance with new technology and standards? Is it every state that’s got to make these up on their own?

Ozgur Ozmen For me, I think it should start with the federal government trying to bring these individual states and individual, like water treatment systems together and then the discussion from there hopefully would grow. As far as I see, like for instance there is a national North American Electric Reliability Corporation that enables regulating the power industry. And a similar agency for water companies, water treatment systems, it would definitely be extremely helpful for them to actually get help, if needed, from a central agency and try to create these standards together with them that would encompass all of these individual states and municipalities.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.