Metro State offers look inside the cybersecurity problem impacting water systems nationwide | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Metro State University has been bolstering cybersecurity training on the same type of critical infrastructure controls hit by hackers recently.

ST PAUL, Minn. — Beneath Metro State’s New Main building, professor Faisal Kaleem can pinpoint the source of a cybersecurity problem that has impacted water systems in at least seven states, including more than 30 in Minnesota.

“If I open up this one, you can see inside that we have the PLCs,” Kaleem said, showing off a water pump simulator that contains a Programmable Logic Controller (PLCs).

In recent days, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about a “significant increase” in cybersecurity attacks targeting those PLCs in the water and wastewater sector.

Kent Erdahl: “So that’s the little controller that controls the pump?” 

Professor Faisal Kaleem: “Yes.” 

Erdahl: “And that’s what they hacked into?” 

Kaleem: “That’s what they hacked into in our water attacks, and they were actually able to take it over.”

According to Minnesota IT, the impact of the attacks was minimal. They reported no impact on water quality, and all of the impacted systems were able to switch to manual controls before noticeable disruptions to service.

“In the future, we may not be that lucky,” Kaleem said.

Despite the quick action, he said the issue with PLCs has been known for years. The EPA has been warning of a cybersecurity threat to drinking water via PLCs since finding “Alarming Vulnerabilities” in over 70% of the systems inspected dating back to 2023.

Kaleem: “Most of them are using default credentials, which also is a major issue… You search online right now, you’ll be able to find out what is the username and password for a particular PLC.”

Erdahl: “So essentially, when they installed that device, they never created their own password?” 

Kaleem: “Yes, most of the time. Most of the time that happens, and that’s where the cyber hygiene training comes in.” 

Cyber hygiene training is just one way that Metro State has been working to increase local cybersecurity help to local cities and counties through its MN Cyber Institute.

“The very reason why these attackers are successful – and especially when it comes to the municipalities – is because they are underserved,” he said. “Why are they underserved? Not just from the resource perspective but from the Human Resource perspective. The last time I checked, nationwide, there are approximately 700,000 jobs available in cybersecurity. Just in Minnesota, there were approximately 7,000 jobs available, and what Metro State is trying to do, is we’re trying to fill those roles.” 

That type of demand won’t be met overnight, which is where the university’s new Minnesota Cyber Center comes in.

“This side over here is what we call our education security operations center,” Kleem said. “This is going to come online in three weeks.”

The new center will be a real-world training ground for students, who will work shifts maintaining actual cybersecurity monitoring for Metro State. 

“It’s a win-win for the students and the university,” he said. “In fact, this is going to be very, very important – not just for Metro State – but I would say for the entire Minnesota state system, which Metro State is part of.” 

And once that is up and running, Metro State has already built out a similar community resource. It received federal dollars to create an off-campus Security Operations Center, which will be available to underserved local governments and schools that need support.

“The communities are getting better protection while we are providing the training for our students,” he said.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW