Terry Gerton We’re going to talk about cybersecurity. And when we do that, generally, I think people think about cybersecurity and data or computers. You’ve got a new report out, though, that focuses on operational technology, specifically ones that move and treat water. Why is OT security such a different challenge?
CheeYee Tang Well, OT technology works in a different environment. So safety, reliability, often under unique operating environments. So all of those factors are important to work for an OT environment, for example for the water and wastewater system. So that makes a tremendous difference than the IT system. The OT system requires a lot of different attention because the system behaves differently or works differently than a pure IT system. That’s why OT has a big challenge. For example, So the OT system could be a very long lifetime, it could be like 15, 20 years or even more that equipment can last that long. So to address those systems, we require very specific security measures to do that.
Terry Gerton Your report specifically focuses on remote access for operational technology. Why did you identify that as such an immediate high priority issue for the water sector?
CheeYee Tang Well, based on our survey to the industry and some of our research work, we identified a few things. For example, network access management, network cementation, and remote access, they are all important. But all of those, it appears to us that remote access is the top priority of many respondents on the survey and the industry concerned. That’s why we started with that.
Terry Gerton And what are the threats to the water system specifically that you’re worried about?
CheeYee Tang Well, for the remote access, we worry about unauthorized access to the remote site of the water system. Some of those remote sites are unmanned, and they do have the control equipment, and they too have the ability to disrupt the operating of the system. So if an unauthorized intruder hacked into the system, they could have the potential to disrupt the normal operation and also may cause a system failure.
Terry Gerton I suspect that the average person only thinks about water when they turn on the tap or when they buy a bottle at the store. So when you think about this operational technology and remote access for maintenance and monitoring and vendor support, how does it create that opportunity for unauthorized access that you’re just talking about?
CheeYee Tang So like you said, the maintenance and the support, they are a huge efficiency enhancer. So people can remotely access some of the equipment and they don’t have to physically go there. So it helps increase the operation efficiency. But on the exact opposite side, if you have people with a bad intention trying to, through the same channel, get into those equipment, then they may have the ability to do some bad impact to the system. They could disrupt and stop the water. They could potentially change the content of the water system. So those are the things that we worry that will be impacting the normal operation and the safe delivery of drinking water and treatment of wastewater.
Terry Gerton Even though clean water is certainly a public asset, many of the water plants and utilities are contractor operated, if not privately owned. How does that change the risk profile here?
CheeYee Tang Well, to our knowledge that many of them, they are different sizes of operation, so it could be, like you said, it could the operator operating it, it could be a contractor operating it. So the water sector has a wide variety of different operation in terms of size and operation and expertise in the cybersecurity sense of, in that manner. So that created a problem. We saw that a larger capability water system may have the resources and the knowledge to defend their system. But we also see that a lot of smaller capability water systems may not have that expertise. So that may create a problem that some of the systems are more vulnerable than the others.
Terry Gerton Chee Tang is an electronic engineer at NIST. Chee, let’s follow on with what you were just talking about, different sizes of operations, different staffs, different budgets. How did that reality shape the architectures and solutions that NIST chose to demonstrate here?
CheeYee Tang So in our publication, we develop three different reference architecture. The intention is to showcase a different way to protect your system. One of them is more classic. The other one is more using the base on cloud computing. That will give the advantage of a smaller scale system that may be able to take advantage of that. That require a little less expertise and have a more budget-friendly entry costs so that they can still have a secure remote access, but they do have a little more flexibility and scalability on the deployment.
Terry Gerton If you were a utility manager listening today and you could only do one thing to improve the security of your water treatment plant, looking at this article, what would you hope that they would do first?
CheeYee Tang That’s a hard question, Terry. You know, the hard is not because of like, what the technology can do, but hard as like, you only can pick one thing, right? So security, as often as you know, security comes as a package. And any weak link may be exploited by the malicious actor. So we try to have a whole package that make this whole system secure. Now, but if I have to pick that one thing I think is to strengthen your authentication or access control to your remote access site so that you have a stronger authentication scheme and also combined with a stronger access control so that you can more protect in that way. Now that doesn’t mean that that solves all your problems as I have to re-emphasize that is a whole package, but if you have to do something, you have to pay, I think that is something, authentication and access control is something you want to consider.
Terry Gerton Oftentimes when I ask that weakest link question, I get a technology answer. And many times we find out that in fact, the people in the system are the weakest link. What are you seeing as the best training or preparation for the humans in this loop to help prevent malicious access?
CheeYee Tang That’s a very good observation. As we say, to protect the whole system, technology is only play a part of it. So the policy, so the organization governance and the whole training and the policy environment does do the whole thing. So as you said, like, it is a human operating system. So all the control system, all the equipment and automation is only helping the human to do their job more efficiently. So the training and the policy of the organization does play an important role in how to protect the overall security.
Terry Gerton And your guide says that these concepts apply beyond water utilities to OT environments more generally. What lessons should federal agencies and other critical infrastructure operators take from this work and apply in different situations?
CheeYee Tang So, many critical infrastructure operators, they have very similar challenges and very similar operating environments. So we think that the lesson we develop or the lesson you learn or the reference architecture we develop in this competition, it could be used by other sectors at least in the high level and architectural level. You may have to modify a little bit in the detail on how you deploy it, but in the general concept, in the general, like, how you secure the remote access, we think that’s a good example for the other sectors to consider.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
