https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
  • Resources & Events
    • Back
    • Resources
    • Webinars
    • White Papers
    • IWCE 2022
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
  • Resources/Events
    • Back
    • Webinars
    • White Papers/eBooks
    • IWCE 2022
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
  • Magazine
acc.com

Commentaries


Photo by El Sun from Pixabay

Commentary

Why water utilities must invest in cybersecurity

Why water utilities must invest in cybersecurity

  • Written by Kristen Sanders
  • 5th May 2021

In Albuquerque, N.M., arid conditions and frequent droughts make water a precious commodity that must be carefully managed. Aggressive conservation programs, water recycling and storage of excess water underground (safe from evaporation) are just some of the methods we employ to safeguard the water supply for our 650,000 users. Recently, safeguarding has taken on new meaning for utilities such as ours, as cybercriminals have made water suppliers targets for attack.

Everyone in the water industry fears a repeat of what happened in Oldsmar, Fla., last February, when hackers took advantage of a remote-access system that was beyond the local water utility’s security perimeter. The intrusion only lasted between three and five minutes, according to the Tampa Bay Times. But that was time enough for the hackers to increase the levels of sodium hydroxide (lye) being fed into the water system as a corrosion inhibitor from 100 parts per million to 11,100 parts per million. If not for the operator who saw the change and quickly corrected it, it could have been a disaster.

The harsh reality is that too many water utilities are stuck with antiquated systems and limited visibility into what’s happening in their operational technology (OT) environments. Historically, OT environments and IT environments were completely separated (air-gapped). We are now able to leverage smart sensors to help detect leaks and save manpower. This technology allows water utilities to become proactive as opposed to reactive. However, this also means the convergence of IT and OT environments. Often, equipment within OT environments was never designed with the intent of one day communicating with IT networks. This opens a whole new world of vulnerabilities that must be addressed, and air-gapping is no longer an adequate fail-safe response.

Fortunately, the Water Authority is not afraid of innovation, and we’re taking advantage of remarkable new technology that offers solutions to the challenges of OT/IT convergence and the security risks that arise when these worlds come together.

Deploying this technology was not an overnight process, and we didn’t fully recognize the need for it until our IT and OT teams began collaborating more on system integration. This led to the realization that our end-of-life network equipment was not up to the task—and that our IT staff lacked an in-depth understanding of the operational environment. Cisco technology opened a window for us into that environment, allowing us to safely leverage the benefits of IoT sensors to monitor a vast array of operational metrics: equipment efficiency, water conditions and even the presence of system leaks. This emerged from our participation in Cisco’s County Digital Acceleration program, which included the stand-up of a network refresh with the help of Cisco Customer Experience (CX), and added solutions like Cisco Cyber Vision, an asset inventory and threat detection tool for industrial control systems that gives both IT and OT teams intuitive and clear visibility into all that’s happening. Besides making the utility more efficient, these improvements mean that we can see and respond to anomalies in real time.

You can’t protect what you don’t know about, and you can’t detect anomalous behavior if you don’t know what’s “normal.” Visibility is key to detecting malicious activity before operations are negatively impacted. A common problem with cyberattacks is that security teams simply don’t know they’re happening, leaving hackers free to steal information or disrupt operations for days, weeks or months.

With solutions like these in place, utilities can become hard targets for cybercriminals. The incident in Oldsmar brought important awareness to the weaknesses in utility IT and OT systems that hackers are eager to exploit.

A recent report from the FBI revealed a 69 percent increase in cybercrime complaints from 2019 to 2020, noting that most cybercriminals had access to networks for several weeks or even months before they were discovered. Given these recent events and threats trending higher, utility companies must become more vigilant in securing their operations—which starts with investing in a security strategy that enables visibility for early threat detection.

It can be challenging for any utility company to justify network upgrades or enhanced security, especially when post-pandemic budgets are tight and revenue is down. Given all that’s at stake, though, there is no better expenditure than taking steps now to secure essential utility services for the public.

Kristen Sanders is the chief information security officer at the Albuquerque Bernalillo County Water Utility Authority.

 

Tags: homepage-featured-1 homepage-featured-4 Public Works & Utilities Commentaries Commentaries Public Works & Utilities Smart Cities & Technology Commentary

Most Recent


  • EV infrastructure
    EVs are coming in a big way – Will charging infrastructure be ready?
    The California Air Resources Board recently announced a new goal of tripling electric vehicle (EV) sales over the next four years, reaching 35 percent of all new vehicle sales in the state by 2026. An executive order is already in place dictating that zero-emission vehicles will be 100 percent of all new vehicle sales in […]
  • MSPs
    The MSP downstream cyberthreat paradox: Understanding the city and county connection
    Recently the Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI, NSA, and international cyber authorities issued a cybersecurity advisory aimed at protecting managed service providers (MSPs) and their customers. This high-level advisory has been gestating for some time ever since the SolarWinds and Kaseya supply chain cyber-attacks. A software supply chain attack occurs […]
  • EV chargers
    Cities steadily adding more EV chargers for public to use
    Local governments are making headway as they develop their electric vehicle (EV) infrastructure. “Progress varies depending on what stage governments are at in the electrification strategy and funding availability,” says Brandon Branham, assistant city manager and chief technology officer for Peachtree Corners, Ga., which is part of the Atlanta metro. Its 2022 population is estimated […]
  • Four years after Hurricane Michael, Panama City, Fla. is replanting, rebuilding
    It’s been nearly four years since Hurricane Michael ripped through Florida’s panhandle, leaving a trail of destruction in its wake that’s still being felt.   “We lost 80 percent of our trees,” said Greg Brudnicki, mayor of Panama City, a municipality of around 30,000 people on Florida’s panhandle. He estimated the number of trees the […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • NLC releases State of Cities 2021 report
  • How local governments can get ahead of the infrastructure wave: Strategies to mitigate risk
  • Prioritizing rapid restore leads to stronger ransomware attack recovery
  • Ultrafast electric vehicle charging will propel local governments into the future

Twitter


AmerCityCounty

Changing recruitment practices can ease retention challenges dlvr.it/SQzzPt

24th May 2022
AmerCityCounty

EVs are coming in a big way – Will charging infrastructure be ready? dlvr.it/SQzfL1

24th May 2022
AmerCityCounty

Optimizing the 3 stages of RFP creation for faster results | June 16, 2022 at 2 PM ET dlvr.it/SQzV7d

24th May 2022
AmerCityCounty

Amid digital evolution, equity in accessibility is of utmost importance dlvr.it/SQwZ3b

23rd May 2022
AmerCityCounty

Hand Hygiene: Compliance Matters dlvr.it/SQwL8f

23rd May 2022
AmerCityCounty

What it Takes to Build a Winning Esports Program dlvr.it/SQwJRj

23rd May 2022
AmerCityCounty

Sixth-Largest US School District Saves Over $500,000 by Utilizing a Cooperative dlvr.it/SQwHPv

23rd May 2022
AmerCityCounty

Amid shifting workplace expectations, local government employers must adapt dlvr.it/SQm2RT

20th May 2022

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X