https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
  • Resources & Events
    • Back
    • Resources
    • Webinars
    • White Papers
    • IWCE 2022
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
  • Resources/Events
    • Back
    • Webinars
    • White Papers/eBooks
    • IWCE 2022
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
  • Magazine
acc.com

Public Works & Utilities


Photo courtesy of WIN-911

Article

Remote alarm notifications add firewall as utilities face mounting threats of cyberattacks

Remote alarm notifications add firewall as utilities face mounting threats of cyberattacks

  • Written by Cody P. Bann
  • 27th May 2022

Municipal utilities are critical to national security, economic stability, and public health and safety. As technology in these sectors evolves, cyberattackers take advantage of opportunities to exploit vulnerabilities. While the Federal Government has taken steps to address this issue by creating innovative public-private partnerships and initiatives, the worldwide attacks on municipal utilities in the past year have virtually doubled. Additionally, because of the geopolitical unrest, cyberattacks have become such a threat that President Biden has urged private sector partners to immediately harden cyber defenses.

Remote alarm notification software offers additional security

A report by the American Water and Works Association, “Cybersecurity Risk & Responsibility in the Water Sector,” states that “…Failing to address cybersecurity risk in a proactive way can have devastating results. Failing to take reasonable measures and employ best practices to prevent, detect, and swiftly respond to cyber-attacks means that organizations and the people who run them will face greater damage—including technical, operational, financial and reputational harm—when the cyberattacks do occur.”

Utilities face myriad challenges to managing cyber risk due to varying infrastructure and entities of vastly different sizes, capabilities, resources and types of ownership. However, turning to additional technology is one answer.

Although replacing legacy systems and networks can be extremely costly, it is essential to work with vendors and cybersecurity experts to implement updates and, if necessary, overhauls of outdated systems. Invoke the help of internal or external advisors to prioritize risks and develop a realistic approach and plan for enhancing cybersecurity. At a minimum, utilities must comply with basic standards including restricted physical and technical access, firewalls, logging and encryption.

Many Supervisory control and data acquisition (SCADA) systems are simply over-exposed to the internet by remote desktop applications (e.g. RDP and TeamViewer). To offer process and asset information to operators, organizations have provided much more, ignoring the principle of least privilege and opening their entire control systems and their hosts to remote desktop access by unnecessary parties. Such broad remote access techniques present an increased security risk for organizations, a risk that Oldsmar experienced firsthand when an improperly secured TeamViewer application allowed an unauthorized party to increase the amount of sodium hydroxide being added to their water treatment process.

Advanced remote alarm notification software allows remote operators access to only the information they need from SCADA but not access to the SCADA itself or its operating system host. Such notification software is compatible with more secure, layered networks in which a series of firewalls provide added protection from attacks. This is done by deploying notification solutions alongside the SCADA system at the network’s control level and using notification modalities that are not internet facing or distributing internet-facing notification processes to higher levels. For example, internal email servers, SMS modems and voice via PBX devices allow communication with the outside world without internet exposure. Likewise, distributing the processes that interface with SCADA from those that interface with external email servers, VoIP solutions and cloud apps allows internet-based notifications without compromising security.

Of course, there are valid use cases for desktop sharing software that do not violate PoLP and go well beyond operator access to process information. For such systems it’s critical that the remote desktop solutions be implemented with sound security.

Utilities should also take steps to secure any remote access software. They should not use unattended access features, and IT leaders should configure the software such that the application and associated background services are stopped when not in use. Integrating the remote alarm notification software through the SCADA system is critical to further reducing cyberattacks.

The new normal

According to McKinsey & Company’s report, Critical resilience: Adapting infrastructure to repel cyber threats,cyberattacks should be thought of as a certainty akin to the forces of nature. Just as engineers must consider the heaviest rains that a dam may need to contain in the next century… those digitizing infrastructure must plan for the worst in considering how an attacker might abuse or exploit systems that enable infrastructure monitoring and control. This shift in thinking will begin to lay the path to connected infrastructure that is resilient by design.

Cody Bann is director of engineer at Austin-based WIN-911 and may be reached at [email protected]. The company helps protect more than 18,000 facilities in 80 countries by delivering critical machine alarms via smartphone or tablet app, voice (VoIP and analog), text, email, and in-plant announcer, reducing operator response times, system downtime, and maintenance costs. For more information, visit www.win911.com/.

Tags: homepage-featured-2 homepage-featured-3 homepage-featured-4 Public Works & Utilities Smart Cities & Technology Public Works & Utilities Smart Cities & Technology Article

Most Recent


  • Report: Reforming emergency dispatch won't be easy, but it's necessary
    Over the last several years, reforming law enforcement has been a primary topic of discussion in communities across the nation. Discourse has mostly centered around the challenges agencies face in addressing the complex needs of those in mental health crisis, and the disparity of experience among community members depending on their race. But in this […]
  • 10 cities ideal for hybrid or full-time telecommuters seeking an outdoor lifestyle
    When the pandemic was first realized, cities emptied out, highways were suddenly devoid of cars and storefronts shuttered overnight. The assumption in many communities was that it would last for a few months and then everything would return to normal—those who’d left would return to their office jobs and apartments.  But these two years later, […]
  • Amid an unprecedented increase in federal spending, cities and counties stand to benefit from partnerships
    The so-called “American dream” of upward mobility has more or less stagnated: Today, a little more than 40 percent of children raised at the bottom of the income ladder remain there as adults, according to Pew Charitable Trusts, and only half grow up to earn more than their parents. This data points to a concerning […]
  • Amid tech labor shortage, outsourcing digital services could provide relief
    The COVID-19 pandemic accelerated tech and digitization globally, forever changing the way local governments conduct daily business, along with the expectations of constituents. Over the last two years, smart city plans have increased in popularity; services like tax bill payments and licensing have mostly shifted into the digital realm; and town offices evolved into comprehensive […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Russian invasion of Ukraine highlights need for cybersecurity at local level
  • Prioritizing rapid restore leads to stronger ransomware attack recovery
  • Why water utilities must invest in cybersecurity
  • The four major tech lessons public sector CIOs learned during COVID-19

White papers


How to Assemble a Rockstar Website Redesign Steering Committee

7th June 2022

Hand Hygiene: Compliance Matters

23rd May 2022

What it Takes to Build a Winning Esports Program

23rd May 2022
view all

Events


PODCAST


Young Leaders Episode 4 – Cyril Jefferson – City Councilman, High Point, North Carolina

13th October 2020

Young Leaders Episode 3 – Shannon Hardin – City Council President, Columbus, Ohio

27th July 2020

Young Leaders Episode 2 – Christian Williams – Development Services Planner, Goodyear, Ariz.

1st July 2020
view all

Twitter


AmerCityCounty

We want to hear from you! Please take this brief survey and let us know how your organization is managing your budg… twitter.com/i/web/status/1…

30th June 2022
AmerCityCounty

Report: Reforming emergency dispatch won’t be easy, but it’s necessary dlvr.it/ST7kQ5

30th June 2022
AmerCityCounty

Three U.S. cities to adopt Bloomberg Philanthropies Mayors Challenge-winning project to combat climate change dlvr.it/ST4bjk

29th June 2022
AmerCityCounty

10 cities ideal for hybrid or full-time telecommuters seeking an outdoor lifestyle dlvr.it/ST4T5g

29th June 2022
AmerCityCounty

Take American City & County’s budgeting survey dlvr.it/ST0qQP

28th June 2022
AmerCityCounty

Six cities and counties will take stock of underutilized assets in Rethinking Revenue incubator dlvr.it/ST0ZVp

28th June 2022
AmerCityCounty

Seamless Cooperative Experience Saves Indiana City Exponentially in Time and Money dlvr.it/SSxp95

27th June 2022
AmerCityCounty

10 best large cities for fishing dlvr.it/SSxbSZ

27th June 2022

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X