The power was out in our area of Maui for over 48 hours due to Hurricane Lala. This is the second time this year that we’ve experienced a multi-day outage due to storms, and this is a typical year. We’ve had similar multi-day and even multi-week outages in our water infrastructure.

We’ve never had a minute of outage, that I’m aware of, on Maui due to a cyber incident.

How much resources, time, attention, and money, should a leader in Maui Electric / Hawaiian Electric divert from making the physical infrastructure stronger and more resilient to fund cyber security / cyber risk management?

Most readers of this article live in the OT cyber security world with minimal vision of the all cause outage and safety incident data, such as SAIDI in US electric or OSHA safety statistics in manufacturing. The small to medium sized utility’s C-suite and risk management team looks at the data and often finds the case for diverting budget to OT security lacking.

Regulation is one way to address this. Require security controls, and have an effective audit and penalty program, and the C-suite will address regulatory risk. However if you go this route don’t complain when the bare minimum to address regulatory risk is funded.

Another way is to focus resource requests on real incident and incident loss data. We have this data for ransomware affecting, typically indirectly, the operations that OT monitors and controls. A project should be easy to win funding for If you can show it will lower the impact of ransomware on IT on your ability to make and deliver your product or service.

We now have data showing that OT accessible by anyone from the Internet with default passwords is increasingly likely to bring your automation down in water systems. We went from it never happening, to a less than a handful of times each year, to 40+ utilities across at least 12 states in one campaign. The funding case to get water OT systems off the Internet and change default passwords is now easier to make.

I know. I know. We should be out in front of this. We know the vulnerabilities and scenarios that could bring OT down, or worse. Why wait until the bad things happen to do the right thing? Intellectually correct, worth pursuing, and yet counter to human nature.

The best description of this human nature is the mining regulation chapter in the Clarke & Eddy book on Cassandras. Time after time mIning safety regulations only got more strict after a tragic accident.

I don’t think this is how OT security should approach cybersecurity. We should try to be out front. It would have been great if we succeeded and gotten those water systems’ PLCs and other OT equipment off the Internet prior to July 2026. After all, we saw the first presentation of this problem at S4 in January 2012.

And … we should leverage the incident similar to the mining safety regulations. Here it is important to not overplay our hand, especially to the budget and manpower strapped small and medium sized utilities. We will fail if we say here are 20 or more security controls you need. And by the way you will need to hire a team of three OT security pro’s to implement and maintain these controls.

The approach that will work is to only make recommendations where every dollar and hour spent will result in significant and demonstrable risk reduction. In this recent water incident it’s straightforward to removing OT from the Internet.

It’s much harder to make the case for deploying and maintaining an advanced OT detection solution. Is it good practice? Cyber hygiene? Yes. Would this detection solution have stopped these latest attacks? No.

Use the data. Take the win. Show perspective.