Coverage and commentary of the US water utility cyber incidents continue to dominate OT security content, often with suggestions to address the problem (including mine). Most of the suggestions are logical. They aren’t “wrong”. And most have failed repeatedly over the past 10 years.
Recommendations that have been given over and over for the past ten years, often with implicit or explicit “I told you so”. And then initiatives to make it happen. We need to stand up this or that. Double down on this program.
I comment on a few posts; it would be a full time job to comment on them all. Why will the results from your repeated recommendation be different this time?
I believe we will mistakenly go down this same path again, perhaps with a bit more volume and emphasis. One of three things will happen.
1) There will be new voluntary programs and additional resources for existing voluntary programs. These programs will continue to have little or no impact. They don’t work for small and medium water utilities.
2) The cadence and number of successful attacks on water systems increases. We start seeing 100+ attacks a year, and this leads to regulation which raises the OT security floor. Small and medium sized water utilities will do the bare minimum to meet regulatory risks. Water rates will go up, and small water systems will be consolidated. It will be a bit harder for the attackers.
3) The impact of successful attacks on water increases. We see systems down for weeks or months. Dangerous water is delivered to customers. Expensive equipment is damaged. The utility’s risk management is dramatically altered, more stringent regulation is passed, and rates increase.
One final note in case you didn’t read my recommendations. Any path that requires utilities serving under 50,000 to get additional funding and manpower to implement will fail. It’s asking them to do too much on OT cyber from a risk management standpoint.