Almost everyone can lose weight and keep it off through a consistent routine of diet and exercise. And some do, but most don’t. Only 12% of obese participants in the Landmark STEP-1 Clinical Trial lost and kept off 10% of their bodyweight with a placebo drug and lifestyle/diet/exercise.

GLP-1 drugs changed this. In this STEP-1 Trial 69.1% with GLP-1 and the same lifestyle/diet/exercise guidance lost and kept off 10% of their bodyweight.

(Data source: Landmark STEP-1 Clinical Trial, 68-week duration; Wilding et al., 2021, New England Journal of Medicine)

Most recommendations and projects to address US water sector OT security since the July incidents have been the equivalent of lose weight through diet and exercise. It’s not bad advice. It’s just unlikely to work. Particularly with small to medium water utilities that fit the definition of cyber poor.

First there is the effort and resources required to develop a mature OT security program. What’s required to lose the weight. And then the harder job to keep the weight off, the OT security maintenance. Those who have audited OT security programs know how rare they find maintenance that matches policy. It’s most commonly seen in regulated environments where rigorous audits are the norm.

It’s not hard to predict that small to medium water utilities will be unable to deploy and maintain a mature OT security program.

What is the GLP-1 for this problem? For small to medium water it is deploying and maintaining a system where complete compromise of the OT network does not result in a high consequence event.

The good news is this is not hard or expensive for them to deploy and maintain. In fact, much of small to medium water is already there. I’m sure there are some water utilities who believe they are in this state and are not.

The recommendations (or regulations), resources, and projects should be identifying any way a compromise of OT in small / medium water could put public safety at risk, cause a long term outage, or result in system damage that is unacceptably costly to repair or replace.

And if any scenarios are identified, add or change something so that the high consequence event would not be possible even if the OT network was completely compromised.

Let’s pretend Oldsmar actually occurred as originally reported. In that case ensure the Day Tank that stored the lye was of a size where the entire tank could be added to the water supply without endangering human safety. It likely was this smaller size and filled daily from the bulk storage tank to prevent an overfeed issue, unrelated to a cyber attack, from causing a safety incident.

It’s going to be a lot easier and less costly to make sure the lye supply remains connected to the day tank rather than the bulk tank than it would be to deploy a mature OT security program.

It’s not too late for the OT security community to push for this consequence reduction based approach. It has been discussed in CCE and CIE, but in those methodologies it’s consequence reduction and a mature OT security program. We should save the effort, expense, and delusion that the cyber poor will be able to deploy and maintain a mature OT security program.