HomeMalware & ThreatsCyber Defense Alone Cannot Ensure the Continuity of Critical Services

Cyber Defense Alone Cannot Ensure the Continuity of Critical Services

Published on

spot_img

Critical Infrastructure Security

States Must Map Dependencies and Engineer Safeguards for Water and Hospitals

Cyber Defense Alone Cannot Ensure the Continuity of Critical Services
State CIOs must decide which water systems, hospitals, and other essential services need protection first. (Image: Shutterstock)

The responsibility of ensuring efficient operation within state governments falls on the shoulders of Chief Information Officers (CIOs), who manage the various technology platforms, networks, and digital services. In an evolving landscape marked by the growing threat of cyberattacks, state CIOs now find themselves tasked with extending their expertise beyond traditional government spheres. They must foster robust defenses across a more extensive network of locally operated water systems, hospitals, and other vital infrastructures, all of which are at risk of disruption from cyber intrusions. Such disruptions can significantly jeopardize public safety by interfering with essential services.

A survey conducted by the National Association of State Chief Information Officers (NASCIO) in 2026 reveals a pervasive concern among state CIOs regarding the threat posed by cyberattacks to critical infrastructure. Approximately 88% of respondents indicated that they regarded cyberattacks against essential services as a pressing concern. In light of this alarming trend, NASCIO has published a report recommending that states conduct thorough inventories of their critical systems while prioritizing resources where they are most needed to achieve maximum impact.

Meredith Ward, NASCIO’s deputy executive director and a key author of the report, emphasized the importance of identifying vulnerabilities within state operations. She suggested that states need to recognize which utilities and services are most critical so that any potential disruption can be dealt with effectively. Identifying these systems is merely the starting point, however; it is equally important for states to strategize on how essential services can sustain operations even in the face of a cyber defense failure.

Josh Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, stresses that while internet connectivity has undoubtedly improved efficiency for small utilities, it also introduces new vulnerabilities. The reliance on integrated digital functions can render vital operations dependent on systems that may fail during a cyber incident, effectively removing traditional manual fallback methods. “Almost all cybersecurity was developed for the confidentiality of information, not the availability of life-saving services,” Corman explains. This distinction underscores a critical need for a shift in focus from merely safeguarding information to ensuring the continued availability of essential services.

Design for Compromise

Critical infrastructure, such as water systems, is designed to endure the test of time, sometimes operating for decades, well past the expiration of both required software and workforce knowledge necessary to maintain it manually. This reality became glaringly evident during an exercise conducted by the Environmental Protection Agency (EPA) where water utilities were asked to function without internet capabilities. Corman notes that participation was strikingly low, as many utilities expressed doubt about their ability to conduct an offline test.

Utilities must comprehend which of their functions necessitate internet connectivity and identify the consequences should that connection fail. Implementing cyber-informed engineering practices is essential; these practices assume that an attacker may infiltrate a control system and thus advocate for mechanical, electrical, and procedural safeguards designed to mitigate the physical consequences of such breaches.

As Corman aptly puts it, “The threats may originate from cybersecurity, but the solutions lie within engineering.” His initiative, called UnDisruptable27, aims to apply this philosophy specifically to water systems and hospitals. In this context, the loss of water pressure can critically disrupt sanitation, sterilization, and patient care.

This initiative advocates for collaboration among water operators, hospital officials, and emergency managers to pinpoint facilities where downtime would pose the gravest threats to public health. For instance, a small water system could escalate to a high priority status if it serves a trauma center or a dialysis clinic, facilities that cannot endure extended outages. Engineers then undertake a reverse engineering approach to identify physical safeguards that can prevent disastrous outcomes. Using techniques such as pressure-reduction valves or time-delay relays could help manage potential damage.

Corman notes that the cost of physical safeguards often exceeds around $10,000, though the required interventions can vary by system. While these engineering measures can curtail the physical consequences of a cyberattack, they do not replace the requisite visibility and access controls necessary to prevent adversaries from infiltrating critical infrastructure.

According to Dawn Cappelli, director of OT-CERT at Dragos, many smaller utilities may not recognize a cyber compromise until it leads to significant failures in physical processes. “They have no idea until pumps and tanks are overflowing, and the system starts malfunctioning,” she observed. This underlines the essential role of state support; quite often, local operators may lack the expertise required to implement monitoring technology or decipher alerts effectively. Strategies such as segmentation and secure remote access can significantly decrease the likelihood of an intrusion compromising critical equipment while engineering controls can help mitigate the physical fallout if such breaches do occur.

Prioritize the Highest-Consequence Risks

NASCIO reports that 73% of states incorporate critical infrastructure into their broader cybersecurity frameworks. However, only 31% of state CIO budgets allocate specific resources for safeguarding local governments and specialized districts, while 22% of states have no dedicated funding for critical infrastructure at all. This discrepancy highlights the urgent need for states to prioritize essential services adequately.

For each critical entity, it is vital for states to document supported essential services, maximum tolerable downtime, risks posed by single points of failure, and the feasibility of manual operations or alternative systems. Given that the vulnerabilities states face far exceed the financial and temporal resources available for remediation, rigorous prioritization becomes imperative. Corman stresses the importance of focusing resources on water systems that serve the most vulnerable facilities, such as trauma centers and nursing homes, which cannot sustain prolonged outages.

Ultimately, tabletop exercises should be conducted to assess how concurrent disruptions could strain available resources and equipment. The goal is to evaluate and potentially dismantle existing assumptions embedded within response plans. “Let’s not fix every water facility; let’s fix the water supply for the hospitals,” concludes Corman, outlining a strategic approach to safeguard essential services.

Source link

Latest articles

Salt Security Enhances CrowdStrike Integration to Address AI Agent Security

Salt Security Enhances Partnership with CrowdStrike to Improve AI Agent Security In a significant advancement...

CISA Enhances Vulnerability Reporting Platform

CISA Launches VINCE-NT: A New Era in Vulnerability Coordination On September 17, 2025, the U.S....

Anthropic AI Takes Center Stage in Developing Future Models

Internal Study Reveals AI's Dominance in Research and Development In a recent internal study conducted...

Feral Wolf Hackers Exploit Confluence and 1C for GenieLocker Ransomware Deployment

Feral Wolf Expands Ransomware Tactics via Atlassian Confluence and 1C:Enterprise Exploits In a significant escalation...

More like this

Salt Security Enhances CrowdStrike Integration to Address AI Agent Security

Salt Security Enhances Partnership with CrowdStrike to Improve AI Agent Security In a significant advancement...

CISA Enhances Vulnerability Reporting Platform

CISA Launches VINCE-NT: A New Era in Vulnerability Coordination On September 17, 2025, the U.S....

Anthropic AI Takes Center Stage in Developing Future Models

Internal Study Reveals AI's Dominance in Research and Development In a recent internal study conducted...