CyberSecurity SEE

States Expand Cyber Support Beyond Their Own Networks

States Expand Cyber Support Beyond Their Own Networks

Local Control and Funding Gaps Complicate Critical Infrastructure Protection

A recent discussion on the growing complexities of cybersecurity protection for critical infrastructure highlights significant challenges faced by local governments and utilities. As states increasingly engage in the management of cybersecurity for locally operated essential services—such as water systems and hospitals—they find themselves grappling with overwhelming responsibilities that often exceed their capabilities to deliver meaningful assistance.

State Concerns on Cybersecurity

A report from the National Association of State Chief Information Officers (NASCIO) outlines the pressing issues states encounter in safeguarding critical infrastructure. The data reveals that an alarming 88% of state CIOs view cyberattacks on vital systems as a substantial concern. Despite this high level of awareness, only 73% of respondents report that their actions are integrated into a comprehensive state cybersecurity plan focused on critical infrastructure. Alarmingly, a mere 31% possess budgetary allocations directed toward supporting local governments and special districts, while 22% lack any designated funds for critical infrastructure protection.

Meredith Ward, the deputy executive director of NASCIO and a key contributor to the report, emphasizes the disparity in state capabilities. "If you’ve seen one state, you’ve seen one state," she remarked, referencing the varying degrees of authority states hold over local governments and the unique demands they face. Many local entities generally remain accountable for their own infrastructure unless dictated otherwise by laws or executive mandates. Consequently, this fragmented governance structure results in state programs relying heavily on voluntary collaboration, which is insufficient given the complexities of modern cyber threats. "The attackers don’t care about jurisdiction lines; they see everyone as a target," Ward stated.

Shared Services Initiatives

Amid these challenges, some states have begun to extend concrete support to local operational technology organizations that lack the resources for independent cybersecurity procurement. For instance, Utah has made significant strides, providing endpoint protection, patching services, security awareness training, and incident response support to nearly 80% of its local municipalities. Oregon has been proactive as well, leveraging federal grants to evaluate water districts with assistance from various partners, including the National Guard and higher-education institutions.

The report indicates that over half of state CIOs offer services such as vulnerability assessments, monitoring, and incident response to local bodies, indicating a growing recognition of the need for collaboration. However, Dawn Cappelli, director of the Operational Technology Cyber Emergency Response Team (OT-CERT) at Dragos, emphasizes that merely providing services is inadequate if those services are not effectively utilized. Local operators often face significant personnel challenges, resulting in a multi-faceted set of responsibilities that stretch their capacities. Cappelli shared an anecdote illustrating this struggle: "I’m the OT, I’m the IT person, I run the plant, and I mow the lawn on Wednesdays."

Technological Limitations

On the technological front, Cappelli mentions that many essential services lack the necessary hardware to implement even donated security solutions effectively. For example, a local utility may receive a free cybersecurity platform but may lack the $5,000 required to obtain the hardware needed for its operation. Other organizations might install monitoring technologies without the human resources to evaluate alerts or maintain logs that facilitate effective incident response.

The limitations of available technology were starkly illustrated by incidents such as the cyberattack on the Littleton Electric Light and Water Department in Massachusetts. Here, Chinese hackers infiltrated the utility’s IT network for almost a year before the FBI provided warning. The incident illuminated the critical role of network segmentation, which successfully prevented access to the organization’s operational technology.

Addressing State Assistance Effectively

Josh Corman, an executive in residence for public safety and resilience at the Institute for Security and Technology, notes that the efficacy of state assistance should not be evaluated merely by the number of cybersecurity tools deployed. Traditional cybersecurity products primarily focus on confidentiality rather than the availability of life-saving services. He argued, “Almost all cybersecurity was developed for the confidentiality of information, not the availability of life-saving services." He also pointed out that relying solely on grants for firewalls and managed services leaves persistent burdens on utilities, raising operational costs and introducing more vulnerabilities.

Utilities are described as "target-rich but cyber-poor," where the landscape demands that state assistance effectively supports their capability to maintain essential services rather than just adding another layer of complexity.

Risks from Vendors and Integrators

Moreover, local operational technology systems face additional risks due to systems integrators and vendors who often work across multiple utilities. A single integrator’s insecure configurations can inadvertently expose numerous entities to potential cyber threats. For instance, Cappelli recounted an incident where a utility opted not to accept Dragos’ offer of free aid, preferring reliance on a vendor that may have left it vulnerable.

Recognizing these risks, Cappelli advocates for better contract language that enforces security controls among vendors. States can work to establish meaningful procurement contracts that enhance local operators’ leverage. Federal support has played a pivotal role in financing many state-wide initiatives, with programs such as the State and Local Cybersecurity Grant Program helping to create avenues for state-level services and financial support.

Nevertheless, Ward emphasizes that federal grants cannot serve as a substitute for enduring state capabilities. "The federal government can’t do the work for states, just as states can’t do the work for local governments," she explained.

Conclusion

Moving forward, it is essential for states to build relationships with local agencies prior to crises, focusing on the implementation of operational technology-sophisticated systems, vendor accountability, and sustainable support models. With the increasing frequency and sophistication of cyberattacks, the time for talk has passed. Action is now imperative to secure local critical infrastructure. "We’ve been discussing these issues for years, and now we’re witnessing these attacks firsthand. We can no longer just talk; we need to act," Cappelli concluded.

Source link

Exit mobile version