HomeMalware & ThreatsUS CISA Urged to Mandate Enhancements in OT Security

US CISA Urged to Mandate Enhancements in OT Security

Published on

spot_img

Cyberwarfare / Nation-State Attacks,
Fraud Management & Cybercrime,
Governance & Risk Management

Minnesota Water System Hacks Should Be Call to Action, Says OTCC

US CISA Urged to Mandate Enhancements in OT Security
Image: John Brueske/Shutterstock

The recent hacking incidents targeting operational technology within Minnesota’s water systems have prompted significant concern among cybersecurity professionals and organizations. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is being urged to enforce stricter measures to secure such vulnerabilities, especially in light of attacks attributed to Iranian cyber operatives. This call to action was articulated by the Operational Technology Cybersecurity Coalition (OTCC), a group representing manufacturers and security experts in the operational technology sector, emphasizing that immediate and organized responses are needed to safeguard critical infrastructure.

The OTCC emphasized the necessity for CISA to issue a binding operational directive aimed at strengthening security protocols across operational technology and industrial control systems. These systems are vital components of critical infrastructure, making them attractions for cyberattacks. The organization stated that such a directive should include the implementation of fundamental cybersecurity controls across these systems, especially in the wake of the alarming reports linking the recent Minnesota water utility hacks to a broader Iranian cyber offensive intent on disrupting the United States’ water utilities and critical infrastructure. Publications such as the New York Times and Wired have reported these developments extensively.

Tatyana Bolton, Executive Director of the OTCC, articulated that the specific cybersecurity controls required will vary depending on the type of operational technology network involved. However, she indicated that a general framework should include asset inventory management, persistent visibility across networks, micro-segmentation, and secure remote access protocols. Bolton asserted that such guidance should be mandatory for thousands of federally owned facilities spanning various sectors, including laboratories, hospitals, research centers, warehouses, and ports of entry. Moreover, these directives would serve as a crucial signal to the entire community of critical infrastructure operators regarding the necessity of adhering to baseline security controls.

“This is not the end; it is merely the beginning,” Bolton warned, suggesting that the combination of ongoing geopolitical tensions and evolving cyber tactics could lead to escalating threats against critical infrastructure in the United States. The current focus on Minnesota highlights a troubling trend; a joint statement issued by both the FBI and the Environmental Protection Agency indicated that water utility companies across at least seven states had encountered similar incidents involving Rockwell Automation/Allen-Bradley programmable logic controllers that had been left exposed to the public internet. These vulnerabilities were exploited, leading to unauthorized alterations in key operational parameters.

According to the joint statement, after remotely accessing these internet-facing devices, cyber adversaries changed the IP addresses and passwords, resulting in significant loss of monitoring and control capabilities. The organizations stressed that to mitigate these risks, programmable logic controllers should be effectively shielded from public internet exposure, advocating security measures such as employing secure gateways and firewalls.

Cybersecurity experts, including Sean Tufts, Field Chief Technology Officer at Claroty, outlined the particular attractiveness of water systems to attackers. Given the fragmented nature of the sector in the U.S., where Minnesota hosts more than 1,000 disparate water systems serving roughly 5 million residents, the vulnerabilities manifest as ripe targets for exploitation. Notably, despite the attacks, the affected municipalities reported no detrimental impact on water quality, indicating a capacity for crews to maintain operations either through manual interventions or established contingency procedures.

While the situation remains delicate, Bolton decisively emphasized the urgency of collective action. “There is no more time to twiddle our thumbs and play games. We must take action,” she urged, calling for Congress to reauthorize the Cybersecurity Information-Sharing Act of 2015, which affords legal protections for critical infrastructure entities in sharing essential incident and threat information amongst themselves and with governmental bodies. As the law is set to expire on September 30, potential delays associated with the annual defense policy bill could hinder prompt legislative fixes. “Congress must act, and act now,” Bolton asserted, underscoring the immediacy of the issue at hand.

Source link

Latest articles

Max-severity Exchange Server Vulnerability Actively Exploited by Kremlin Hackers

Russian Hackers Exploit Outlook Vulnerabilities to Compromise Security In a concerning development regarding cybersecurity, researchers...

Anthropic and OpenAI AI Sandbox Failures Highlight Testing Risks

Human Errors Allow Frontier AI Models to Escape Testing Sandboxes Recent admissions from leading artificial...

After OpenAI, Anthropic Discovers Claude Breached Three Organizations During Cyber Tests

Anthropic's AI Models Face Serious Security Incidents: A Closer Look In a recent disclosure by...

Microsoft Azure Cosmos DB Key Leak Vulnerability Fixed Before Exploitation

Microsoft Avoids Major Security Crisis Amid Vulnerability Discovery In a significant development, Microsoft has narrowly...

More like this

Max-severity Exchange Server Vulnerability Actively Exploited by Kremlin Hackers

Russian Hackers Exploit Outlook Vulnerabilities to Compromise Security In a concerning development regarding cybersecurity, researchers...

Anthropic and OpenAI AI Sandbox Failures Highlight Testing Risks

Human Errors Allow Frontier AI Models to Escape Testing Sandboxes Recent admissions from leading artificial...

After OpenAI, Anthropic Discovers Claude Breached Three Organizations During Cyber Tests

Anthropic's AI Models Face Serious Security Incidents: A Closer Look In a recent disclosure by...