Cyber Resilience in Water: Threats, Risks, and Solutions by Gabriel Agboruche

THE SUMMARYAI-generated

Key Concepts

  • Cyber Resilience: The ability of a water sector organization to anticipate, withstand, recover from, and adapt to cyber incidents.
  • OT (Operational Technology): Hardware and software that directly monitors and/or controls physical devices, processes, and events in industrial operations.
  • SCADA (Supervisory Control and Data Acquisition): A type of OT system used to control and monitor industrial processes.
  • PLC (Programmable Logic Controller): A specialized computer used to automate industrial processes.
  • HMI (Human Machine Interface): A user interface that allows operators to monitor and control industrial processes.
  • Cyber Kill Chain: A framework that outlines the stages of a cyber attack, from reconnaissance to actions on objectives.
  • C2 (Command and Control): Infrastructure used by attackers to maintain control over compromised systems.
  • Threat Actor: An individual or group that attempts to cause harm through cyber attacks.
  • Ransomware: A type of malware that encrypts data and demands a ransom for its release.
  • AI-Assisted Threat Actor: An attacker who uses artificial intelligence to enhance their capabilities.
  • Showdan: A search engine for internet-connected devices.
  • VNC (Virtual Network Computing): A protocol that allows remote access to graphical desktops.
  • Perdue Model: A reference model for industrial control systems network architecture.
  • IEC 62443: A series of standards for industrial control systems security.
  • Incident Response Plan: A documented set of procedures for responding to cyber incidents.
  • Recovery Plan: A documented set of procedures for restoring systems and data after a cyber incident.

Anatomy of a Water Cyber Attack

  • Reconnaissance: Adversaries identify vulnerable water treatment facilities with internet-exposed PLCs and HMIs.
  • Weaponization: Exploits are developed to compromise PLCs, often leveraging default passwords and insecure remote access (e.g., lacking multi-factor authentication). Post-exploitation frameworks like Metasploit may be used.
  • Delivery and Exploitation: Exploits are automated to find more internet-connected devices. Payloads are delivered via protocols like Telnet and SSH. Original ladder logic files are erased, and HMIs are defaced, disrupting operations.
  • Command and Control (C2): Adversaries establish C2 infrastructure to maintain control over compromised devices and send further commands.
  • Actions on Objectives: Water pressure and flow controls are modified, potentially causing equipment damage and disruptions to the water treatment plant.

Example: The Cyber Avengers (Islamic Revolutionary Guard Corps) conducted four waves of cyber attacks, compromising at least 75 internet-connected devices, including 34 in the US water and wastewater sector (SIZA, December 18, 2024).

Cyber Threats in the Water Sector

  • Geopolitical Cyber Battlefield: Private organizations, including water facilities, are increasingly targeted in nation-state-sponsored cyber attacks. The goal is to disrupt industrial processes and compromise safety.
  • Ransomware: Attacks originating in IT environments are pivoting into OT, where clear text protocols and lack of encryption make systems vulnerable. Encryption of shares and communication protocols disrupts operations.
  • AI-Assisted Threat Actors: Adversaries use AI to rapidly learn about OT systems and vulnerabilities, enabling them to cause more disruptions.

Example of AI-Assisted Attack:

  1. Reconnaissance: Using Showdan to find internet-connected HMIs using the VNC protocol.
  2. Information Gathering: Inputting a screenshot of an unknown HMI into chat GPT to identify the system (e.g., industrial chilling system) and its components (e.g., chilling power, glycol inlet/outlet temperatures).
  3. Exploitation Research: Asking chat GPT for more details about the vendor and product version.
  4. Potential Attack Vectors: Chat GPT suggests methods to send commands to the HMI, including physical access, remote access via SCADA or VNC, and communication protocols like Modbus, Profinet, or Ethernet/IP. It even generates a Python script for interacting with the HMI or PLC.

Defending Water Systems

  • Reduce Exposure to Publicly Facing Environments:
    • Assess network connectivity to identify all connections and potential entry points.
    • Evaluate perimeter defenses, recognizing that a single firewall is insufficient.
    • Minimize exposure points while maintaining operational efficiency.
  • Conduct Regular Cyber Security Assessments:
    • Engage third parties to perform penetration testing, vulnerability assessments, and threat hunting.
    • Address security gaps before adversaries can exploit them.
    • Recognize that OT environments require tailored assessments due to their unique characteristics.
  • Develop and Exercise Incident Response and Recovery Plans:
    • Include OT systems (water systems, pump systems, PLCs, SCADA servers) in incident response plans.
    • Exercise the plan through tabletop exercises to prove its effectiveness.
    • Develop recovery plans to restore systems and data after an incident.
    • Example recovery action: Manually operate systems while replacement devices are procured and configured.

Conclusion

Cyber resilience in the water sector is critical due to the increasing sophistication of cyber threats and the sector's importance to public health and safety. Organizations must prioritize reducing exposure to the internet, conducting regular security assessments, and developing comprehensive incident response and recovery plans. Public-private partnerships and information sharing are essential for enhancing cyber security resilience across the water sector.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.