Is Your Water System’s Control Equipment Safe from the Open Internet?

Recent attacks on U.S. water systems succeeded because control equipment set up at remote sites could be reached directly from the open Internet. These are four questions you should consider sending to your integrator or IT department today.

Integrator-IT questions

Four questions you should ask your IT Provider and Integrator today

1. Can our PLCs or control equipment be reached directly from the public Internet?

If they answer yes, ask them why that is needed.  Be aware that exposing controllers and SCADA equipment to the Public Internet with a Public IP shouldn’t be required in 99.99% of all cases and puts your facility at a significant risk.  Note: "yes, but it's password protected" is not enough anymore.  Ask what it would take to put that equipment behind a firewall and VPN or how you can keep and do it. 

2. Can you give me a diagram that shows all our sites and lists any sites that have “open ports” to the Internet?

You already have a network diagram of your SCADA environment, right?  You should.  If one of your IT or Integrator tells you that there are no sites with ports open to the Internet, ask the other one to verify the claim (shouldn’t take more than an hour).   If your integrator or IT provider asks you what you mean by open ports, find a new Integrator or IT provider.  Seriously.  If there are sites with open ports, call a meeting with your IT provider and your Integrator this week to verify the need given the grave risk of open ports.

3. Do we have Multi-Factor Authentication for all remote access (including vendors)?

ALL remote access or control should require a multi-factor login and a unique password for every employee and vendor.  No exceptions.  There should never be shared or default credentials used in any water system.  If you do not have multi-factor authentication set up for remote access, ask your Integrator or IT provider for a proposal to get it done and do it.

4. What should I do if I suspect someone has hacked us?

Your integrator should work with you to develop a short, easy-to-understand help document to know what to do if you have a problem.  You should have a support agreement with them that allows you to call them 24x7x365.  If they don’t do 24x7 support, get a new integrator.  That said, there is no one-size-fits-all answer to this, as many connected controllers might also be involved in your system’s control.

About Waterly

Waterly and our partners are designed to support secure remote connectivity without ever putting a facility’s control system directly on the public internet. Our approach with our partners uses secured, controlled, and audited connections that send information out from the facility rather than leaving equipment openly accessible from the outside.  We also support common best practices such as network separation, single sign-on, unique logins, limited access, and system monitoring to help utilities reduce cybersecurity risk while still getting the benefits of remote data access.

For a more in-depth technical treatment of the issue see this write-up by our CTO Jason Vasquez.‍ ‍

Previous
Previous

A Technical Response from our CTO on the Recent Cybersecurity Attacks on Water Systems

Next
Next

SCADA Data and Water/Wastewater Compliance – Risks and Rewards