Security Breach: Water Treatment Hacks Reflect Larger OT Threats

The basic, yet essential building blocks, for securing critical assets.

Although the need to defend the networks, data and endpoints of critical infrastructure dates back to the first time a PLC was connected to an HMI, the realization of how damaging such a compromise could be was probably Stuxnet.

And while we’ve progressed enough to typically spot an unknown or malicious player armed with a suspicious USB, the threat landscape has expanded, and the bad actors have evolved.

Combining those factors with a lack of funds, training, expertise and resources has opened the doors to ransomware groups and state-sponsored hackers to infiltrate, shutdown or compromise infrastructure operations across the globe, and more recently, across the United States.

These growing threats were recently on display when over 100 water treatment facilities across 12 states experienced temporary shutdowns due to breeches believed to have been carried out by Iranian hacking groups. Here to discuss the rise in these attacks, and what they mean in the broader scope of industrial cybersecurity is Jen Sovada, General Manager for Public Sector initiatives at Claroty.

Watch/listen as we discuss:

  • The blocking and tackling of OT security that has become vital in defending critical assets on any plant floor.
  • How Watershed 250 is working to help utilities protect their OT infrastructure.
  • How the ongoing IT/OT divide is hurting new cybersecurity initiatives.
  • The proper implementation of strategies like microsegmentation, artificial intelligence tools.
  • How, despite all the challenges facing industrial cybersecurity, she can still sleep at night.

To catch up on past episodes, you can go to Manufacturing.net, IEN.com  or  MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at [email protected].

More in Cybersecurity