Water utilities may not immediately be top-of-mind when one thinks about cyberattack targets; typically, that designation goes to finance, healthcare, and other critical infrastructure sectors, such as nuclear power. Despite their seemingly benign role, they are an ideal target for hackers. Water utilities are also a target because so many critical third parties (emergency services, hospitals and healthcare facilities, firefighting services) rely on water to sustain their operations.
One of the simplest, and most impactful steps water utilities companies can take to protect their users and teams, is to deploy an enterprise-grade password manager. Password managers, such as Bitwarden, help strengthen water utility digital infrastructures by enhancing password security and enabling additional access controls, while empowering each individual user with the tools to simplify their workflow, while also making it more secure.
Water utilities as an attack vector
To start, water utilities provide a good - water - that is consumed by a large number of people within a small radius. Depending on the breadth, scope, and nature of the cyberattack, a compromised water supply could range from disruptive (temporarily shutting down the supply) to deadly (poisoning water with chemicals). Hackers, some operating from thousands of miles away, can easily cause an outsized impact to an area’s population. One example of a near-disastrous water utility attack occurred in 2021, when
Recent survey data and real-world incidents reveal how vulnerable water utilities are to cyberattacks. In late 2023, the Municipal Water Authority of Aliquippa, which serves a portion of Western Pennsylvania, was targeted by Iranian hackers. According to a
The U.S. has
Uncovering cybersecurity gaps at water utilities
Building up water utility resilience used to be primarily focused around environmental or sustainability-oriented objectives, such as mitigating risks from climate change. However,
“Both the ability to ‘supply water’ and ‘manage wastewater’ are considered National Critical Functions – functions of government and the private sector so vital to the U.S. that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.”
Unfortunately, the challenges don’t stop there. As mentioned above, most water utilities are municipality-run and do not have dedicated IT security teams devoted to security or staying up-to-date on the latest threats. Another large area of concern is that water utilities often rely on outdated, legacy IT equipment that is challenging to upgrade or make compatible with more current, cloud-based technology.
Other
A survey conducted by the
32% of respondents don’t conduct cybersecurity risk assessments or know if they conduct cybersecurity risk assessments
38% allocate less than 1% of their budgets to information technology (IT) cybersecurity, while 45% allocate less than 1% to operational technology (OT) security
64% of respondents said that their utility does not employ a Chief Information Security Officer (CISO) or equivalent
42% of respondents do not have a cybersecurity awareness program
Only 22% of respondents have implemented cyber protection efforts that are monitored regularly
YOU MIGHT ALSO LIKE:
Why Employees are the Front Line of Enterprise Threat Prevention
Implementing solutions to help protect against cybersecurity threats
A
Reduce exposure to the public-facing internet
Conduct regular cybersecurity assessments
Change default passwords immediately
Conduct an inventory of operational technology/informational technology assets
Develop and exercise cybersecurity incident response and recovery plans
Backup OT/IT Systems
Water utilities can implement some of the recommendations presented above immediately. Going back to the key recommendation cited earlier, water utilities should also go beyond changing default passwords and implement an enterprise-grade password manager that will deliver better password security, provide additional access controls, help train employees in cybersecurity practices, and support cybersecurity incident response strategies.
Why Bitwarden is the trusted cybersecurity solution for water utilities
In December 2023, U.S. water utilities connected to the open internet with the
Implementing an enterprise-grade
Strengthening authentication with single-sign-on (SSO) and directory integration options.
Enforcing strong password policies such as minimum password length and two-factor authentication, offering an additional bulwark against data breaches.
Protecting against credential attacks by eliminating the need for weak or reused passwords and ensuring employees can share credentials securely.
Enabling role-based access controls that allow administrators to customize permissions, control who has access to certain functions, and issue granular permissions (e.g. Hide Passwords, Read-Only). By limiting user access based on necessity, utilities maintain control over sensitive systems. Monitoring
log eventsprovides additional protection.Centralizing business information in an end-to-end encrypted vault that protects not just passwords, but company cards and other personally identifiable information (PII). Cyber-criminals seeking to disrupt water supply may also come across other sensitive information that could be stolen and used to compromise other accounts. Encryption makes this virtually impossible.
Improving Cybersecurity Culture: Building employee awareness around password security best practices creates a more advanced security culture and encourages employees to be more thoughtful about their password management practices.
The digital infrastructures of water utilities present a unique security challenge because they control, manage, and protect the only utility that people can ingest. This lends urgency to the need for more stringent security controls. Fortunately, water utilities can take a big step in the right direction by implementing an enterprise-wide password manager that will immediately secure critical data. In doing so, they are also further protecting society’s health and well-being.
Get started with Bitwarden
To explore Bitwarden business features and capabilities, get started with a