451
CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet
(www.privacyguides.org)
This is a most excellent place for technology news and articles.
Went on the public tour of our local waste-treatment facility. Really fascinating stuff. Highly recommend it if you're even slightly curious.
There are definitely industrial-scale automation systems. Mostly PLCs, but also SCADA for monitoring. Lots of 20-30 year-old tech. Those networks have no reason to be connected to the internet.
But there were also office equipment and personal devices everywhere. All it takes is for someone wanting to monitor the state of a digester on their laptop from home.
You just crossed the beams.
You're talking a massive nation with more systems like this than you could ever imagine. Probably more than all of Europe combined.
They are in every state of repair and disrepair that you could imagine, and many have been receiving government funding for at least at decade now (def more, but I can only speak to the last ten years or so) to replace these systems, including SCADA and PLCs.
So you have a patchwork of countless systems, in every level of tech modernity that you can imagine.
The newer systems usually have an internal network of sorts, and they might have a portal for someone outside the network to log in to remotely monitor.
The problem seems to be that these idiots kept the default credentials, etc.
But to answer you're question, they're not all 20-30 years old, and network connectivity (without being open to the outside internet, obviously), is a very useful feature when replacing those old systems with newer ones.
That's why.
Automation engineer here who does a lot of SCADA
There are soooo many good ways to securely monitor stuff from home. But especially in critical infrastructure it's just usually air gapped which is unbeatable in cyber security.
Tours of any local facility are super cool! I find it all so interesting, seeing how the things we use work!
I worked on new SCADA for a water company across all theirs sites. Previously they were a mismatch of different systems and all airgapped.
They standardised everything and put them all on VPN. Suddenly you could access the secure water treatment works with 24/7 security guards and the control room was a bunker, from the unmanned rural sewage works with a portacabin for the server, the key hidden under a brick, and wifi for the PLCs.
The sewage works had always operated like that because it was deemed low risk. No one considered the VPN changed the threat model.