Discussion about this post

User's avatar
Tracy Sanders's avatar

Is there any way to move the needle on this issue other than for Federal regulatory enforcement? In my experience, FERC audits do drive some accountability, but the road to get there is frequently carved through intentional complexity and obfuscation that did not improve the security posture of the utility, but created enough complexity that the RF auditor does not understand what is going on.

For example, instead of having point to point secure encrypted tunnels with segmentation/isolation and tight ACLs with IDS/IPS/logging/layer7 inspection, corporate IT at a utility will route traffic back through a zone Z configuration so that it takes 6 people on the same web meeting to troubleshoot anything. This lack of intentional visibility makes items nearly impossible to audit. It causes RF auditors to fail to spot the security failure.

Excess complexity that results in a lack of ability to audit is a very serious vulnerability.

I would rather see an approach that couples or partners water utilities with certified information technology security experts such as network security architects that have decades of experience in the OT space. These people exist. But the municipalities are not looking for them. All it would take is one person per utility to function as the consultative network security architect. That person could audit, formulate an engineering plan, project manage and execute migrations and corrective actions, and produce the legal attestation documentation required.

My estimate is this would cost $36,000 per year for a continuous improvement approach that introduces change at a pace that matches not only what the utility can absorb in terms of budget for labor but also the pace of change that the environment can handle politically.

The approach would need to be assess, strategic plan, engineering plan, budget, procurement, remediation. All the while, improving operational maturity. Where asset inventory is lacking, rectify that. Where a GRC is missing, implement it. There are open source GRCs and open source asset inventory platforms. There are no excuses. They can be self-hosted in an isolated supply-chain risk managed approach.

It's all about the political will to solve the problem. The local municipalities need to get the political will to correct the issues. Municipal leaders are probably asking "are we good? are we fine?" The correct line of questioning should be show me the non-tamperable legal attestation of configurations that prove continuous configuration and state of the environment coupled with has that information been audited by someone qualified to do that work?

No posts

Ready for more?