The breach of a Florida water treatment system that could have poisoned citizens sent shockwaves through local government. No-cost assessment tools and low-cost fixes can increase security in this sector.
On Monday, February 8, a press conference hosted by Pinellas County, Florida, sheriff Bob Gualtieri dropped an industrial cybersecurity bombshell that reverberated worldwide. Gualtieri, along with the mayor and city manager of Oldsmar (population 15,000), revealed that a hacker had infiltrated the Oldsmar water treatment system to change the city’s water supply levels of sodium hydroxide from 100 parts per million to 11,100 parts per million. Sodium hydroxide, also called lye, is a highly caustic chemical that is a key ingredient in liquid drain cleaners.
The hackers gained unauthorized access to an internal industrial control system (ICS), likely using stolen or lost credentials, via TeamViewer, a remote desktop application that allows users to log into systems from afar, a ubiquity across many organizations during the COVID-19 crisis. Gualtieri and the city officials offered only a few other details of the disturbing breach.
To embed, copy and paste the code into your website or blog:
In light of the major cybersecurity breach of the SolarWinds Orion software by malicious actors, the Water Information Sharing and Analysis Center (WaterISAC) recently issued a series of advisories providing guidance for water providers across the country on how to respond and react to this unprecedented cyberattack.
As highlighted in the WaterISAC advisory issued on December 16, 2020, the Environmental Protection Agency has recommended that all water and wastewater utilities review the Cybersecurity and Infrastructure Security Agency s (CISA s) Emergency Directive 21-01 for mitigation procedures. While Emergency Directive 21-01 is specifically directed at federal agencies, it provides helpful steps that water providers can take to mitigate the potential impacts of this widespread attack that has impacted major international institutions.