ics-ottrade-pressNewsThe Broadside1 min read

Nobody tracked the cellular modems on water controllers

The devices showed up on carrier invoices but never in an IT asset inventory. Matching the two costs nothing and can start Monday.


TL;DR

In July, intruders compromised water and wastewater controllers across multiple states through an exposure no asset inventory caught: the devices were connected to public cellular networks, not the city LAN. The modems appeared on carrier invoices but nowhere on network scans. The former CIO of Waco, Texas, writing from direct experience, argues the core problem isn't technical. No single person owns accountability for the whole municipal network. Matching carrier invoices to actual devices costs nothing in tools or headcount and can start this fiscal year with money already in a budget request.

Nobody tracked the cellular modems on water controllers
Editorial illustration · drawn by The Broadside

The July water-sector intrusions produced the usual federal response: an advisory, expanded indicators of compromise, and a recommendation to segment OT networks from IT. That's the right advice for the wrong problem. The controllers compromised in late July weren't sitting on the city LAN behind a firewall. They were connected directly to public cellular networks through modems installed years ago, sometimes by a vendor, sometimes by a contractor, and tracked by exactly nobody.

The former CIO of Waco, Texas traced his own water-plant network and found the controller, the branch library, and the golf-course register all terminating in the same cabinet. The cellular modems appeared nowhere in IT's asset inventory and nowhere on network scans. But every carrier invoice lists every SIM the city pays for. Only accounts payable tracks them.

Matching carrier invoices to actual devices costs nothing and can start this fiscal year with money already in a budget request. What it requires is a single person who owns the question. In most cities, that person doesn't exist.

The plant answers to public works. Cameras and card readers arrived with a building project and get treated like light fixtures. The IT department runs the LAN. Each silo has its own budget, its own vendors, and its own boss. Nobody owns accountability for the network they all share.

State reporting rules compound the blindness. Texas requires incident reporting within 48 hours, but only for personal-information breaches or ransomware. An intrusion that seizes control of a water-treatment controller while touching neither sits outside the trigger. That's exactly what happened in July. The FBI and EPA now recommend isolated architectures and private access point names for OT equipment. Good guidance, but the first step is simpler: someone has to know the devices exist.


Published ·Deep Fathom