supply-chaintrade-pressNewsThe Broadside1 min read

ONCD to launch water-sector cyber defense program with private partners

Neither the ONCD program nor the recently launched Water Watch Center requires what CISA has been urging utilities to do: remove exposed operational technology from the public internet.


TL;DR

The Office of the National Cyber Director is preparing a program that would enlist private cybersecurity firms to help states defend water and wastewater systems, a person familiar with the plans told Nextgov. The program could be announced next week and may begin in Texas as a pilot before expanding to other states. It arrives as roughly 12 states have reported suspicious cyber activity on water systems, and days after the National Rural Water Association and DEF CON Franklin launched the Water Watch Center, a separate assistance initiative for utilities serving fewer than 10,000 people.

The Office of the National Cyber Director is preparing to unveil a program that would enlist private-sector cybersecurity firms to help states defend water and wastewater infrastructure, a person with knowledge of the plans told Nextgov. The program could be announced next week and may launch in Texas as a pilot before expanding to other states that request services. It isn't clear how many companies, or which ones, would participate.

The initiative arrives as water utilities across roughly 12 states have reported suspicious cyber activity in recent weeks. More than 30 community water systems in Minnesota were targeted in late July, and some officials suspect Iran-linked actors are behind the intrusions, though attribution hasn't been confirmed. CISA and the FBI are assisting with incident response. CISA's guidance to utilities has been blunt: get operational technology off the public internet and set passwords on exposed controllers.

The ONCD program follows the Water Watch Center, launched at DEF CON on August 7 by the National Rural Water Association and DEF CON Franklin, a University of Chicago Harris School project. That initiative provides direct mitigation support to utilities serving fewer than 10,000 people, with an initial group of five cybersecurity firms delivering services.

Neither program requires what CISA has spent weeks urging: removing internet-exposed programmable logic controllers from public access. Acting CISA Director Nick Andersen said at Black Hat last week that the agency is still finding PLCs online with no password or default credentials. "We're not making ourselves hardened targets," he said.


Published ·Deep Fathom