Water and Sewer Utilities Strengthen Cybersecurity Defenses Against Hackers

0
35

Key Takeaways

  • Albany’s water and sewer departments received a combined $193,330 in New York State grant funding to bolster cybersecurity defenses.
  • The money will be used to strengthen firewalls, virtual private networks (VPNs), employee training, and to secure operational technology such as programmable logic controllers (PLCs).
  • Albany relies on three separate computer networks: business transactions (e.g., online bill pay), security systems (cameras, access control), and the operational network that controls pumps, valves, chemical feeds, and sewage flow.
  • PLCs—often Allen‑Bradley models—are the “brain” of water‑treatment equipment; compromising them could allow attackers to manipulate flow, pressure, chemical dosing, or cause sewage backups.
  • The grant program stems from new statewide cybersecurity standards that took effect in March, requiring regular training, breach reporting, and basic hygiene practices like changing default passwords and isolating devices from the open internet.
  • Federal agencies (CISA and the FBI) have warned that Iranian‑linked threat actors have targeted exposed PLCs, altering passwords, locking out operators, and changing IP addresses to disrupt water services.
  • Albany mitigates risk by keeping its Allen‑Bradley PLCs off public networks, employing multiple layers of consultant support, and applying regular updates and patches.
  • Similar funding has been awarded to over 150 municipal water facilities across New York, including communities in the Capital Region such as East Greenbush, Guilderland, Hudson, and Rensselaer.
  • Officials stress that sophisticated tools are not always necessary; fundamental security practices—strong passwords, VPNs, network segmentation, and staff awareness—provide the bulk of protection.
  • Historical incidents (e.g., a 2013 Iranian‑backed hack of a Westchester County dam) and the growing use of artificial intelligence to accelerate attacks underscore the evolving threat landscape.
  • A key resilience strategy highlighted by state cyber officials is the ability to switch to manual operations when automated systems are compromised, ensuring continuity of service even during a cyber incident.
  • Ongoing vigilance, regular updates, and adherence to the new state standards are essential for safeguarding New York’s water and sewer infrastructure against increasingly sophisticated cyber threats.

Overview of Albany’s Grant Funding
The city of Albany’s water and sewer departments have been awarded $120,160 for its drinking‑water system and $73,170 for its sewer system, totaling $193,330 in state grant money. This funding is part of a broader $9 million initiative launched by Governor Kathy Hochul’s office to improve cybersecurity defenses at municipal water facilities across New York. The grants aim to harden operations against the rising tide of cyberattacks that have targeted water utilities in multiple states, some with suspected ties to Iranian threat actors. Albany plans to allocate the resources toward upgrading firewalls, deploying virtual private networks (VPNs), conducting staff training, and securing the specialized equipment that controls water treatment and sewage flow.

Breakdown of Grant Allocation and Intended Uses
Of the total award, the drinking‑water portion will focus on protecting the SCADA (Supervisory Control and Data Acquisition) network that monitors reservoir levels, pump stations, and chemical dosing. The sewer‑system grant will similarly safeguard the network that manages lift stations, flow meters, and overflow controls. A significant share of the funds will be directed toward cybersecurity training for operators and IT staff, ensuring they can recognize phishing attempts, apply patches, and respond to incidents. Additionally, the city will invest in network segmentation tools that isolate operational technology from business‑facing systems, reducing the attack surface available to intruders.

Albany’s Three Separate Computer Networks
Albany operates three distinct computer systems within its water and sewer departments. The first handles business functions such as online bill payment, customer account management, and internal communications. The second supports physical security, including video surveillance, building access controls, and alarm systems. The third—and most critical from a safety standpoint—governs operational technology: pumps that move water, valves that regulate flow, chemical feed systems that add chlorine or other treatments, and the sewage conveyance network. By keeping these networks separate, the city hopes to limit lateral movement should an attacker breach one segment.

The Role of Programmable Logic Controllers (PLCs)
At the core of the operational network are programmable logic controllers (PLCs), ruggedized computers that execute logic commands to start/stop pumps, open/close valves, and adjust chemical dosing rates. PLCs receive sensor data, execute pre‑programmed routines, and relay status updates to human‑machine interfaces (HMIs). Because they directly manipulate physical processes, PLCs are prime targets for cyber adversaries seeking to disrupt water quality, cause overflows, or damage infrastructure. Compromising a PLC could allow an attacker to silently alter dosing levels, shut down pump stations, or redirect sewage into unintended pathways.

Potential Consequences of a PLC Breach
If threat actors gain control of Albany’s PLCs, the impacts could be immediate and hazardous. Pumps might be cycled on or off, leading to pressure surges or insufficient water distribution. Valves could be opened incorrectly, causing flooding in low‑lying areas or starving sections of the system of needed flow. Chemical feed rates could be manipulated, resulting in either under‑dosing (risking microbial contamination) or over‑dosing (creating toxic by‑products or corrosive conditions). In the sewer system, altered pump operation could cause backups, sending untreated wastewater into streets or nearby waterways. Such scenarios underscore why securing PLCs is a top priority for water utilities.

Statewide Grant Program and Participating Communities
Albany’s award is one of more than 150 grants distributed statewide under the governor’s cybersecurity initiative. Recipients span the Capital Region and beyond, including the towns of East Greenbush and Guilderland and the cities of Hudson and Rensselaer. The program reflects a recognition that small and mid‑sized municipalities often lack the dedicated cybersecurity staff and resources of larger utilities, making them attractive targets for attackers. By providing funds for training, hardware upgrades, and expert consulting, the state hopes to raise the baseline security posture across the entire water‑and‑sewer sector.

New Cybersecurity Standards and Compliance Requirements
The grant funding flows from cybersecurity standards enacted in 2023 that took effect in March 2024. These standards mandate that all covered utilities conduct annual cybersecurity awareness training, maintain an incident‑response plan, and report any confirmed or suspected breaches to the state within a defined timeframe. They also require basic hygiene measures such as changing default vendor passwords, disabling unnecessary remote‑access services, and ensuring that critical devices are not directly exposed to the public internet. Compliance is verified through self‑assessments and occasional audits, with non‑compliant entities risking loss of future grant eligibility.

Guidance from State and Local Officials
Michaela Lee, acting chief cyber officer in the governor’s office, emphasizes that sophisticated tools are not a prerequisite for effective defense. “You don’t need all sorts of fancy tools to defend against adversaries. You just need to know the basics,” she notes, highlighting practices like strong password policies, network segmentation, and timely patching. William Simcoe, Albany’s acting water commissioner, echoes this advice, stating that the city’s strategy includes changing manufacturer‑default passwords on all devices, placing PLCs behind VPNs, and limiting remote access to strictly necessary, authenticated channels.

Federal Warnings and Specific Threat Vectors
The federal Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security, has issued alerts warning that Iranian‑linked hackers have compromised PLCs by altering passwords, locking out legitimate operators, and changing the devices’ IP addresses to isolate them from control networks. The FBI has added that certain internet‑exposed Allen‑Bradley PLC models have been actively targeted, with attackers causing water pressure loss, flooding, or unsafe chemical releases. Sarah Ruane, spokesperson for the FBI Albany field office, said her office works closely with utilities to share threat intelligence, conduct security briefings, and guide breach‑reporting procedures.

Albany’s Use of Allen‑Bradley PLCs and Mitigation Measures
Simcoe confirmed that Albany relies heavily on Allen‑Bradley PLCs, describing them as “the GE, the Microsoft” of PLCs due to their widespread use and reliability. However, the city does not connect these controllers to the open internet. Instead, they are situated behind multiple layers of security: firewalls, VPNs, and a suite of consulting firms that handle configuration, monitoring, and regular patch updates. This defense‑in‑depth approach aims to ensure that even if an attacker penetrates the outer network, reaching the PLCs remains extremely difficult without legitimate credentials and proper network traversal.

Broader Context: Historical Incidents and Emerging Risks
Lee pointed to a 2013 episode in Westchester County where an Iranian‑backed group infiltrated a dam’s control network, reading files containing usernames and passwords, although the dam’s physical operations were unaffected. The incident illustrated that even peripheral access can yield valuable intelligence for future attacks. Beyond water, hospitals and other critical infrastructure are also receiving heightened attention as potential targets. Looking ahead, officials warn that the integration of artificial intelligence into hacking toolkits could enable threat actors to automate reconnaissance, craft more convincing phishing lures, and exploit vulnerabilities at unprecedented speed and scale.

Manual Operation as a Resilience Backstop
A key resilience strategy highlighted by both state and local experts is the capacity to switch to manual operations when automated systems are compromised. Lee explained that many utilities now maintain procedural guides allowing operators to control pumps, valves, and chemical feeds via local panels or hand‑held devices if SCADA or PLC communications are disrupted. Simcoe added that training staff to operate equipment manually reduces reliance on potentially compromised digital pathways and ensures that essential services can continue, albeit at reduced efficiency, during a cyber incident.

Conclusion and Outlook
Albany’s recent grant awards represent a proactive step in fortifying its water and sewer infrastructure against an evolving cyber threat landscape. By focusing on foundational security practices—network segmentation, strong authentication, regular patching, and staff awareness—the city aims to protect the critical PLCs that underlie its treatment and distribution processes. The statewide program, bolstered by new compliance standards and federal advisories, seeks to create a uniform baseline of resilience across New York’s municipal utilities. As adversaries increasingly leverage sophisticated tools and possibly AI‑driven tactics, the emphasis on basic hygiene, vigilant monitoring, and the readiness to revert to manual control will be vital in safeguarding public health and environmental safety. Continued investment, ongoing training, and inter‑agency cooperation will remain essential components of the city’s long‑term cybersecurity strategy.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here