Water and Sewer Departments Strengthen Cybersecurity Defenses Against Hacker Threats

0
4

Key Takeaways

  • New York State is allocating over $9 million in grants to 153 municipal water and sewer facilities to improve cybersecurity after a wave of attacks linked to Iran.
  • Funding supports basic defenses such as changing default passwords, using virtual private networks (VPNs), staff training, and securing internet connections.
  • The most critical targets are programmable logic controllers (PLCs) that control pumps, valves, and chemical dosing; compromising them can disrupt water pressure, cause sewage backups, or alter treatment chemicals.
  • Federal agencies (CISA and the FBI) have warned that internet‑exposed Allen‑Bradley PLCs are being manipulated to lock operators out, change passwords, and induce flooding or pressure loss.
  • Utilities are layering defenses—separate networks for business, security, and operational technology—and retaining the ability to switch to manual operation as a fallback safeguard.
  • The emerging threat of AI‑driven attacks heightens the need for continual training, regular system updates, and information sharing across sectors, including hospitals and dams.

Overview of the Grant Initiative
Gov. Kathy Hochul’s office is distributing more than $9 million in grants to 153 municipal water facilities across New York State to bolster cybersecurity. The funding follows a series of cyberattacks on water and sewer systems reported in at least seven states since July 27, with investigators noting suspected ties to Iranian threat actors. The grant program stems from new cybersecurity standards enacted last year that took effect in March, which mandate employee training, breach reporting, and minimum technical safeguards for operational technology.

Capital Region Allocations
Over a dozen water and sewer departments in the Capital Region received portions of the state grant, including the towns of East Greenbush and Guilderland and the cities of Hudson and Rensselaer. These awards are intended to help local utilities meet the new standards by financing staff education, securing remote connections, and obtaining expert consulting support. Michaela Lee, acting chief cyber officer in the governor’s office, emphasized that effective defense does not require extravagant tools; mastering basic hygiene—such as patching systems and controlling access—is often sufficient.

Practical Safety Measures
William Simcoe, acting water commissioner for the city of Albany, highlighted simple but critical steps: changing default manufacturer passwords and keeping devices off the open internet by routing them through virtual private networks (VPNs). Albany received $120,160 for its drinking‑water system and $73,170 for its sewer system under the grant program. Simcoe noted that the city maintains three distinct computer networks: one for business functions like online bill pay, a second for security systems such as cameras and building access, and a third dedicated to operational technology that controls pumps, valves, and chemical feeds.

Operational Technology as the Prime Target
The operational technology network—responsible for managing physical infrastructure—is the most likely target for adversaries. Simcoe explained that compromising this layer could allow hackers to shut off remote access to pump stations and water tanks, cause sewage to back up or divert into overflow lines, or manipulate pumps and valves to alter water flow and chemical dosing. Such interference could lead to pressure loss, flooding, or unsafe water quality, posing direct risks to public health and the environment.

Role of Programmable Logic Controllers
At the core of the operational technology stack lies the programmable logic controller (PLC), a specialized computer that programs equipment and transmits data to human‑machine interfaces. Michaela Lee warned that threat actors often focus on PLCs and other OT components because they directly control physical processes. The federal Cybersecurity and Infrastructure Security Agency (CISA) has reported incidents where attackers modified PLC passwords, locked out legitimate operators, and changed IP addresses to disconnect devices from the network.

FBI Warnings on Specific PLC Models
The FBI has issued alerts that certain internet‑exposed models of Allen‑Bradley PLCs—described by Simcoe as the “GE, the Microsoft” of PLCs—have been targeted in attacks that resulted in water pressure loss and flooding. Sarah Ruane, spokeswoman for the FBI Albany field office, stated that her office works closely with utilities to share threat intelligence, provide security briefings, and guide breach‑reporting procedures. Simcoe confirmed that Albany uses Allen‑Bradley PLCs but keeps them isolated from the public internet, relying on several layers of consultants to configure, monitor, and update the devices regularly.

Broader Critical‑Infrastructure Concerns
Lee pointed out that water systems are not the only critical infrastructure under threat; a 2013 incident in Westchester County saw an Iranian‑backed group hack a dam, although the dam itself remained unharmed while attackers accessed files containing usernames and passwords. Hospitals are also receiving heightened attention as part of the state’s broader cybersecurity push. Lee noted that over the past 13 years, considerable work has been done to improve assurance and safeguards across sectors, but the threat landscape continues to evolve.

Emerging AI‑Enabled Threats
A growing concern is the potential use of artificial intelligence by hackers to accelerate and scale attacks. AI‑driven tools could automate reconnaissance, password cracking, and the exploitation of vulnerabilities, allowing threat actors to compromise more systems in less time. Lee stressed that this underscores the need for continuous training, regular system hardening, and rapid information sharing among utilities, state agencies, and federal partners.

Manual Operation as a Fallback Safeguard
One practical mitigation highlighted by both Lee and Simcoe is the capability to switch critical processes to manual operation when automated systems are compromised. By maintaining trained staff who can operate pumps, valves, and chemical feeds without relying on networked controls, utilities can limit the damage of a cyber intrusion. Simcoe remarked that contemplating manual fallback encourages operators to think deeply about redundancy and resilience, reinforcing overall system robustness.

Conclusion and Ongoing Efforts
The state’s grant program represents a coordinated effort to raise the cybersecurity baseline for municipal water and sewer infrastructure. By funding training, securing remote connections, isolating operational technology, and retaining manual‑override capabilities, New York aims to mitigate the risk posed by state‑linked actors and emerging AI‑enhanced tactics. Continued vigilance, interagency collaboration, and investment in both technology and human expertise will be essential as utilities defend essential public‑health services against an evolving cyber threat landscape.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here