Connecticut Issues Water Utility Cybersecurity Advisory After Recent Attacks

0
2

Key Takeaways

  • Recent cyber incidents targeting Rockwell Automation and Allen‑Bradley MicroLogix programmable logic controllers (PLCs) have prompted warnings from the FBI and EPA, though no successful attacks have been reported in Connecticut so far.
  • Connecticut relies on an intelligence‑sharing network—centered on the Connecticut Intelligence Center (CTIC)—to disseminate alerts and mitigation steps quickly, rather than maintaining a centralized inventory of every controller.
  • State officials emphasize rapid warning distribution and encouraging individual utilities to recognize and address their own risks, with most critical‑infrastructure partners accepting the guidance.
  • PLCs enable remote monitoring and control of water‑system equipment but become vulnerable when exposed directly to the internet; recommended protections include removing PLCs from public exposure, using secure gateways, strong passwords, and multifactor authentication.
  • Many Connecticut water systems are small (serving fewer than 500 people) and may lack detailed component inventories, making it difficult to assess how many use the specific PLC models targeted in the alerts.
  • Experts stress that basic cybersecurity hygiene—such as changing default credentials, segmenting operational technology from public networks, and continual vulnerability monitoring—is more decisive than sophisticated attack techniques.
  • While larger utilities like Aquarion Water Authority are proactively adopting advanced measures, smaller systems often face funding, staffing, and legacy‑equipment challenges that hinder timely upgrades.
  • Federal law requires risk assessments and emergency‑response plans only for community water systems serving more than 3,300 people, leaving many smaller Connecticut systems without mandatory cybersecurity planning.
  • Ongoing information sharing, voluntary vulnerability assessments (e.g., via CISA), and utility‑level verification of protections are seen as essential to maintaining resilience against evolving cyber threats to water infrastructure.

Overview of Recent Cyber Threats to U.S. Water Systems
In recent weeks, federal agencies have observed a series of cyber intrusions targeting water and wastewater utilities across at least seven states. Attackers gained remote access to internet‑facing Rockwell Automation and Allen‑Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs), altered the devices’ IP addresses and passwords, and consequently caused operators to lose monitoring or control capabilities. Depending on the equipment affected and whether facilities could switch to manual control, the intrusions resulted in flooding or loss of water pressure. The FBI and the Environmental Protection Agency (EPA) issued alerts describing the tactics and recommending immediate mitigation steps. Although several states reported incidents, Connecticut’s water utilities have not yet confirmed any attempted or successful activity linked to this campaign.

Connecticut’s Intelligence‑Sharing Approach
Evan Allard, director of the Connecticut Intelligence Center (CTIC), explained that upon receiving the federal warning, CTIC promptly circulated information about the affected equipment, suspicious internet addresses, and recommended protective measures to water systems statewide. Allard noted that no Connecticut water system has reported activity tied to the attacks, but the state does not keep a centralized inventory of which utilities use the specific PLC models identified by federal authorities. Consequently, officials cannot verify how many systems have completed the recommended security measures. Allard downplayed the concern over the missing inventory, stressing that Connecticut’s strategy hinges on rapid warning distribution and ensuring individual operators recognize and address their own risks rather than maintaining a master list of every controller.

Structure and Function of CTIC
CTIC operates as a fusion center that brings together state, local, and federal partners—including the Department of Emergency Services and Public Protection (DESPP), the Cybersecurity and Infrastructure Security Agency (CISA), and the Connecticut National Guard’s cyber response team—to exchange intelligence on terrorism, crime, and cyber threats. Allard highlighted the value of pre‑existing relationships with water entities, which enable CTIC to turn around and disseminate actionable guidance swiftly. The center aims to deliver short, practical advisories—often a single page—rather than lengthy technical manuals, encouraging recipients to call with questions so they can be connected to the appropriate expert. While CTIC provides the information and mitigation steps, the ultimate decision to implement recommendations rests with each utility’s management.

Response from State Agencies and Utilities
Following the July 30 federal warning, the Connecticut Department of Public Health (DPH) contacted all community water systems and their certified operators, urging those using programmable logic controllers to enact the federal mitigation measures immediately. DPH spokesperson Brittany Schaeffer confirmed that the department has not received notifications of any attempted or successful attacks targeting Connecticut public water systems. The state regulates 2,387 public water systems, of which 492 are community systems; the majority serve fewer than 500 people, with many serving fewer than 100 residents. Although some of these systems employ PLCs and other remotely accessible technology, DPH does not maintain a component‑level inventory, leaving it unable to quantify how many utilize the exact controller models highlighted in the warnings.

Details on the Targeted PLCs and Associated Risks
Programmable logic controllers are compact industrial computers that interpret sensor data—such as pressure, chemical levels, or tank volumes—to automatically control pumps, valves, alarms, and treatment processes. Remote access enables operators to monitor distant equipment, respond to after‑hours alarms, or allow vendors to diagnose problems without traveling onsite. However, when a PLC is directly exposed to the public internet, it becomes discoverable by attackers who may attempt default or stolen passwords, exploit known vulnerabilities, or take advantage of poorly secured connections. Federal guidance advises removing PLCs from direct internet exposure, protecting necessary remote links with secure gateways and firewalls, employing strong, unique passwords, and restricting communications to authorized devices only. Despite these recommendations, DPH acknowledges it cannot verify how many Connecticut systems have implemented them due to the absence of detailed infrastructure data.

Manual Control Capabilities and Operational Challenges
Schaeffer emphasized that all Connecticut public water systems can revert to full manual control if automated equipment is disabled, although the time required to make that transition varies with system complexity, staffing levels, and operator training. Larger, more integrated networks may need more time to shift operations manually, whereas smaller, simpler setups might adapt more quickly. The ability to operate manually serves as a critical safety net, but reliance on manual processes can strain resources and affect service continuity during prolonged cyber incidents.

Insights from the GAO Report and Basic Cybersecurity Principles
A May report by the U.S. Government Accountability Office (GAO) found that water and wastewater systems exhibit widely varying cybersecurity capabilities, often hampered by worker shortages, limited funding, and aging equipment that is difficult to update. Allard observed that many significant cyber incidents stem not from highly sophisticated techniques but from basic security failures—such as reused passwords, lack of multifactor authentication, default login credentials, or devices left exposed to the internet. He asserted that adhering to fundamental cybersecurity hygiene—changing passwords, enabling multifactor authentication, segmenting operational technology from public networks, and regularly patching systems—typically provides the strongest defense. Connecticut’s advantage lies in its collaborative network of federal, state, local, and private‑sector partners, which pools limited budgets into a more robust defensive posture.

Academic Perspective on Preparedness
Tirthankar Ghosh, a cybersecurity professor and director of the Connecticut Institute of Technology at the University of New Haven, concurred that information sharing is vital but stressed that each operator must know what equipment it possesses, understand its vulnerabilities, and verify that protective measures are in place. Ghosh noted that operational technology once isolated is increasingly integrated with conventional computer networks, improving usability while simultaneously expanding the attack surface. He warned that the state is not yet fully prepared for such threats and advocated for continual vulnerability identification, threat monitoring, elimination of default passwords, use of multifactor authentication, and strict separation of operational equipment from public‑facing networks. Ghosh also pointed out that legacy systems often run outdated software because newer versions are incompatible with existing controllers, creating a “weak link” that can jeopardize an entire supply chain if not addressed.

Regulatory Scope and Enforcement Gaps
Federal law mandates risk assessments and emergency‑response plans that address cyber threats for community water systems serving more than 3,300 people. Smaller community systems and non‑community systems are exempt from these requirements, meaning many of Connecticut’s numerous small utilities are not compelled by law to conduct formal cybersecurity planning. DPH declined to disclose how many Connecticut systems have completed cybersecurity assessments through state, EPA, or CISA channels, citing the sensitivity of the information. Ghosh warned that the persistence of the threat leaves little margin for complacency and urged that preparedness levels remain extremely high, with constant vigilance across all system sizes.

Conclusion: Balancing Sharing, Responsibility, and Resilience
Connecticut’s response to the recent PLC‑focused cyber threats illustrates a model that prioritizes rapid intelligence sharing, practical guidance, and utility‑level accountability over exhaustive inventories. While the state’s fusion‑center framework enables timely dissemination of warnings and best practices, the effectiveness of the defense ultimately depends on each water provider’s willingness and ability to implement recommended safeguards—particularly given the prevalence of small, resource‑constrained systems and legacy infrastructure. Ongoing collaboration among CTIC, CISA, public‑health officials, utilities, and academic experts, combined with a steadfast focus on basic cybersecurity hygiene, will be essential to safeguarding Connecticut’s water supply against evolving cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here