Back to Newsroom

The Real Threat of Cyber Attacks On Smaller Water Systems Can be Avoided With One Simple Step

AWWA LOGO

For smaller Public Water Systems (PWSs) in the United States, the vulnerability of the water supply system to potential attacks is a very real issue. This is especially true for those systems operating on limited or no budget for upgrading outdated IT equipment and cybersecurity plans. The sophistication of hackers has reached a level where they could potentially gain control over the water treatment infrastructure, manipulating chemical dosages meant for water treatment. Adding or removing large quantities of these chemicals could pose serious health risks to the public.

For example - Sodium hydroxide is used in small amounts to regulate water's pH levels. If a hacker could raise the sodium hydroxide (lye) concentration in the water from a safe level of 100 parts per million to a dangerous level, it can cause skin damage and hair loss upon contact or, if ingested, induce life-threatening gastrointestinal symptoms.

To address these types of concerns, the Americas Water Infrastructure Act (AWIA), enacted in 2018, mandates that community drinking water systems (CWSs) serving more than 3,300 people must create or revise risk and resilience assessments (RRAs) and emergency response plans (ERPs) to mitigate the potential for such cyber-attacks. The US EPA has also formulated guidelines for cybersecurity in the water sector to implement fundamental cybersecurity practices.

All water utilities regardless of size need to take steps to protect against a cyber- attack that could jeopardize the city's water supply through unauthorized access to its water treatment software.

Secure Software Designed for Water Utilities

A simple approach to ensuring a water utility is protected is to use a modern software management solution designed specifically for the water industry to manage data for operations. These programs also streamline processes, maintain assets, help with budgeting, and aid in regulatory reporting. A modern industry software solution will provide the assurance that data and operational integrity will be safeguarded from malicious intent, similar to the security used by a trusted banking application for transaction protection.

Most modern utility management software programs use the Microsoft Azure cloud platform, a system also employed by the US military for highly classified national security missions. This cloud environment maintains a FedRAMP Authorization to Operate (ATO) for systems with moderate and high impacts, adhering to security standards including ISO/IEC 27001, ISO 27018, SOC 1, SOC 2, SOC3, FedRAMP, HITRUST, MTCS, IRAP, and ENS.

It’s Easier to Use than You Think

It’s not uncommon for smaller utilities to have staff that have been in the organization for years and have been doing the same tasks, the same way for a long time. There can also be the perception that technology is hard to use and that a person needs to be an expert or a computer geek to use it.

The reality, however, is that good programs that are designed specifically for water utilities, mirror the manual process with much less data entry and calculations required. This makes it intuitive for less techie users and also lends itself well to attracting new employees who are led through the program with the necessary steps of meeting daily operational requirements. The system does the hard work in the background, such as QA/QC, sends alerts for potential anomalies wherever they may lie, and most importantly updates the program with the latest security to protect against cyber-attacks. There is no need for users to have an in- depth knowledge of potential network vulnerabilities or cloud security practices.

There are typically several layers of authorization and controls to allow different stakeholders access whether it be to simply view data, or manage real-time monitoring, file compliance reports, or perform predictive and prescriptive plant operations. A modern operational technology network that is critical for system control remains accessible only to authorized personnel.

Most modern software is designed to integrate seamlessly with existing IT infrastructure, including legacy systems, to ensure minimal disruption during implementation. Software that is designed for the cloud also has the benefit of seamless upgrades to address emerging cybersecurity threats.

Finding the Right Program

Experts in cybersecurity point out that the decentralized structure of the US water supply network—comprising approximately 70,000 individual water and wastewater utilities—contributes to its susceptibility to cyber intrusions. If you are a smaller PWS, it’s important to do your research to find a software solution that not only improves your operations but protects you from cyber-attacks. Not all programs are alike, ensuring the software is ISO/IEC 27001 and FedRAMP compliant, is a good foundation.

Here are 12 questions to consider asking suppliers:

  1. Does the software vendor have a documented cybersecurity policy?
  2. Does the software vendor have a documented data privacy policy that is in compliance with laws and regulations that are applicable in your jurisdiction?
  3. Are all the software vendor’s employees required to take annual security awareness and data protection training?
  4. Does the software vendor have a password policy and is it enforced by technical means?
  5. How does the software vendor apply encryption to protect customers' data?
  6. How are duties segregated to prevent unauthorized access or disclosure of customer information?
  7. Does the software vendor conduct security assessment due diligence for all its suppliers before engaging in the use of their products or services?
  8. Has the software vendor suffered any security incidents in the last 12 months?
  9. How frequently does the vendor update their software to address emerging cybersecurity?
  10. Does the software vendor conduct regular vulnerability scans of its IT infrastructure and have a process to remediate vulnerability findings?
  11. What is the software vendor’s upgrade and patching policy for all its IT systems? How often are the security patches applied?
  12. What is the vendor's track record in working with water utilities, and can they provide references or case studies from similar-sized organizations?

The answers to these questions will help you to identify vendors that have designed programs with security at the heart of every building block, not as an add-on. This ensures a comprehensive layer of protection at every access point, and safeguards data during software updates to incorporate the latest security.

It’s also a good idea to ask neighboring utilities what they use and ask suppliers for demos, and most importantly involve key personnel in the decision-making process to help make a smooth transition to a modern data platform that all users like because it improves operations and delivers better outcomes.

Author: Kevin Koshko is the Product Manager for Water Treatment Data Management at Aquatic Informatics. He brings over 24 years of experience helping municipalities and water professionals solve some of their biggest challenges. Kevin has spent the last two decades as a software developer, architect, and product manager as well as a licensed water distribution and wastewater treatment operator.