Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.
Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.
The federal government could potentially oversee the most populous areas of the state and those near a military installation pretty easily. They don’t have to look at every one.
The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.
There's no "national infrastructure" for water. Aside from what the EPA does, it isn't within the remit of the federal government to manage municipality water systems.
My wording was ambiguous. “national infrastructure” can refer to either the infrastructure in our nation or infrastructure managed by the federal government. I meant the former.
The US government does meat inspections, that seems like a much broader scope than auditing the security of a couple hundred thousand utilities every few years. At the very least they could send them a set of best practices and require them to certify compliance. Larger ones could get random on-site inspections.
Usually these commenters are not from the US but get energized by US topics and misunderstand scale of things. E.g., they come from countries with a single nationalized entity for many things.
There are 150 million taxpayers and the federal government regulates all of them. I don’t see why they can’t audit 0.1% of that. If there are 150,000 utilities then absent some regulation, some of them will fuck up. If we want fewer fuckups, you need regulation.
It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports.
> make the feds do it
National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a war with another country they’re absolutely responsible for minimizing by collateral damage at a fucking minimum.
National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground?
NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.
I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.
And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.
> The issue comes down to actual skilled people hours to do the work and resource constraints to do so.
It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly.
> But what does that fundamentally mean for boots on the ground?
How does any regulation look on the ground? How does the federal government regulate banks and airports?
> these are for the most part, not federal government funded entities nor government controlled even at a state level
Neither are banks or airports
> What about Energy? Data Centers? Pharma?
Energy and pharma are already regulated. Maybe data centers will be eventually if they are deemed sufficiently critical.
> Regulation is way too far behind to just instantly drop a silver bullet.
I don’t know what this even means in the context of securing our water system. Do you mean to say that regulation can’t ensure that these software systems don’t use default passwords and so on?
> And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI
What is new is that we started a war with a country with a respectable technology competency without doing anything to shore up our defenses.
Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”.
It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.
It needs some real backing and effort to make it happen.
> Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”.
Top down regulation drives the systematic change, just like it did with the banking sector.
> It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.
I'm not sure how this analogy works. What's the ATC equivalent to leaving default passwords on critical infrastructure?
> Top down regulation drives the systematic change, just like it did with the banking sector.
Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default passwords are a symptom, not the failure mode.
ATC is already federal, with the FAA running that. 20 years of regulation has not fixed the problems that still plague that industry: outdated equipment, short-staffed, a small niche talent and training pipeline, and people dying as a consequence of those systemic problems. That's even closer to my point. Making something regulated doesn't change the inherent problems inside the industry.
“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
can't reboot, the machinists have the windows sized and positioned on screen just like they like them since 1997, so if you reboot it will cause downtime