Full Report
The provision of safe and reliable drinking water and wastewater is critical for society to function. The water sector is one of the critical infrastructure sectors as safe and reliable drinking water is required for consumption, fire protection, manufacturing, cooling, etc., by almost all businesses and residences. The increase in water security and preparedness started…
Analysis Summary
# Best Practices: Water and Wastewater Sector Cybersecurity
## Overview
These practices address the evolving threat landscape for Community Water Systems (CWSs), transitioning from a post-9/11 focus on physical security to a modern "all-hazards" approach. They specifically target the vulnerabilities in Operational Technology (OT), Business Systems, and Internet-exposed critical infrastructure that could lead to operational disruptions or public health crises (e.g., boil water notices).
## Key Recommendations
### Immediate Actions
1. **Secure OT Exposure:** Identify and disconnect Programmable Logic Controllers (PLCs), such as Rockwell Automation/Allen-Bradley MicroLogix and Siemens S7, from the public internet.
2. **Update Default Credentials:** Change all factory-default passwords on PLCs and gateway devices immediately.
3. **Emergency Response Refresh:** Review and update Emergency Response Plans (ERPs) to include specific protocols for cyber-induced operational failures.
### Short-term Improvements (1-3 months)
1. **Conduct RRAs:** Perform a Risk and Resilience Assessment (RRA) covering physical infrastructure, OT, and business systems (required every five years for systems serving >3,300 people).
2. **Implement MFA:** Deploy Multi-Factor Authentication for all remote access to the water system’s network.
3. **Gap Remediation:** Move beyond "checkbox compliance" by identifying and funding the closure of security gaps found during initial assessments.
### Long-term Strategy (3+ months)
1. **Regulatory Alignment:** Prepare for a formal regulatory framework for cybersecurity as the sector moves away from voluntary tool adoption.
2. **Lifecycle Funding:** Secure long-term funding for continuous OT hardware/software upgrades rather than one-time fixes.
3. **Workforce Training:** Establish ongoing cybersecurity training for plant operators to recognize and report suspicious OT behavior.
## Implementation Guidance
### For Small Organizations (Serving >3,300 residents)
- Focus on free resources from the EPA and CISA to conduct mandatory RRAs.
- Prioritize physical access control and simple network isolation for OT devices.
### For Medium Organizations
- Utilize the American Water Works Association (AWWA) cybersecurity toolset to benchmark security posture.
- Formalize the link between VA (Vulnerability Assessment) findings and capital improvement budgets.
### For Large Enterprises
- Implement advanced network segmentation between business (IT) and operational (OT) networks.
- Conduct regular red-teaming or penetration testing specifically targeting PLC logic and IP address stability.
## Configuration Examples
*While the article provides high-level guidance, the following technical configurations are emphasized based on recent threat activity:*
* **PLC Hardening:**
* Change default IP addresses of internet-facing controllers.
* Disable unused ports and services on Siemens S7 and Allen-Bradley controllers.
* Enable logging for all successful and failed login attempts to OT controllers.
## Compliance Alignment
- **AWIA Section 1433:** Requirements for Risk and Resilience Assessments (RRAs).
- **Safe Drinking Water Act (SDWA):** The primary regulatory vehicle for water safety.
- **NIST/CISA Standards:** General alignment with CISA’s "urgent alerts" for critical infrastructure protection.
## Common Pitfalls to Avoid
- **The "Checkbox" Mentality:** Only performing assessments to satisfy regulatory deadlines without implementing the corrective actions identified.
- **Ignoring OT:** Focusing exclusively on business IT security while leaving the "pipes and pumps" (OT) exposed to the internet.
- **Exclusion of Wastewater:** Assuming security mandates only apply to drinking water; wastewater systems face similar risks and require similar vigilance.
## Resources
- **EPA Cybersecurity Water Sector Tools:** [www.epa.gov/cyberwater/epa-cybersecurity-water-sector]
- **CISA OT/PLC Alerts:** [www.cisa.gov/news-events/alerts]
- **AWWA Security Resources:** [www.awwa.org]
- **America’s Water Infrastructure Act (AWIA) Guidance:** [www.epa.gov/waterresilience/awia-section-2013]