Ex-NSA chief Paul Nakasone emphasizes the risks of internet-connected water system controllers after cyberattacks linked to Iran.
In a recent address at DEF CON, former NSA chief Paul Nakasone raised significant concerns regarding the cybersecurity of U.S. water systems. His comments come in light of suspected cyberattacks linked to Iran affecting at least 12 states. Nakasone highlighted a glaring risk: water system controllers—critical components in managing water supply—should not be connected to the internet.
As the FBI investigates malicious cyber actors targeting operational technology devices, Nakasone pointed to the implications these attacks have on the nation’s vital collaboration/">infrastructure. Nearly every water facility, he noted, relies on programmable logic controllers (PLCs) that supervise essential functions like managing tank levels and controlling pump operations.
The recent uptick in cyberattacks represents a troubling trend that has seen groups potentially linked to Iran launching incursions into these systems. “I’d be shocked if it’s not Iran,” stated Cynthia Kaiser, a senior vice president at the Halcyon Ransomware Research Center, echoing widespread concerns at the event. Yet, despite these indications, official attribution from cybercriminals/">law enforcement remains cautious.
Nakasone stressed the historical context, noting that Iranian cyber units had previously demonstrated their ability to infiltrate U.S. water facilities. In his view, there’s sufficient evidence indicating both capability and intent from these groups. Nakasone stated, “We’re in conflict with Iran” and emphasized that vigilance is crucial.
U.S. water systems represent a complex and inadequate battleground when it comes to cybersecurity. With over 50,000 municipal water authorities operating across the nation, most facilities have limited funding and deficient cybersecurity measures. According to Nakasone, many of these sites lack dedicated IT staff, which further exacerbates their vulnerability.
“We have to think differently about how we defend it,” he said, calling for a more comprehensive strategy to bolster defense mechanisms within these infrastructures. The lunar disc of available resources and cybersecurity personnel creates a daunting challenge in safeguarding against potential attacks.
With 90% of the nation’s water supply sourced from these 50,000 municipalities, the implications of a successful cyberattack could be catastrophic, impacting millions of Americans if these systems are compromised. The water industry’s insufficient preparedness coupled with inadequate funding raises serious questions about national security.
In light of these vulnerabilities, Nakasone emphasized the need for partnerships as a pillar of cybersecurity strategy. He advocated for collaborative efforts among public and private sectors to strengthen defenses. A prime example is DEF CON Franklin, an initiative launched at DEF CON two years ago that encourages ethical hackers to lend their expertise in securing water facilities.
Nakasone’s extensive experience in cybersecurity has informed his belief that solving national security challenges requires cooperative measures. He acknowledged the multifaceted difficulties that lie ahead and indicated that real progress is made when various stakeholders collaborate in innovative ways.
Additionally, Nakasone is also spearheading Project Chimera—an initiative aimed at enhancing the cybersecurity resilience of critical infrastructure through collaboration with academic institutions and cybersecurity professionals. The project combines open-source technologies while drawing insights from experts across the sector.
Facing the constant threat of cyber attacks, particularly from state-sponsored actors like Iran, raises critical questions about the future of water system cybersecurity. As more attacks emerge, the pressing need for an articulated and sustained defensive strategy becomes evident.
Nakasone concluded that defending these crucial systems involves a shift towards a cooperative and integrated approach. He calls for the engagement of various sectors—public, private, and academic—to take action before a catastrophic incident occurs.
His warning resonates across the industry: without fundamentally changing our approach to cybersecurity in water systems, we risk leaving vital resources vulnerable to exploitative actors. The collaboration he champions must be prioritized, effectively bridging the gap in current defenses, aiming for an overall fortified infrastructure that recognizes the urgent need for cybersecurity vigilance.
The implication of these remarks extends beyond just water systems; they beckon a broader conversation about the security of critical infrastructure across the nation. As cyber threats evolve, so must our strategies to protect not only water but also other critical elements essential to public health and safety.