OT Security Alliance Calls on Congress and CISA to Advance Reforms in Response to Cyberattacks on Water Sector
U.S. water facilities were attacked by hackers suspected of being linked to Iran, affecting at least seven states. The OT Cybersecurity Alliance calls on CISA to issue binding operational directives and asks Congress to take three specific measures to strengthen critical infrastructure security.

A security coalition focused on operational technology is calling for immediate action to strengthen the security of national critical infrastructure, following coordinated attacks on U.S. water infrastructure sites.
Federal and state authorities are investigating a campaign of attacks targeting vulnerable industrial devices at thousands of drinking water and wastewater treatment facilities nationwide.
Threat actors believed to be linked to Iran successfully locked operators out of their own systems by targeting industrial devices exposed to the open internet. To date, water utilities in at least seven states, including Minnesota and Michigan, have been affected.
The series of attacks began on July 26-27, hitting about 30 systems in Minnesota. Federal and state officials say the incidents are consistent with hackers targeting vulnerable logic controllers that are often misconfigured, use default passwords, do not require multi-factor authentication, and are discoverable via the open internet.
Last week, CISA and the FBI urged water system operators to strengthen system security, particularly programmable logic controllers, which are widely used in local utilities for water quality monitoring and other functions.
A spokesperson for the Michigan Department of Environment, Great Lakes, and Energy said that after receiving warnings from federal authorities, Michigan officials confirmed similar attempts to tamper with their OT systems.
"All systems continue to operate safely. Issues were resolved by local operators, and there are no known impacts that pose a public health concern," spokesperson Dale George told Cybersecurity Dive.
Widespread risk
According to Alison King, chair of the OT Cybersecurity Coalition and vice president of government affairs at Forescout, there are currently about 148,000 public water systems in the U.S., including about 50,000 community water systems and 16,000 wastewater treatment sites.
"These systems are decentralized, many are underfunded, and security postures vary widely," King said. "Only a small fraction directly participate in threat intelligence sharing, and many operators have limited knowledge of the infrastructure information adversaries may already possess."
In a statement released last Friday, Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition, called these attacks a wake-up call. The coalition urged the Cybersecurity and Infrastructure Security Agency to issue a binding operational directive requiring immediate action by federal civilian executive branch agencies to mitigate risks to thousands of critical sites used by the government for heating and cooling, power, access management, and other functions.
Bolton also urged Congress and CISA to take three specific immediate measures.
-
Congress should reauthorize and fund the State and Local Cybersecurity Grant Program. This program provides funding to state, local, and territorial governments to protect critical infrastructure sites.
-
Congress should support Andrew McClure as director of the Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response. McClure was appointed to this position at the end of last month. The office is responsible for protecting the nation's energy sector, including the electric grid, from malicious cyber activity.
-
CISA is urged to pass a long-term authorization of the Cybersecurity Information Sharing Act of 2015. This authorization would allow private sector partners to continue sharing information about potential cyber threats with CISA and allow CISA and the FBI to pass that information to a broader set of potential victims. The authorizationis set to expire at the end of September。