Cybersecurity for water and power: Overcoming legacy systems and regulatory pressure
The security breaches that recently disrupted UK retailers and Spanish power grids serve as a stark reminder of mounting cyber threats facing both private and public sectors. While these attacks have caused logistical chaos and financial losses, they pale in comparison to the potential impact of a coordinated cyber attack on critical public infrastructure, like the water sector. Several high-profile hacks of water utilities have taken place in the US and Europe in recent years, which cyber security experts warn underscores the vulnerability of the sector to sophisticated cyber attacks.
According to Tobias Nitzsche, Global Cyber Security Practice Lead at ABB, the existence of legacy systems – defined as outdated or obsolete hardware and software – is a potential Achilles Heel. “Like any other distributed control system (DCS) environment, you will find a lot of legacy systems so in that respect the water industry is no different to any other,” says Nitzsche. “But what we’re seeing in the water sector is that smaller companies are most vulnerable. They have less dedicated resources for specific tasks, especially when it comes to cyber security, which often means that one person or one department must cover a lot of ground.”
Nitzsche warns that legacy systems are more exposed to cyber attacks because they often lack modern security features, are not regularly updated, and may have vulnerabilities that are well-known to attackers.
Read more at International Water Power