Tackling the growing need for cybersecurity in public utilities

by | September 5, 2024

Public utilities providing mission-critical water and power services are becoming prime targets for cyberattacks. According to the International Energy Agency (IEA), on average, utility companies faced more than 1,100 cyberattacks per week in 2022. That’s up from 750 attacks per week in 2021 and 500 in 2020. The actual numbers may be even higher as many of these incidents go undetected or unreported. The increase in cyberattacks raises alarms as cyberattacks not only disrupt utilities but can also have serious consequences for the communities and businesses they serve.

Cyberattacks on public utilities have far-reaching impact

Cyberattacks on public utilities can lead to outages, water supply issues, compromised gas distribution, and other disruptions that can impact households, businesses, and critical infrastructure like hospitals and emergency services.

The economic fallout from these disruptions can be substantial. According to the Cost of a Data Breach Report 2024, the cost of a data breach in the energy sector has increased from $4.78 million in 2023 to $5.29 million in 2024, earning a top 5 spot in a ranking of industries.

Beyond the financial cost, utility outages caused by cyberattacks pose significant public safety risks by disrupting essential services. A few examples include:

  • Hospitals and emergency responders rely on consistent power and water supplies to function, and outages can impair life-saving equipment and communication systems.
  • Public health is jeopardized when water supplies are compromised, potentially spreading diseases.
  • Transportation systems can become hazardous, leading to accidents and delays.
  • Vulnerable populations, such as older adults or those dependent on medical devices, face immediate health threats.

Generally, disruptions to public utilities increase the risk of accidents, crime and food safety issues, underscoring the critical need for strong cybersecurity measures to protect vital services.

Why cybersecurity risk for utility infrastructure is increasing

Public utilities are more vulnerable to cybersecurity risk today because they’re more interconnected than ever before. To enhance operational efficiency and service delivery, they’ve connected their existing infrastructure and added newer smart technologies, such as:

Operational Technology (OT)

OT, also known as Industrial Control Systems (ICS), encompasses the hardware and software systems that monitor and control physical devices and processes in the field, such as the following:

  • Supervisory Control and Data Acquisition (SCADA) Systems โ€” SCADA systems collect real-time data from remote sensors and equipment, allowing operators to centrally monitor and control various operations such as monitoring water pressure, flow rates, and reservoir levels in water utilities, or managing electrical distribution grids.
  • Programmable Logic Controllers (PLCs) โ€” PLCs automate processes and machinery. In utilities, they control critical infrastructure such as pumps, valves and circuit breakers so they work safely and efficiently.

lnternet of Things (IoT) and Industrial Internet of Things (IIoT)

IoT and IIoT technologies are also being used in utilities to enhance operational efficiency, improve service reliability, and better manage resources. Examples of IoT and IIoT include:

  • Advanced Metering Infrastructure (AMI) โ€” AMI in utilities are used to poll smart meters for real-time data on electricity, water, and gas usage.
  • Automated Control Systems (ACS) โ€” ACS in utilities automate various control systems โ€” from managing the operation of substations to controlling water treatment processes.
  • Asset Monitoring โ€” In utilities, asset monitoring devices oversee the performance of critical infrastructure, such as transformers, pumps and pipelines.

As recently as a few years ago, we were not worried about cybersecurity for utilities because industrial control systems were isolated by design,” said Frank Ferdowsian, Partner & Managing Director at UPSTACK. “In the last few years, the transition from closed systems to connected systems has provided additional exposure. OT and IoT make it easier to remotely monitor plants, but introduce risks. Utility organizations thought first about how these connected technologies could facilitate ease of access, but now theyโ€™re beginning to understand the risk of a bad actor getting into those controls and disrupting operations.”

Cyber threats on public utilities target OT, IoT and SCADA systems

IoT solutions, OT and SCADA systems are prime targets for cyberattacks due to their critical roles in managing and controlling utility operations. As a result, public utilities are increasingly impacted by a variety of cyberthreats, such as:

  • Ransomware โ€” Ransomware can stifle utility operations by locking access to critical systems and data until the utility pays the ransom.
  • Phishing โ€” These deceptive emails or messages trick employees into revealing sensitive information or installing malware, opening the door to more severe breaches.
  • Advanced Persistent Threats (APTs) โ€” APTs are long-term stealth attacks where cybercriminals sneak into a network and stay hidden, stealing data or disrupting operations over time.

Cybercriminals have a few objectives in mind, such as:

  • Disrupting operations โ€” They aim to create chaos and operational downtime by interfering with critical systems.
  • Extorting money โ€” They demand payments in exchange for restoring access to systems or data.
  • Stealing sensitive dataโ€” They’re after confidential information, like operational data, customer details, and strategic plans, which they can use for further attacks or sell on the black market.

As cybercriminals become more sophisticated and threats become more frequent, the need for strong cybersecurity measures is becoming even more critical. er hygiene and plan ahead for potential interruptions. Communicate clearly and openly the risks, expectations, plans, and response procedures put in place, and allow your team to grow stronger with that knowledge.

Public utilities must prepare for cyber threats to the grid and water systems

Cyberattacks are always evolving and finding new ways to bypass security defenses. Utilities must stay on their toes and constantly update their security strategies to stay ahead of ever-changing threats.

However, preparedness varies widely among public utilities. Some use effective cybersecurity frameworks, while others struggle with tight budgets, outdated infrastructure and limited cybersecurity skills.

One of the biggest challenges is lack of expertise โ€” not only on the public utilities side, says Ferdowsian, noting that few security providers have experience managing cybersecurity for OT and IoT environments.

“Unlike IT (e.g., desktops, laptops, servers), OT is talking a different language,” he says. “With IT, when there’s a threat, one immediate action is to isolate the compromised system from the network so it doesn’t infect other systems and impact larger operations. With OT and IoT, sometimes isolation is not an option. Quarantine can trigger additional risks to control systems they monitor or manage.”

For example, if a SCADA system has been compromised, it can’t just shut down, he says, explaining that the risk may be greater in doing so than from the cyberattack. “The automation typically done to secure IT systems doesn’t necessarily translate to OT,” Ferdowsian says. “Instead, we have to alert staff to respond manually.”

The good news is that cybersecurity preparedness among public utilities is improving. According to Morningstar Sustainalytics research, in 2023, companies with weak management dropped to 27 percent from 38 percent in 2022. Companies with adequate management increased to 30 percent, up from 19 percent in 2022.

“In the last two to three years, there’s been greater awareness, coordination and documentation among various entities from state governments to national cybersecurity advisory agencies,” says Ferdowsian. “They have put guidelines and checklists together to advise municipalities and various utilities โ€“ electric, water, gas โ€“ on cybersecurity.”

A few cases in point:

Effective preparedness involves regular risk assessments, investment in modern security technologies, and comprehensive incident response planning.

Public utilities should conduct cybersecurity risk assessments

With the rise in cyberthreats targeting critical infrastructure, public utilities should conduct cybersecurity risk assessments. There isn’t a uniform federal law mandating cybersecurity assessments for U.S. public utilities, but some states are taking it upon themselves to implement regulations. The Tennessee legislature passed a bill in its 2021-22 session requiring water and wastewater utilities to develop a cybersecurity plan to be updated every two years.

“A number of states require public utilities to undergo third-party vulnerability assessments,” says Ferdowsian. UPSTACK facilitates those assessments to identify risk and also provide remediation. We create partnerships between operators and utilities to meet the state requirements.”

Public utilities must shore up Security solutions

To protect IoT, OT and SCADA systems, public utilities should consider the following measures:

  • Regular software and firmware updates โ€” Ensure all systems are regularly updated and patched to protect against known vulnerabilities.
  • Strong access controls โ€” Implement strict controls to prevent unauthorized entry.
  • Network segmentation โ€” Separate OT and IT networks to limit lateral movement by attackers and contain potential breaches.
  • Advanced monitoring and detection โ€” Use advanced monitoring tools and intrusion detection systems (IDS) to promptly identify and respond to threats.
  • Security awareness training โ€” Educate employees on cybersecurity best practices and how to recognize potential threats.
  • Business Continuity solutions โ€” Implement robust backup and recovery solutions to restore operations quickly after an attack.

Public utilities must adopt best practices for incident response & recovery

In addition to prevention strategies, utilities must be prepared with a response and recovery plan, including:

  • Comprehensive Incident Response Plan โ€” Develop and maintain a detailed Incident Response Plan that outlines specific roles, responsibilities, and procedures.
  • Regular training and drills โ€” Conduct regular training and simulation exercises to prepare staff for real-world incidents.
  • Post-incident analysis โ€” Perform thorough post-incident reviews to identify lessons learned and improve future response efforts.

Where can public utilities get expert assistance with cybersecurity?

As cyber threats targeting IoT, OT, and SCADA systems evolve, public utilities must improve cybersecurity. They must understand their vulnerabilities, be prepared, and implement effective security solutions to protect their critical infrastructure. That’s easier said than done since many public utilities don’t have cybersecurity experts on staff and are looking for guidance.

UPSTACK understands the threats to public utilities, the recommended cybersecurity frameworks and the providers that follow those frameworks,” says Ferdowsian. “We have been working closely with utilities to do three things: understand what systems they have, ascertain the risks to those systems and find partnerships with managed security service providers to protect them.”

By investing in advanced security technologies and promoting cybersecurity awareness, public utilities can safeguard their operations and deliver essential services reliably to their communities.

Share

Discover More From UPSTACK

Colocation & Hybrid Cloud

Internet Connectivity

Wide-Area Networking

Cloud & Network Security

Customer Experience

Related Articles

Digital transformation is ever-evolvingโ€”so are we.

Get the latest updates, insights, and innovations delivered to your inbox.