White House Has a Half-Baked Plan to Improve Public Water System Security
Actually, for the White House, half-baked is a pretty high bar. Here is what is going on and what they are doing.
You may remember that a number of public water supply systems were recently hacked. Initially, it was reported that a half dozen systems in Minnesota were attacked. The president blew that off with a disparaging comment about the state. Days later they were forced to admit that over a hundred public water systems, all over the country, were attacked.
A couple of years ago the EPA tried to improve the cybersecurity of public water supplies, but the industry said they were not interested in improving the security and sued the government and won.
Now that a hundred systems – out of thousands – were recently attacked, maybe, possibly, the White House may get a more favorable response. But, given the plan is half baked, maybe not.
Here is the government’s plan.
The government decided to try a 6 month/180 day pilot in cooperation with Texas. Why Texas? I don’t know. Maybe because it is a red state? Not sure. Anyway, the White House coordinated with a bunch of tech and service firms to go into some of the water supplies – I assume this is voluntary, but maybe not – and first do a risk assessment. How bad is their security?
Next, these companies will provide software and people to install and maintain the software. The cost will be born by the government. Texas Cyber Command will help with the monitoring. This could be why they picked Texas – because TXCC agreed to provide the manpower.
After 180 days they should have some decent data – how bad were things, what did it take to fix it, what could they not fix, what will it take to maintain this (continue to pay for the software and the people).
I assume the companies that are participating are assuming that this will be good PR and once the software is installed, they are hoping that someone (the Feds, the state, the utility customers?) will pay for it after the 180 day free trial is over.
And this is why the plan is half baked. To be fair, they know it is half baked, but the need to collect the data to understand how much it is going to cost on an annual basis to maintain what they did so that they can try to figure out how to fund it going forward.
MAYBE, on day 181, Microsoft or CrowdStrike is not going to shut off the software, but I seriously doubt they will leave it running for free forever. And the labor to maintain and monitor it; for 180 days Texas Cyber Command is picking up the bill. Do they have the money to keep doing this? Absolutely not.
Someone described this problem as it is free like puppies, not free like beer.
That is why I call the plan half-baked. Assuming it takes most of the six months to get this completed at the more than 7,000 public water systems. In fact, it is likely COMPLETELY IMPOSSIBLE to get this completed in six months. I don’t know how many they can do in six months. Maybe a few dozen? Maybe a few hundred. I don’t they can do thousands. But what do I know? That means that some percentage will get done in six months, the rest won’t and on day 181 the work they did complete self destructs.
Also, don’t forget that water systems are totally an “Internet of Things” play. All sorts of control systems. Many decades old and many sitting in a box pretty much in the middle of nowhere. How to you protect them?
This is the way the government works. Half-baked. The biggest concern for me is what happens on day 181 and forward. Otherwise, it is just a political stunt. Unfortunately, we really don’t know what is going to happen.
Credit: Infosecurity Magazine and Data Breach Today
