> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> WaterISAC reckons with range of threats after summer of cyberattacks

[SOURCE] CyberScoop [AUTHOR: Tim Starks] [DATE: 30/09/2026 10:00] [LANGUAGE: EN]
The computers that automate water treatment systems across the country were built for durability, not for an internet-connected world. Many still accomplish their fundamental function, but as cyberattacks on the sector mounted this summer, water industry officials say those aging systems, especially internet-exposed operational technology and programmable logic controllers, remain among the easiest ways for adversaries to break in. Tom Dobbins, executive director of the Water Information Sharing and Analysis Center or WaterISAC, told CyberScoop the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure connections through integrators and poor cyber hygiene at smaller utilities, which have pushed the center to make threat sharing faster across the sector. “We have been under attack, and our enemies, the threat actors, are stepping up their activity as the U.S. is involved in a number of conflicts around the world,” Dobbins said. That includes not only threats from Iran, the nation the U.S. government reportedly believes is behind this summer’s water facility attacks, but also China and Russia, he said. WaterISAC is announcing a partnership with Cyware Wednesday to use its threat intelligence platform, selecting the company in part because of its existing relationships with other industry ISACs, Dobbins said. The ISAC already has a partnership with the National Rural Water Association to serve 20,000 of the water sector’s smallest utilities, and Dobbins said Cyware would help its analysts further. It’s a sector that faces myriad challenges, seen by many as further behind on protecting its systems due to financial and technological constraints. “OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible to the internet,” Dobbins said. Furthermore, programmable logic controllers (PLCs) are “obviously” a “vulnerability point,” he said.  Those two vulnerabilities were the ones most commonly linked to this summer’s attacks. Across the sector, PLCs have been the “main point of entry” for hackers, in part because they date back to a “simpler, gentler time,” Dobbins said. “A lot of the equipment was developed pre-cyber threats and activities,” he said. “The equipment, it’s still valuable, it still is operational, so there’s not a huge reason for or incentive for utilities to upgrade it.” President Donald Trump has disputed the notion that Iran was behind this summer’s attacks, despite alerts from the Cybersecurity and Infrastructure Security Agency. “Let’s put it this way: I saw a recent CISA release that pointed to Iran as threat actors, and I know that the president kind of implied that it was not Iran, but I’ll say that CISA maybe is more expert in this area than maybe the president,” Dobbins said. “The president may not have been fully briefed when he made that comment.” But CISA has also warned of potential threats from Russia and China, he said. Two other sources of vulnerability for the sector are external — integrators — and internal — employees. “If those integrators are working and they have a connection into an OT system that’s not managed discretely, then a threat actor can come in through an integrator and get into a system,” he said.  Then there’s someone “who’s actually a good employee who’s tried to do the right thing and opens an email that has a malicious link in it, so they become subject to a phishing attack,” Dobbins said. At smaller utilities, it can be difficult to keep up with basic cyber hygiene as well, he said: changing passwords, implementing multifactor authentication. One way that Cyware might be able to help is by leveraging its relationships with other ISACs, said Tom Stockmeyer, managing director of government and critical infrastructure at Cyware. “We’re thrilled to add water to the portfolio and start enabling cross-sector sharing,” he said. The post WaterISAC reckons with range of threats after summer of cyberattacks appeared first on CyberScoop.
[messages.read_original_source] →