Showing posts with label Water Treatment Security. Show all posts
Showing posts with label Water Treatment Security. Show all posts

Tuesday, July 10, 2012

DHS Inspects Water Plant Control System


There is an interesting article on TheDailyMail.net about a recent DHS inspection of a water treatment facility in a small town in New York. The article claims that “the Department of Homeland Security is requiring the Village of Athens to replace the computers at the water filtration plant to make them less vulnerable to potential hacking of the computer system”. It seems that there is currently just a single computer controlling the drinking water treatment system and supporting the administrative office for the system.

Now, I am absolutely sure that whoever came through to do this inspection it wasn’t anyone from the US Department of Homeland Security. DHS has no authority over security at water treatment plants; that authority has been loosely given to the US Environmental Protection Agency. Even the EPA wouldn’t be concerned with the Athens water treatment facility because it serves less than 3,500 customers (total population of Athens, NY is 3991 according to Wikipedia with only 1600 households which would equate to less than 2,000 customers).

I suppose that it could be a New York State agency making this inspection, but the appropriate agency in NY is the Division of Homeland Security and Emergency Services (DHSES). Even so, this water system is so small that I doubt that even they would be terribly involved in looking at the cybersecurity of the installation. There are certainly larger, more viable targets in the State of New York that need attention.

It is almost certainly a good idea to have the administrative functions of the water authority and the control system for the treatment plant on separate networks. And that is certainly hard to do when the network consists of a single computer. Having said that, it appears that, in this case at least, those security measures are beyond the budget of this system; they only have money for one additional computer.

On a closing note the article explains:

“Once the new system is in place, Homeland Security officials will come in and monitor the system for free to ensure it meets current security needs.”

That cinches the case, it wasn’t DHS involved in this operation, nor DHSES. No government agency would spend that kind of time on a small, low risk water system like this.

Thursday, February 18, 2010

Water Security Breach

There is an interesting article over on Dispatch.com (Columbus, OH Dispatch) about a recent security breach at a local water treatment plant. The interesting thing about this breach is that the police can only narrow the time of the breach down to a time period of about 15 DAYS long. The intruders cut through two fences and stole 200 feet of copper wire from an on-site electrical sub-station while avoiding detection by facility security cameras.

According to the article, a spokesman from the American Water Works Association downplayed the seriousness of the breach since the drinking water treatment equipment on the 148 acre facility was not involved in the break-in. Hopefully that spokesman is not involved in advising member utilities on security matters.

Purpose of Perimeter Security

There are three complimentary reasons for having perimeter fences. The most obvious is to keep people out of the facility. All security professionals realize that fences can not stop unauthorized access, just deter it. To paraphrase a common folk saying; fences are designed to keep honest people honest. They will not keep out people determined to enter the facility.

With this in mind, we can see that a well constructed perimeter fence serves the second purpose of classifying intruders. Anyone breaching that barrier is a threat to the facility. Without a good perimeter barrier intruders could be anything from a casual passerby to someone with nefarious intent.

The third purpose is to provide early warning of intruders. This will allow a security response team, either guard force or police, to interdict and apprehend the intruders before they get into the restricted area at the heart of the facility; in this case the actual water treatment works or drinking water distribution system.

In this case while the perimeter barrier performed the first two functions, the third was completely lacking. While it was not apparently the intent of these intruders, someone wishing to do damage to the water supply for 1.1 million people could have conducted an extensive on-site reconnaissance of the facility security and conducted a well rehearsed attack on the water treatment equipment in the 15 day period that the breach had not been detected.

Critical Resources 

One would assume that an electrical substation on the grounds of the water treatment facility would be there, at least in part, to supply power to the water treatment equipment used on site. As such we would have to consider this substation a critical resource for this facility. A successful attack on this substation would shut down the water treatment facility and the supply of drinking water to much of the city of Columbus, OH.

Now there was another perimeter fence around this substation, but it was also penetrated without detection. It is not clear if this fence was simply a safety device, installed to keep untrained personnel away from dangerous electrical currents, or if it was an actual security barrier. It obviously performed neither function well.

One would like to assume that the security barrier around the actual treatment and distribution equipment would provide more of a warning of penetration. Based on the news report on this incident, I really doubt it. Oh well, it doesn’t matter anyway; no one wants to do harm to this country, there is no terrorist threat, and no one has ever attacked a water treatment facility. Why do we need security anyway……

Tuesday, July 28, 2009

4th ISA WWAC Symposium

I’ve passed this by a couple of times because I did not see any mention of coverage of security measures, but the International Society of Automation (ISA) is holding their 4th annual Water & Wastewater and Automatic Controls (WWAC) Symposium next week in Orlando, FL. While none of the announcements that I have seen mentioned security for control systems, I finally did some digging and found a copy of the program brochure which does show two security sessions. Security Related sessions include:
A Practical Approach to Securing Your WTP/WWTP, Kevin Finnan, CSE-Semaphore SCADA Cyber Security Defense — In-depth Approach, Jim Redifer, Rockwell Automation
I must admit that I believe that these two 30-minute sessions hardly provide adequate treatment of control system security and am surprised that ISA is providing so little coverage of this important topic especially on critical infrastructure systems like water & wastewater treatment facilities. If professional organizations like ISA don’t take the lead in this area, our critical infrastructure is going to continue to become more at risk from catastrophic cyber attacks.
 
/* Use this with templates/template-twocol.html */