A policy response to cyberattacks against key US infrastructure

A policy response to cyberattacks against key US infrastructure

The war with Iran has come for U.S. infrastructure. A cyberattack last month affected more than 30 Minnesota water systems and 11 other states, according to a government report. There are no reports of water contamination or human harm, but some utilities have reported pressure loss and flooding. It was sufficiently severe that several municipal utilities disabled digital controls and switched to manual operations. Intelligence agencies and federal authorities believe that Iran-backed hackers are behind the attack, and a hacking group closely tied to Iran has claimed responsibility.There is broad agreement that U.S. water utility security controls are outdated and cannot keep pace with rapidly evolving cyber threats. A recent inspection by the Environmental Protection Agency revealed that roughly 70% of U.S. water systems failed to meet basic cybersecurity standards. Specific identified problems include unchanged default passwords, reliance on factory-set credentials that hackers can quickly find online, single shared logins, former employee accounts that remain active, and failure to immediately cut off network access upon threat detection, among others.Local water utilities struggle to address such threats alone, given their small scale and limited resources. The Bureau of Labor Statistics estimates there are about 51,700 water and wastewater treatment plant and system operators in the United States. More than half have only one or two employees, while roughly 85% have three or fewer staff members, who of necessity must perform a variety of tasks. Many are also rural, rely on a single part-time certified operator, and are small enough to be viewed as “micro-systems.” Meanwhile, many municipal governments face serious budget shortfalls. With pandemic-era federal relief funds expiring, sluggish revenue growth, and rising operational costs, adequately confronting global cyber threats might seem like a hopeless task.Fortunately, a set of new policy approaches can help bring local governments’ cyber systems up to cutting-edge standards with minimal cash outlay. First, the municipalities that own most U.S. water systems must contract with private-sector partners with the technology, capital, and expertise to confront evolving cybersecurity threats. Such contracts not only include bringing security systems up to global standards, but also longer-term maintenance to ensure system protections remain cutting-edge.Owners must also be experts in concepts such as future-proofing, which means drafting a contract that recognizes risks will arise in the future and clearly assigns the risk to one party or the other. A future-proofed cyber contract can put the risk of not adopting the latest cyber protections on a private partner who is better positioned to address it.Second, municipalities must seek opportunities to bundle cyber contracts with other similarly situated asset owners. Many municipalities are likely to face similar technological challenges, suggesting that dozens or even hundreds of systems can band together to secure services at scale.Larger-scale contracts can be better designed and will attract a larger set of skilled global bidders, making them more competitive. The Pennsylvania Rapid Bridge Replacement program, which bundled together and successfully replaced 558 structurally deficient, mostly rural bridges across the state, serves as a model. What would have taken years to bid out individually was consolidated into a $1.12 billion public-private partnership (P3) to replace Pennsylvania’s bridges much faster.Third, municipalities must search for value-capture arrangements to help fund enhanced cybersecurity. Many U.S. water systems are old and inefficient, but therein lies a massive, untapped opportunity. For example, many old water systems rely on “settling ponds,” which are large, man-made pools used to remove solid waste from water and wastewater. The ponds release natural gas, which is partly methane, that can be captured in a modern digester and used to make electricity. Such a value-capture deal, conducted with a private-sector partner, converts waste gas into electricity while generating a new revenue stream for the municipality. The cost of installing and maintaining the technology can be fully covered (or offset) by sharing that new revenue, which can be used to enhance cybersecurity. Given the ongoing revolution in infrastructure technology, other examples abound.IRAN IS BUYING GEORGIA, AND TRUMP IS ABOUT TO SANCTION THE WRONG PEOPLEThe thousands of tiny public entities that own and operate U.S. water systems may not have the expertise necessary to face cyber threats alone or to properly execute such innovative public-private arrangements. Fortunately, a new type of quasi-public entity, known globally as a public-private partnership unit, or “PPP Unit,” can help numerous municipalities to execute all three of the above steps at scale.The United States is lucky that the damage from this wave of cyberattacks was minimal. It may not be so fortunate the next time, leaving millions of Americans vulnerable to an attack on their most basic resource: water. It’s past due time to adopt new policy approaches that will protect our critical water systems from bad global actors.R. Richard Geddes is a Nonresident Senior Fellow at the American Enterprise Institute, a professor in Cornell’s Jeb E. Brooks School of Public Policy and the Founding Director of the Brooks Center for Infrastructure Policy. His research focuses on infrastructure technology and policy.

Original Source

Read the full article at Washingtonexaminer →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.