|
View this as a web page
The Washington State Department of Health Office of Drinking Water is committed to sharing information on cybersecurity threats as we learn of them. We recently received an alert from the U.S. Environmental Protection Agency (EPA), and Cybersecurity and Infrastructure Security Agency (CISA) of an uptick in national cyber security incidents at public water systems across the U.S. Please take time to read through the mitigation measures included below to avoid Operational Technology (OT) impacts to you and your customers.
This press release from the Cybersecurity and Infrastructure Security Agency (CISA), "CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs," highlights current cybersecurity threats and ways to protect your OT against exposed programmable logic controllers (PLCs), and includes key actions to reduce vulnerabilities and defend against threat actors seeking to exploit your systems.
Mitigation Measures
- Use strong passwords.
- Do not expose any system components directly to the public facing internet, use a private network, firewall, VPN, etc.
- Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT team members and/or integrators to perform this action.
- Install PLCs consistent with manufacturers' guidelines and security best practices.
- Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.
- For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.
Organizations can report cyber incidents 24/7 to Contact@mail.cisa.dhs.gov or by calling 1-844-Say-CISA (1-844-729-2472). CISA Region 10 CISARegion10@cisa.dhs.gov.
Organizations are encouraged to report cyber incidents to the Washington State Department of Health, Office of Drinking Water, our afterhours number for utility personnel experiencing emergencies is 1-877-481-4901. During normal business hours please consult our contact list Drinking Water Contacts and Office Location.
Resources
Specific Manufacturers' Contact Information
- Rockwell Automation: Contact the Rockwell Automation Product Security Incident Response Team (PSIRT) at PSIRT@rockwellautomation.com for questions regarding this guidance, or to report cyber incidents related to Rockwell Automation products.
- Schneider Electric: Contact the Schneider Electric Corporate Product Cyber Emergency Response Team (CPCERT) at cpcert@se.com for questions regarding this guidance, or to report cyber incidents related to Schneider Electric products.
- Siemens: Contact Siemens ProductCERT at productcert@siemens.com for questions regarding this guidance, or to report cyber incidents and vulnerabilities related to Siemens products.
|