Blog
Multi-State Cyberattacks Are a Wake-Up Call for Every Organization
Christopher Souza | CEO
Cybersecurity incidents often make headlines because of ransomware or stolen data, but the coordinated attacks reported in late July against water systems in multiple U.S. states were different: they targeted operational technology responsible for keeping essential water services running.
Minnesota drew the earliest public attention after officials said hackers targeted about 30 water systems there on July 26 and 27. But the campaign was not limited to Minnesota. CNN reported related cyber incidents in roughly six states, with Wisconsin also detecting malicious activity at water facilities. Federal agencies including CISA, the FBI and the EPA worked with state and local officials to secure affected systems; no incidents of water contamination had been reported, although some utilities issued boil-water notices or shifted to manual operations.
This should not be viewed as a problem limited to water utilities or municipalities as it is another warning that cybercriminals, hacktivists, and nation-state actors are increasingly targeting the technology that businesses and communities depend on to maintain operations.
The Objective Was Disruption, Not Simply Data Theft
The attackers targeted operational technology, notably the systems that control physical equipment such as pumps, wells, treatment systems and water pressure. CISA subsequently warned that threat actors targeting internet-accessible programmable logic controllers having changed passwords, modified network settings and disconnected equipment from operator control that turn unauthorized digital access into physical disruption. (CISA)
The same risk exists outside the water sector as manufacturers depend on similar production equipment and industrial control systems. Healthcare organizations rely on connected medical and building systems, professional-services businesses depend on cloud platforms, identity systems and remote access and defense contractors rely on interconnected IT, manufacturing and supply-chain environments.
For many organizations, the most damaging consequence of a cyberattack may not be lost data but also included the negative impacts of halted production, inaccessible applications, interrupted customer service, missed deliveries or an inability to operate safely.
Could These Attacks Have Been Prevented?
No cybersecurity provider can guarantee complete protection. However, many successful attacks continue to exploit preventable weaknesses such as internet-exposed equipment, default credentials, inadequate network segmentation, unsupported systems and poorly controlled remote access.
Organizations should prioritize:
- Exposure reduction: Remove unnecessary internet access to control systems, management interfaces and remote administration tools.
- Identity security: Require multifactor authentication for remote, administrative and cloud access while eliminating shared or default accounts.
- Continuous monitoring: Use EDR, MDR and SIEM capabilities to identify suspicious behavior across endpoints, networks, identities and cloud environments.
- Network segmentation: Separate critical systems, operational technology, servers, users and guest networks to restrict lateral movement.
- Vulnerability management: Regularly scan, patch and securely configure operating systems, applications, firewalls and network-connected devices.
- Resilient recovery: Maintain protected backups, test restoration procedures and preserve the ability to operate critical processes manually.
- Incident preparedness: Develop and test an incident-response plan that identifies responsibilities, communication procedures and outside response partners.
- Employee and vendor security: Train employees and tightly control third-party access to sensitive or operational systems.
What Defense Contractors Should Learn from These Attacks
The timing of these multi-state water-system attacks is especially relevant for the Defense Industrial Base.
On July 13, the Department announced the suspension of the transition to CMMC Phase II and initiated a 60-day review of the program. However, Phase I self-assessment requirements remain in place, and contractors are still required to comply with NIST SP 800-171 and safeguard covered defense information under DFARS 252.204-7012. (U.S. Department of War)
A delay in a certification timetable is not a delay in adversary activity.
Defense contractors and subcontractors remain attractive targets because they possess Controlled Unclassified Information, intellectual property, technical specifications and information about military programs and supply chains. Manufacturers supporting defense programs may also have production equipment and operational technology that could be disrupted even when an attacker cannot reach CUI directly.
CMMC readiness should therefore be treated as an operational-security initiative. Organizations should continue:
- Identifying where FCI and CUI are stored, processed and transmitted.
- Defining and controlling their CMMC assessment boundary.
- Implementing the 110 NIST SP 800-171 security requirements.
- Maintaining an accurate System Security Plan and POA&M.
- Validating that security controls are operating effectively.
- Evaluating MSPs, cloud providers and other external service providers with access to regulated systems or information.
- Preserving the logs and evidence needed to demonstrate compliance.
The purpose is not merely to pass an assessment. It is to prevent sensitive information, critical operations and national-security supply chains from being compromised.
What This Means for Organizations Considering a Managed Services Provider (MSP)
Cybersecurity starts with the foundation of well-managed IT. A capable MSP should do more than respond when technology breaks. It should reduce the weaknesses attackers commonly exploit.
That includes:
- Maintaining an accurate inventory of devices, applications and network equipment.
- Keeping operating systems and third-party applications patched.
- Managing identities, privileged accounts and employee access.
- Securing remote connectivity and third-party access.
- Monitoring the health and availability of critical systems.
- Maintaining tested backups and recovery procedures.
- Identifying and replacing unsupported or improperly configured technology.
Unknown assets, shared accounts, unpatched systems and inconsistent IT practices create unnecessary risk and strong cybersecurity requires disciplined IT management.
What This Means for Organizations Considering a Managed Security Service Provider (MSSP)
Prevention alone is no longer enough and organizations also need the ability to detect, investigate and contain threats before they disrupt operations. A capable MSSP should provide layered protection through capabilities such as EDR, MDR, SIEM, vulnerability management, security monitoring, threat investigation and incident-response support. This is increasingly important because attackers do not always rely on obvious malware and now more commonly exploit compromised credentials, legitimate remote-management tools and trusted third-party access that allow malicious activity to blend into normal operations. Without continuous monitoring across endpoints, identities, networks and cloud environments, an attack may go undetected until the damage is already underway.
How TSI Can Help
As an MSP, MSSP and CMMC Registered Provider Organization, TSI helps organizations manage IT, cybersecurity and compliance as one coordinated strategy. TSI can help your organization:
- Assess its current IT and cybersecurity posture and identify critical gaps.
- Strengthen endpoint, identity, network and cloud security.
- Implement continuous monitoring and managed threat detection.
- Improve vulnerability, patch and configuration management.
- Strengthen backup, disaster recovery and incident-response capabilities.
- Define CMMC scope and implement NIST SP 800-171 requirements.
- Develop the SSP, POA&M, policies and supporting evidence required for CMMC readiness.
- Provide ongoing vCISO guidance and security-program management.
To learn more about how TSI can help manage your IT environment, improve your cybersecurity posture and address your CMMC objectives, please visit the links below:Â
Boston IT Support Services – TSI Support
Cyber Security Services – TSI Support
TSI’s NIST SP 800-171 Solutions – TSI Support
Don’t Wait for an Attack to Expose the Gaps
The multi-state water-system attacks first reported publicly in Minnesota demonstrate how quickly a cybersecurity incident can become an operational crisis. Do not wait for a breach, outage, customer requirement or compliance deadline to determine whether your organization is adequately protected.
If you are evaluating your current MSP or MSSP, preparing for CMMC, or simply unsure whether your IT and cybersecurity environment could withstand a serious attack, contact TSI today to schedule a cybersecurity and IT readiness discussion.
We can help you identify where your greatest risks exist, determine what should be addressed first and develop a practical strategy to strengthen your organization before an attacker forces you to.
About Technical Support International
TSI is 37-year old cybersecurity (MSSP) and IT support (MSP) company specializing in helping DIB organizations address their NIST 800-171 and CMMC compliance obligations. As a CMMC-AB Registered Provider Organization (RPO), TSI offers a complete NIST 800-171 and CMMC support solution to help guide our clients toward a successful certification audit and provide the assurance that they’re adhering to these expansive compliance requirements.
Categories
- Backup & Disaster Recovery
- Business Operations
- Case Studies
- Cloud Services
- Cyber Security
- Employee Spotlight
- Finance & Budgeting
- Glossary Term
- Governance & IT Compliance
- Managed Services
- Mobile Device Management
- Network Infrastructure
- NIST 800-171 & CMMC 2.0
- PCI
- Podcast
- Project Management
- TSI
- Uncategorized
- vCIO
Cyber Security Policy Starter Kit:
10 Critical Policies That Every Company Should Have in Place
