Today, CISA, the Environmental Protection Agency (EPA), and the Federal Bureau of Investigation (FBI) updated the joint fact sheet Top Cyber Actions for Securing Water Systems. This update includes additional resources—from American Water Works Association, the WaterISAC, and MS-ISAC—to support water systems in defending against from malicious cyber activity.Â

The fact sheet outlines the following practical actions Water and Wastewater Systems (WWS) Sector entities can take to better protect water systems from malicious cyber activity and provides actionable guidance to implement concurrently:

Reduce Exposure to the Public-Facing Internet
Conduct Regular Cybersecurity Assessments
Change Default Passwords Immediately
Conduct an Inventory of Operational Technology/Information Technology Assets
Develop and Exercise Cybersecurity Incident Response and Recovery Plans
Backup OT/IT Systems
Reduce Exposure to Vulnerabilities
Conduct Cybersecurity Awareness Training

CISA, EPA, and FBI urge all WWS Sector and critical infrastructure organizations to review the fact sheet and implement the actions to improve resilience to cyber threat activity. Organizations can visit cisa.gov/water for additional sector tools, information, and resources.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

CISA Adds Two Known Exploited Vulnerabilities to Catalog

February 15, 2024 0 Comments 0 tags

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2020-3259 Cisco ASA and FTD Information Disclosure Vulnerability CVE-2024-21410 Microsoft Exchange Server Privilege

Report: Manufacturing bears the brunt of industrial ransomware

February 20, 2024 0 Comments 0 tags

Manufacturing continues to be the industrial sector hardest hit by ransomware, according to a new report by industrial cybersecurity firm Dragos. The firm’s year-in-review reported more than 900 ransomware incidents

CISA Releases Two Industrial Control Systems Advisories

February 29, 2024 0 Comments 0 tags

CISA released two Industrial Control Systems (ICS) advisories on February 29, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-060-01 Delta Electronics CNCSoft-B