Pages

Showing posts with label CISA. Show all posts
Showing posts with label CISA. Show all posts

Wednesday, August 6, 2025

Cybersecurity: NIST's Updated Password Guidelines & Sector Resources

The water and wastewater sectors are essential to daily life, and safeguarding them from cyber threats is crucial. The newly updated National Institute of Standards and Technology’s (NIST) password guidelines, along with the range of resources offered by the EPA and CISA, provide a strong foundation for improving cybersecurity across the industry. We encourage you and your colleagues to implement these new password guidelines and general cyber hygiene. Here’s a breakdown of the key updates and additional cybersecurity resources that can help strengthen your system's defenses.

NIST’s Updated Password Guidelines: What’s New?

In September 2024, NIST introduced new password management guidelines aimed at improving both security and user experience. The changes reflect a shift towards longer, more memorable passwords, and away from overly complex password requirements.

Key Updates:

  1. Password Length: NIST now recommends using passwords or passphrases that are at least 15 characters long. The focus has shifted from enforcing complexity (e.g., mixing uppercase, numbers, and symbols) to prioritizing longer passwords that are easier to remember.
  2. Password Composition: Gone are the days of forcing users to include specific character types. The new focus is on allowing longer, memorable passwords, which reduces the chances of people creating easily guessable passwords. 
  3. Fewer Password Changes: Unless there’s evidence of a security breach, mandatory password changes are no longer required. This policy change helps users avoid creating predictable patterns due to frequent password resets.
  4. Password Managers: NIST now strongly encourages the use of password manager software, which can generate and store strong, unique passwords for each account. It’s a vital tool to prevent the risk of password reuse across different accounts.
  5. Avoid Password Hints & Security Questions: To minimize the risk of social engineering attacks, NIST advises against using password hints or security questions that could easily be guessed.
  6. Multi-Factor Authentication (MFA): MFA is a non-negotiable security measure. By requiring more than just a password to access sensitive systems, MFA adds an additional layer of protection.

These updated guidelines emphasize simplicity and practicality, reducing user frustration while enhancing security. In an industry like water and wastewater, where systems are critical to public health, these updates offer a crucial balance of usability and protection.

Additional Cybersecurity Resources for the Water & Wastewater Sector

Alongside these password updates, there are also significant resources available to bolster cybersecurity across water and wastewater systems.

On March 13, 2025, the EPA will host a cybersecurity briefing for the water and wastewater sector. The session will cover unclassified threats, along with available funding and technical resources from the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA). Here are a few resources to explore:

By staying informed and adopting the latest cybersecurity practices, water and wastewater utilities can ensure a secure future, protecting critical infrastructure from evolving threats.

➽ Kyra Gregory, Drinking Water Training Specialists 

Wednesday, July 16, 2025

Coordination with Public Water Systems on SCADA Vulnerabilities


In June 2025, the EPA’s Water Infrastructure and Cyber Resilience Division (WICRD) notified the Water Quality Control Division (WQCD) that they had identified potential cybersecurity vulnerabilities at four Colorado public water systems (PWSs). While scanning for vulnerable devices, EPA identified the specific TCP/IP addresses of four BIF3800 SCADA Control Systems that were internet-exposed and could potentially allow a remote user to access the device and disrupt the utility’s operations. WQCD Field Services immediately reached out to the four water systems to notify them of the potential vulnerability so they could take action to protect their systems. 

Many utilities installed SCADA BIF3800 units as early as the 1990s and were controlling ancillary processes in the distribution systems of the water systems. There was a common thought that hackers would not be interested in equipment that is so old, or that the older control systems would be less vulnerable to cyber attacks. Unfortunately, hackers can exploit any internet-exposed interfaces like these. The EPA and the Cybersecurity and Infrastructure Security Agency (CISA) recently published this joint fact sheet, which highlights the risks posed by internet-exposed Human Machine Interfaces (HMIs), including how hackers can find and exploit HMIs with cybersecurity weaknesses easily. The EPA and CISA fact sheet includes recommended mitigations to secure HMIs, including:

  • Conduct an inventory of all internet-exposed devices.
  • If possible, disconnect HMIs and all other accessible and unprotected systems from the public-facing internet.
  • If it is not possible to disconnect the device, secure it by creating a username and a strong password to prevent a threat actor from easily viewing and accessing the device. Change factory default passwords.

Thankfully, the four water systems quickly responded to remove the exposure and did not experience any cyber events due to this issue. The CISA team in Colorado also reached out to the water systems to provide technical support to mitigate the vulnerabilities.  

WQCD encourages water systems to continue to evaluate and protect their systems against cyber threats. Utilities that need support can contact the Colorado CISA Team, including Edward (Charlie) Marmon at edward.marmon@cisa.dhs.gov  or Kindra Brewer at kindra.brewer@cisa.dhs.gov, and the EPA’s Cybersecurity Technical Assistance Help Desk is also available for assistance. The WQCD Drinking Water Security Response Toolbox is a one-stop shop for security resources. 

➽ Heather Young, PE, CWP, Field Services Section Manager

➽ Naheem Noah, Field Services Section

Wednesday, July 9, 2025

Cyber Alert: Global Conflict Potential to Impact US Critical Infrastructure

EPA Cyber Alert: Iran Conflict is Increasing the Likelihood of Low-Level Cyberattacks Against US Networks

Note: The Water Quality Control Division is posting the following information out in partnership with the Environmental Protection Agency (EPA) .

The U.S. EPA is issuing this alert to inform water and wastewater system owners and operators of the need for increased vigilance for potential cyber activity in the United States due to the current geopolitical environment. The U.S. Department of Homeland Security (DHS) published a National Terrorism Advisory System Bulletin, indicating that low-level cyberattacks against U.S. networks by pro-Iranian hacktivists are likely, and cyber actors affiliated with the Iranian Government may conduct attacks against U.S. networks. Additionally, the Cybersecurity and Infrastructure Security Agency (CISA) published a fact sheet warning that Iranian-affiliated cyber actors may target U.S. devices and networks for near-term cyber operations.

Iranian-affiliated cyber actors have demonstrated the ability to exploit operational technology (OT) devices at U.S. water and wastewater systems, forcing many systems to revert to manual operations and resulting in operational impacts.

All drinking water and wastewater systems are strongly encouraged to implement the following mitigations immediately to enhance resilience against low-level cyberattacks:

  • Reduce OT Exposure to the Public-Facing Internet
  • Replace All Default Passwords on OT Devices with Strong, Unique Passwords
  • Implement Multifactor Authentication for Remote Access to OT Devices

In addition to these immediate actions, drinking water and wastewater systems are encouraged to adopt the actions outlined in the CISA, EPA, and FBI Top Cyber Actions for Securing Water Systems Fact Sheet to further reduce cyber risk and improve resilience against malicious cyber activity.

The U.S. EPA requests that the Water Sector Coordinating Council (WSCC)/Government

Coordinating Council (GCC) review this advisory and pass it along to all water & wastewater entities that may be susceptible to this threat. Additionally, we encourage the EPA Regions share the advisory with the state primacy agencies and direct implementation utilities.

Water and wastewater system owners and operators should direct their IT/OT system

administrators to review this alert for further use and implementation. If you rely on third party vendors for technology support, then you are encouraged to contact them to confirm their awareness of this threat. Organizations are encouraged to report information concerning suspicious or criminal activity to FBI Internet Crime Complaint Center (IC3) at IC3.gov or to CISA via CISA’s Incident Reporting System. If you have questions about any of the information contained in this document, please contact the Water Infrastructure and Cyber Resilience Division, Cybersecurity Branch at watercyberta@epa.gov.

Stay Informed

If you are interested in subscribing to receive security alert notifications immediately upon release, please sign up using this form and select the topics that interest you. This topic is General - Security updates - Water and wastewater systems.

➽ WQCD Security Workgroup