Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The water sector just got it’s wake-up call. Again.

By: Greg Otto
6 August 2026 at 06:00

Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency.

Nothing about these attacks required sophisticated methods. The attackers didn’t use zero-day exploits or novel malware. They found controllers exposed to the public internet, many of them so old that they stopped receiving security patches years ago. They logged in, changed IP addresses and passwords, and locked operators out of their own equipment. In at least one case, they modified the ladder logic controlling industrial equipment. These were not Hollywood-style hacks. The controllers sat exposed and undefended.

If this feels familiar, it should. In late 2023, attackers compromised controllers at water utilities across several states, including the widely reported incident in Aliquippa, Pennsylvania. The federal government issued guidance then, too. One of the crucial differences between then and now is that attackers have grown in ambition. They’ve moved from defacing screens to disrupting operations across dozens of systems at once, exploiting the fact that third-party integrators often deploy the same vulnerable configuration across many small utilities. 

The uncomfortable truth is that this was preventable. The reason it wasn’t stopped is more structural than technical. The United States has roughly 50,000 community water systems. Most are small, publicly funded, and run by operators whose primary job is keeping water safe and flowing. Cybersecurity ranks far below that, if it ranks at all. The devices in question are often a decade or more old and replacing them takes capital these utilities don’t have. Rules governing water cybersecurity remain mostly voluntary. Attackers understand these economics perfectly. We should too, yet these attacks keep happening.

 But inaction is a choice. The defenses that work here cost little and require no exotic technology. The FBI and EPA guidance is sound, and every water and wastewater organization should act on it this week, not later. Here’s how:

  • Get controllers off the public internet. No PLC should be reachable from the outside world. Remote access should go through a secure gateway that mediates, monitors, and logs every connection. That includes cellular modems, which are the overlooked entry point in nearly every audit.
  • Fix passwords. Default and shared credentials are still the most common way in. Strong, unique passwords are the cheapest security control available.
  • Restrict communication between devices. Firewall rules and access control lists should allow only expected communication between known control system devices. Block traffic from hosting providers and other sources that have no business touching a water plant.
  • Lock the logic. Keep physical and software key switches in the run position except during authorized updates. This prevents unauthorized changes to configuration and firmware.
  • Practice running manually. The utilities that survived these attacks best were the those that switched to manual operations quickly. That skill requires constant practice.
  • Verify, don’t assume. Nearly every utility believes its PLCs aren’t internet-exposed, right up until an inventory proves otherwise. You can’t protect what you can’t see. Most operators are surprised by what a complete asset inventory reveals: forgotten modems, integrator-installed remote access, devices nobody knew were still online.

Every attack like this follows the same pattern. Attackers change configurations, reset passwords, and modify project files. Every one of those actions creates a signal on the network before operations degrade. In this most recent case, one victim only noticed ladder logic discrepancies across multiple sites. Catching intrusions shouldn’t depend on a sharp-eyed engineer having a good day. Continuous monitoring of OT environments exists to turn those signals into alerts within minutes instead of days. That difference is the difference between an incident report and a boil-water notice.

Water systems have the least margin for error and, too often, the fewest resources to defend themselves. The FBI and EPA have told us plainly what’s happening and what to do about it. The attackers are betting we won’t follow through. For the third time in three years, they’re testing that bet.

Let’s finally prove them wrong.

The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop.

What the World Cup can teach us about cybersecurity resilience

By: Greg Otto
21 July 2026 at 06:00

With the World Cup now complete, its biggest cybersecurity story may be what didn’t happen. While no major public cyber disruption has been reported, that shouldn’t be mistaken for a lack of risk. 

In the run-up to the tournament, the FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement warning organizations and fans about fraudulent, spoofed websites impersonating the FIFA event – a reminder that the absence of a headline-grabbing breach doesn’t mean bad actors weren’t trying. In many ways, it’s evidence of the planning, coordination, and resilience required to keep an event of this scale running securely.

A global event like the World Cup depends on far more than what happens inside the stadium. It relies on local governments, venues, transportation systems, telecom providers, payment platforms, hotels, vendors, public safety agencies, and law enforcement, all working together. 

When I worked at the FBI, I saw how fast major events test teamwork across agencies, regions, and businesses. The World Cup offered that test at a scale few events can match.

Successful resilience is built months before kickoff

Successful major-event security depends on what happens long before there is a visible incident: trusted relationships, clear roles, shared intelligence and response plans. Planning becomes even more important when an event is not limited to a single city or venue.

In the past, event security consisted of guards, gates, and stadium perimeters. Those still matter, but they’re only part of the picture. Today, an event this big that brings millions of people together depends on many systems working in concert. No single organization owns the full risk picture, which means resilience depends on how well these groups can share information, coordinate response plans, and keep essential services operating under pressure. This means security can’t be planned around one perimeter. The real perimeter is the full event ecosystem.

Resilience starts much earlier, with planning across organizations that may not normally operate as one team. The real test for major events is whether public- and private-sector partners know their roles before pressure hits. That includes who shares information, who validates threats, who communicates with the public, who has decision-making authority and how quickly partners can act if a system slows down or becomes unavailable.

Major events are only as resilient as the systems behind them

Attackers don’t need to compromise the most visible organization to create disruption. They can look for weaker points across the event ecosystem. A disruption may begin with a vendor, ticketing platform, transportation partner, payment provider, hotel, contractor or communications provider, but the impact can quickly become broader than any one organization.

Sports organizations now operate like large businesses, with ticketing systems, VIP data, sponsors, vendors, media partners, stadium operations, payment systems, and fan engagement platforms. They depend on networks of suppliers and partners, and that creates multiple possible entry points.

Operational technology (OT) deserves more attention than it typically gets in these conversations. A ransomware attack that disrupted stadium operations directly, rather than a ticketing site or a fan-facing app, would be one of the most damaging scenarios organizers could face. OT security has to sit alongside the more visible concerns like payment fraud and spoofed domains, not behind them.

Bad actors don’t let a good crisis go to waste. Fans are often an easy target. Excitement drives a fan to buy a last-minute ticket or check a score on an unknown site. That excitement is exactly what fraudsters count on.

This risk grows over time. As the event gets closer and attracts more eyes, it becomes a richer target. A fake FIFA ticket site is useless to a crook a month after the last game. Groups running these systems must act faster as opening day nears, and share threat intelligence without delay.

Threat intelligence turns planning into proactive defense

The World Cup may be over, but the work isn’t. Cities, governments, and private-sector organizations will continue supporting large-scale public events that depend on complex digital and physical ecosystems. The question isn’t whether another major event will face cyber threats, it’s whether the planning starts early enough.

Organizations involved in future major events should focus on resilience, not just prevention. That means planning for what happens if a critical system slows down, goes offline, or becomes unreliable, and ensuring partners know how to coordinate before an incident occurs.

Every major event forces defenders to prepare for known risks. The harder challenge is anticipating the ones that haven’t emerged yet.

The next major disruption may not come from the attack that organizations spent months preparing for. It could target a new dependency, exploit emerging technology, or capitalize on a moment when public attention is at its highest. That’s why resilience can’t be built around yesterday’s playbook. It has to be informed by continuous threat intelligence, regular coordination across public- and private-sector partners, and the flexibility to adapt as the threat landscape changes.

The World Cup demonstrated what’s possible when that preparation comes together. As cities, governments, and private organizations look ahead to future global events, success won’t be measured solely by the attacks they stop. It will be measured by how effectively they can maintain critical operations, share information, and adapt under pressure when the unexpected happens.

The post What the World Cup can teach us about cybersecurity resilience appeared first on CyberScoop.

Accenture shells out $4.18B on three companies in big industrial cybersecurity push

By: Greg Otto
18 June 2026 at 11:05

Accenture announced Thursday it would acquire a majority stake in industrial cybersecurity firm Dragos for $3.25 billion and purchase two smaller security companies outright, essentially making a $4.18 billion bet that defending the IT networks of power grids, pipelines, factories and critical infrastructure sectors will become one of the defining challenges of the AI era.

The deals — which also include two Austin, Texas-based companies, runZero and NetRise —  represent a significant strategic pivot for Accenture toward operational technology (OT) security,  a segment of the cybersecurity market that has long been underfunded relative to traditional IT defenses. The announcement comes as the consulting giant faces pressure on its core business from the same AI tools reshaping the threat environment it is now moving to address.

Dragos, founded in 2016 by former intelligence specialists and based in Hanover, Maryland, has built what the industry regards as a leader detecting threats in OT environments. Its proprietary dataset of industrial threat intelligence has made it a trusted partner to critical infrastructure operators globally.

RunZero specializes in asset discovery and attack-surface intelligence — essentially mapping what is connected to a network and identifying where it is exposed. NetRise focuses on firmware-level visibility and software supply chain security, areas that have drawn increased scrutiny since high-profile incidents revealed how deeply embedded vulnerabilities can propagate through industrial device ecosystems.

Dragos co-founder and CEO Robert M. Lee will continue leading the combined entity, which will operate as an independent business under Accenture’s ownership. The CEOs of runZero and NetRise, HD Moore and Tom Pace, respectively, along with NetRise’s chief technology officer Michael Scott, will join Dragos as senior executives.

The acquisitions are not Accenture’s first move in OT security. The company acquired Cimation in 2015 and Revolutionary Security in 2020, along with several other OT-focused firms. 

Thursday’s deal, however, is of a different scale and ambition. Where previous acquisitions built out Accenture’s services capabilities, the addition of Dragos, runZero and NetRise moves the company firmly into OT cybersecurity software, a market it had not previously entered at scale.

Accenture and Dragos describe this expanding environment — which also encompasses Internet of Things devices, cloud-connected sensors and related IT infrastructure — as “xOT.” The concern is that as AI is integrated into industrial decision-making, the attack surface grows. At the same time, adversaries are using AI to shorten the window between compromising an IT network and pivoting to OT systems underneath it.

Despite that convergence, most cybersecurity budgets remain concentrated on traditional IT, leaving critical infrastructure comparatively exposed. The OT cybersecurity services market is estimated at roughly $7 billion in 2026. The broader OT cybersecurity market, which includes software, is estimated at $27 billion this year and projected to reach nearly $59 billion by 2031, growing at approximately 16% annually.

“Our energy and water systems, manufacturing plants, data centers and other operational environments need cybersecurity built from the ground up for xOT and designed to keep pace as threats evolve. The consequences of getting it wrong become societal threats,” Lee said in a release. “Organizations need solutions, not a patchwork of software and services. The addition of runZero and NetRise will allow the Dragos Platform to be a unique end-to-end platform for global defense, and Accenture will bring its decades of trusted relationships and deep expertise to help us scale and secure more critical infrastructure and physical operations globally.”

The transactions are expected to close in August or September, pending customary regulatory approvals.

The post Accenture shells out $4.18B on three companies in big industrial cybersecurity push appeared first on CyberScoop.

CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict

By: djohnson
5 May 2026 at 17:47

The Cybersecurity and Infrastructure Security Agency is urging critical infrastructure owners and operators to plan for delivering essential services under emergency conditions – potentially for months at a time.

The federal government’s top cybersecurity agency warned that state-sponsored hackers, particularly two Chinese groups known as Salt Typhoon and Volt Typhoon, continue to threaten critical sectors like electricity, water, and internet. 

The agency is now working with the private sector to protect operational technology – the systems that control the heavy machinery and equipment that powers most critical infrastructure – from attacks that enter through business IT systems or third-party vendor products.

The initiative  — known as CI Fortify – will include CISA conducting targeted technical assessments of critical infrastructure entities and aims to create plans that “allow for safe operations for weeks to months while isolated” from IT networks and third-party tools, according to the agency’s website.

Nick Andersen, CISA’s acting director, told reporters that the goal is “service delivery [that] can still reach critical infrastructure after the asset owner has disconnected with IT and OT, disconnected from third party vendors and service provider connections and disconnected from third party telecommunications equipment.”

Over the past two years, wars in Ukraine, Gaza, Iran and elsewhere have seen water plants, power substations, data centers and other critical infrastructure targeted by kinetic or cyberattacks.

Andersen said the agency has already begun engaging with some companies to pilot the assessments and expects that work to ramp up considerably as CISA hires additional staff in the coming months.

He declined to name the entities involved in the pilot program, but said they will focus on organizations that support national security, defense, public health and safety and economic continuity. He added that CISA’s assessments will vary from sector to sector depending on their unique needs.

“Water isn’t necessarily designed to prioritize specific customer needs outside of recovery periods, while energy and transportation have more immediate tradeoffs for selecting one load or one set of cargo over another,” Andersen said as an example.

One pillar of CISA’s strategy is isolation: essentially turning off all third-party and business network connections to an OT network when facing an emergency or unknown vulnerability.

Organizations also need to develop an internal plan for what acceptable service levels look like under those conditions and reach understandings with their critical customers, like U.S. military installations and lifeline services.

The second pillar, recovery, involves best practices for organizations: backing up files, documenting systems and having manual backups for operations when normal computer systems are down.

In conversations with cybersecurity specialists who focus on critical infrastructure and operational technology, it is widely assumed that China is not the only nation to have broadly compromised Americans critical infrastructure. That hacking groups tied to other nations have almost surely noticed and exploited the same basic vulnerabilities and hygiene issues found by the Typhoons.

Agencies like the FBI and Federal Communications Commission have touted efforts to purge Chinese hackers and work voluntarily with telecoms to harden their network security. But U.S. national security officials and cybersecurity defenders have consistently said both Salt Typhoon and Volt Typhoon remain active threats to U.S. critical infrastructure.

The post CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict appeared first on CyberScoop.

❌
❌