State and local governments across the U.S. are facing significant gaps in their ability to protect critical infrastructure at a time of increased threat activity.
State authorities said they need additional funding, federal support and staffing in order to protect key sectors like water, energy and healthcare, according to a report from the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology.
“The research indicates that states and localities do not necessarily have the funding they need in place to address these cyber security challenges,” Mischa Beckett, senior director of cyber threat intelligence at GDIT, told Cybersecurity Dive.
The report is being released at an urgent time for state and local governments. In July, suspected Iran-nexus actors launched a series of coordinated hacks targeting water utilities across the U.S., impacting drinking and wastewater utilities in at least 12 states. Late last month, the Cybersecurity and Infrastructure Security Agency confirmed that more than 100 internet-exposed systems were targeted in the July attacks.
For months, suspected Iran-nexus hackers have been targeting exposed industrial devices — called programmable logic controllers — that are used by water utilities, power companies and other key industrial sectors. These attacks forced many utilities to temporarily suspend water service and left operators unable to access monitoring equipment in their own utilities.
NASCIO research shows the safety of water utilities is a top concern among state officials, and they are also facing significant threats to other facilities, including electric and gas utilities, telecommunication networks, hospitals and transportation systems.
Limited resources
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center, said state assistance has become critically important due in part to the federal government scaling back their own resources and shifting much of the burden to states.
“This report is especially relevant to healthcare because it treats cybersecurity as a whole-of-state, critical infrastructure issue and hospitals depend on state and local partners for emergency management, public health coordination, utilities, and transportation,” Weiss told Cybersecurity Dive.
Key states have adopted shared services or whole-of state plans, where a series of training, resource and other measures are adopted to help local providers protect their systems against cyber threats.
State governments have taken additional measures to step in and fill some of the void left by federal cutbacks.
New York State in early August announced $9 million in grants to help 153 local drinking and wastewater utilities.
The report cited additional efforts by New Jersey, Utah and Oregon to develop plans across local governments and other organizations to provide additional resources and training.
“Attackers don’t care where local, county or state lines begin and end,” said Meredith Ward, deputy executive director at NASCIO. “Everyone is a target, which is why we must work together.”
The White House launched a plan just last month to provide additional resources to water utilities, beginning with a pilot program in Texas.
CISA has also outlined plans to fill hundreds of vacant positions, a move that could help under-resourced entities get additional support.
The report recommends several immediate steps:
- States need to inventory and assess the highest risk critical infrastructure systems that could endanger safety and health.
- States should employ a whole of government approach to cyber risk.
- Strongly encourage or mandate basic cyber hygiene standards.
- States may need to mandate cyber incident reporting requirements.
- Maintain or expand critical infrastructure services to local entities and special districts.