Cybersecurity threats are combining with resource constraints and regulatory inconsistencies to create a difficult operating environment for U.S. water systems, while healthcare organizations also face mounting cyberattacks and looming regulations, according to Fitch Ratings.
In a pair of analyses published on Tuesday for customers and shared with Cybersecurity Dive, analysts said that both critical infrastructure sectors were struggling as hackers targeted them because of their archaic technology and low tolerance for operational downtime.
“The combination of essential service delivery, increased connectivity, and limited financial and technical resources at many utilities makes water systems compelling targets for adversaries,” Fitch’s experts wrote.
In the case of healthcare, analysts said, “While rating actions [related to cyberattacks] have been limited to date, the cost and severity of cyber events are increasing, as is the likelihood of rating pressure.”
The new assessments come as the water and healthcare sectors receive heightened cybersecurity scrutiny, with water utilities fending off a hacking campaign that U.S. officials have tentatively attributed to the Iranian government.
Planning helps maintain ratings
Cyberattacks alone rarely prompt analysts to change their credit ratings of victim organizations, Fitch said. Instead, ratings change when cyberattacks “exacerbate broader operational and financial challenges.” Organizations with “healthy operating margins” rarely receive ratings downgrades after experiencing hacks, the healthcare report said.
Organizations with strong credit ratings can maintain those favorable financial assessments despite a cyberattack, as long as they are ready to respond, Fitch analysts wrote.
The providers “most likely to mitigate potential negative ratings momentum are those that demonstrate business resiliency and have robust incident response capabilities, effective operational continuity planning and sufficient ratings headroom to absorb the financial stress of a cyber event,” Fitch said in its healthcare report. Analysts made the same point in the water report.
But that imperative to plan for cyberattacks in advance is challenging for small healthcare organizations with constrained finances and limited cybersecurity experience. Those providers, analysts wrote, are “typically more vulnerable to durable operational and financial stress, which could create negative ratings momentum.”
Attacks could complicate rate raises
Cyberattacks on water utilities could cause long-term challenges in an underappreciated way, Fitch said.
Cash-strapped water utilities can only afford to pay for new cybersecurity measures or personnel by raising rates, a prospect that is politically challenging even in a steady-state operating environment. A major hack that affects water distribution or exposes customer data, for example, could significantly undermine confidence in the utility’s management. Lost confidence, in turn, might make it politically untenable for the utility to raise rates.
In addition, the small, rural utilities most vulnerable to cyberattacks are also the ones least able to raise rates before a hack to fund better defenses.
Those utilities “may be less able to fully pass on what could be considerable costs, as its customer base could be less able to bear a jump in rates,” Fitch analysts wrote. “As a result, margins could suffer, liquidity and leverage could weaken, and negative rating pressure could build.”
Encouraging HIPAA compliance prognosis
Fitch’s healthcare report summarizes several imminent regulatory changes, most notably the Department of Health and Human Services’ update to the cybersecurity standards in the Health Insurance Portability and Accountability Act (HIPAA). But despite the prospect of new security requirements that HHS has estimated could cost $33 billion over the next five years, Fitch said it didn’t expect its rated organizations to experience significant financial challenges as a result of compliance.
“Even under a 2.0x stress test, Fitch does not anticipate any rating actions in its rated portfolio,” the company said, “in part due to the rated universe having already implemented many of these proposed requirements and their low cost relative to median operating revenue for the sector.”