Site navigation

NCSC Urges Water Sector to Secure Its Networks

Michael Edgar

,

Water Sector Security
The UK’s water sector is urged to bolster cybersecurity efforts amidst a slew of attacks against US facilities. 

The UK’s National Cyber Security Centre (NCSC) is calling on the country’s water sector to adopt best practices to safeguard critical infrastructure against the threat of cyber attack. 

“We are notifying UK providers of this threat, and recommend they protect consumers by following the mitigation advice set out in the advisor,” said Jonathon Ellison, NCSC director for national resilience and future technology.

This is in the wake of almost ten facilities in different parts of the US, and in each case, the equipment targeted was an Israeli-made computer system, according to the US’s CISA (Cybersecurity & Infrastructure Security Agency).

While the NCSC is downplaying the immediate severity of the threat to UK water providers, it urges them to exercise caution, saying: “The exploitation is of limited sophistication, and is highly unlikely to cause any disruption to the routine operations of affected organisations.”

“There is a very low potential risk, if the threat is unmitigated, to some small suppliers. As such, the NCSC is encouraging organisations using Unitronics PLCs to follow the steps outlined in the cyber security advisory.”


Recommended reading


The advisory includes a number of measures to implement, such as: 

  • Change all default passwords on PLCs and human machine interfaces (HMIs) to a strong password. 
  • Mandate multi-factor authentication (MFA) for all remote access to the operational technology (OT) network.
  • Disconnect the PLC from the public internet and implement a firewall or VPN to control network access.
  • Backup the logic and configurations on any Unitronics PLCs to enable fast recovery and familiarise with the factory reset process in the event of ransomware.
  • Use a TCP port different from the default port.
  • Update Unitronics PLCs/HMIs to the latest version.

“The NCSC has warned for some time of the enduring threat to the UK’s critical national infrastructure,” continued Ellison. 

The call to action from the NCSC serves as a reminder of the ongoing need for vigilance and proactive measures to ensure the resilience and security of essential services.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data