Cyberattacks Highlight Vulnerabilities in Aging State Technology

On the August 5 StateScoop Priorities Podcast, Patrick Gillespie, OT practice director at the firm GuidePoint Security, called the water utility cyberattacks in Minnesota opportunistic. The recent attacks ultimately affected 12 states, with the federal government investigating Iran’s possible involvement. “The reason this is happening right now,” Gillespie explains “is these are inherently insecure devices directly connected to the internet. They have no firewall, no cyber protections on the devices themselves or a firewall in front of them. It is not sophisticated attacks. It’s essentially low-hanging fruit, just devices that are legacy, sometimes years or decades old, without encryption, without authentication or sometimes default credentials.”

On July 30, the Federal Bureau of Investigation and the Environmental Protection Agency issued a Public Service Announcement to warn critical infrastructure asset owners and operators that malicious cyber actors are conducting cyber attacks targeting Operational Technology (OT) devices. The FBI reported that “after remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.”

FBI and EPA Tips to Protect Yourself from Cyber Attacks

In the announcement, the FBI and EPA recommended that individuals take the following cybersecurity precautions:

  • Disconnect PLC from the public-facing internet.
  • Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable.
  • Strictly control network access to PLC devices.
  • Place physical and software key switches into the run position to block unauthorized changes to logic, configuration, and firmware.
  • Practice and maintain the ability to operate OT systems manually.
  • Review project files running on PLCs for unauthorized changes.
  • Plan for end-of-life (EOL) replacements when possible.

Audit: 34 States Used Unlicensed Placements for Foster Children

According to a July federal audit, as reported in News from the States on July 30, 9,000 children in foster care temporarily stayed in hotels, offices and other unlicensed settings, including cabins in state parks. Of the 49 states that responded to the Inspector General’s questionnaire, 34 reported temporarily placing children in these unlicensed settings. States with a high number of placements, according to the report included: Arizona, Texas, Tennessee, Illinois and Washington state. Seven states reported not placing any children in emergency settings; these included Connecticut, Iowa, Massachusetts, New Jersey, Rhode Island, Utah and Wyoming.

According to the audit, National Overview of State-Level Challenges and Efforts To Minimize or Eliminate Temporary Emergency Placements in Foster Care, other findings included:

  • States found securing foster care placement challenging, especially for children with complex or special needs.
  • Other reasons for temporary placement included challenges stemming from COVID-19, along with impacts from illicit drug use.
  • Accurate reporting helps reveal shortages of foster homes and difficulties in recruiting and retraining foster parents.

GovRAMP Leaders Discuss Shared Risk Strategies

During a GovRAMP panel the theme centered on the shared responsibility of state cybersecurity. Leah McGrath, Executive Director of GovRAMP, moderated the discussion at GovForward’s 8th Annual Carahsoft Summit on FedRAMP on July 23 in Washington, D.C. That shared risk management requires government agencies, technology providers, and other stakeholders to work together to identify, manage, and reduce cybersecurity risk. According to GovRAMP, that “success depends on trusted partnerships, common security expectations, and a commitment to continuous improvement across the entire public sector ecosystem.” Members of the panel included Shawnzia Thomas, State Chief Information Officer, State of Georgia; David Resler, Chief Operating Officer and Chief Technology Officer, GovRAMP; and Charles Rote, State Chief Information Security Officer, State of Maine. “Cybersecurity is no longer the responsibility of a single organization—it requires shared ownership, trusted partnerships, and a commitment to protecting the public together,” said Thomas.

Time to Modernize

GL Solutions helps your regulatory agency run, grow and adapt with modern software and automation designed to address your agency’s biggest challenges. GL Solutions embeds AI into regulatory agency workflows in GL Suite, giving staff practical, policy-driven support that boosts efficiency, improves consistency and advances modernization—while keeping agency control and accountability at the forefront. Contact us to learn more.