Search This Blog

Powered by Blogger.

Blog Archive

Labels

Showing posts with label FERC. Show all posts

U.S. Dams Vulnerable to Cyber Threats

 



The cybersecurity of America's dams has come under intense scrutiny, with experts warning of the potential for devastating cyberattacks. Concerns were raised during a recent hearing on cybersecurity threats to critical water infrastructure, where Senator Ron Wyden expressed fears of cyberattacks causing catastrophic floods and chaos in communities.

Current Vulnerabilities

Despite the growing cyber threat, most dams under Federal Energy Regulatory Commission (FERC) oversight have not undergone comprehensive cyber audits. With only four full-time employees overseeing 2,500 dams nationwide, experts agree that the sector is vulnerable to cyberattacks that could result in loss of human lives.

Ageing Infrastructure and Lack of Regulation

The majority of U.S. dams are privately operated, with FERC's cybersecurity requirements for commercial dam operators last updated in 2016. Only 5% of the 91,827 dams in the United States fall under federal regulation, and many of them are ageing, with approximately 2,200 classified as "high-hazard" and in poor condition.

Industry Challenges

The water industry, including dam operators, is considered one of the least secure sectors in terms of cybersecurity. Corporate cultures centred around traditional engineering and operational technology pose challenges in adapting to the fast-paced IT and cyber world. 

Government Response

FERC has cited a lack of funding and staff as reasons for not being able to audit remaining dams within the next decade. Additionally, the commission's cybersecurity rules only apply to dams that are remotely managed over the internet, leaving on-site operators unregulated.

Senator Wyden urged Congress to address the lack of comprehensive cybersecurity regulations across critical infrastructure sectors and accelerate the development of cybersecurity standards for dams. Without forceful government mandates, experts warn of the potential for a catastrophic cyberattack that could result in loss of life and severe operational disruptions.

FERC is in the process of developing new cybersecurity guidance for the dam sector, expected to be completed within the next nine months. However, national security experts stress the urgent need for federal support to enhance the cybersecurity posture of dam operators and mitigate the risks posed by cyber threats.

With outdated infrastructure, lack of regulation, and growing cyber threats, urgent action is needed to safeguard critical water infrastructure and prevent potential disasters.